Privacy Policy
This is the formal version of what I promise on the security page โ same rules, more detail. If anything here ever contradicts what the app actually does, that's a bug and I want to hear about it. โ Siki ๐ฆ
Last updated: July 2026
What we access
Sikizana is an AI bookkeeping assistant for Xero. When you use it, we access:
- Your Xero accounting dataโ invoices, bank transactions, contacts, accounts, and reports (P&L, balance sheet). This is read on demand via Xero's OAuth API when you ask a question or run a health check. We do not bulk-copy your Xero organisation into our own database.
- Receipts you upload โ receipt images or PDFs you choose to upload are analysed by vision AI to extract the supplier, amount, and date so they can be matched to a bank transaction.
- Feedback you giveโ thumbs up/down ratings and optional comments on the assistant's answers, which we store to improve the product.
Who processes your data
We use a small number of service providers, each for one specific job:
- NVIDIA (with Venice AI as backup)โ the AI models that generate the assistant's answers process your questions and the Xero data retrieved to answer them. Your data is not used to train models.
- Google Gemini โ reads receipt images you choose to upload, to extract the supplier, amount, and date.
- Postmark โ delivers the emails you approve: invoice reminders to your customers and your weekly digest.
- Stripe โ handles payments. We never see card numbers.
- Exa & Firecrawl โ used to look up public HMRC guidance. Only pre-written generic search queries are sent โ never your questions, customer names, or amounts.
Writing to Xero
The assistant can propose journal entries, but nothing is written to your Xero organisation without your explicit approval โ human-in-the-loop by design. In demo mode, journal posts are simulated and never touch a real Xero organisation.
Data retention & your control
- Xero access tokensare stored encrypted so the assistant can read your data during your sessions. You can revoke access at any time with the Disconnect button in the app, or from Xero's connected apps settings โ either immediately invalidates our access.
- Conversation history, activity trail, and chase schedules are stored on our servers, scoped to your private session so no other visitor can ever see them.
- Feedback (ratings and comments) is stored on our servers.
- Delete everything, anytime:the "Delete my data" button on your Account page revokes the Xero connection AND permanently erases your conversations, activity history, chase schedules, and metrics from our servers.
Emails sent on your behalf
Chasing is Zana's department. If you approve a chase sequence for an overdue invoice, reminder emails are sent to that invoice's billing contact under your business nameโ not ours โ with replies routed to your own email address. Sequences stop automatically the moment the invoice is paid, and you can cancel them at any time. Zana never emails your customers without your explicit approval of that specific invoice's sequence.
"I'm persistent, not reckless. You approve, I chase, I stop the second they pay." โ Zana
What we don't do
- We do not sell your data. Ever.
- We do not share your accounting data with advertisers.
- We do not post to Xero without your approval.
Cookies
We use a single session cookie to keep you connected to the backend. No advertising or cross-site tracking cookies.
Contact
Questions about this policy or your data? Email [email protected]. For the plain-English version of all of this, see how your data is protected.