BAMF Books: Privacy Policy
Effective date: June 21, 2026 Last updated: September 30, 2026
This Privacy Policy explains how data is handled in BAMF Books (the "Software"), a self-hosted bookkeeping application published by BAMF Apps LLC ("we," "us," "our"). Contact: support@bamfapps.com.
The most important thing to understand: BAMF Books is self-hosted
BAMF Books is software you install and run on infrastructure you control: your own server and your own PostgreSQL database. The publisher does not operate a hosted service for it, does not receive a copy of your data, and has no access to the books, transactions, user accounts, or credentials stored in your instance.
In data-protection terms, you (the operator who deploys BAMF Books) are the data controller for the financial and personal data in your instance. We are the software author. The sections below describe how the Software handles data on your own system so you can configure and operate it responsibly, and so you can adapt this policy if you expose your instance to other users.
Data the publisher collects
None. We do not collect, receive, transmit to ourselves, store, sell, or share any data from your BAMF Books instance. There is no analytics SDK, no crash/telemetry reporting, no advertising, and no "phone home." The Software makes no network calls to the publisher.
If you contact us for support by email, we will of course see what you choose to send us (your email address and the contents of your message). We use that only to respond.
Data the Software stores (on your infrastructure)
Within your own database, BAMF Books stores the records needed to keep your books:
- Financial ledger data: entities (your sets of books), chart of accounts, sources/feeds, transactions, signed postings, classification rules, reconciliations, sync-run history, and loan/amortization schedules.
- Imported feed data: bank and credit-card transactions retrieved via SimpleFIN, and charge/fee/payout/refund detail retrieved via Stripe (see "Third-party services" below).
- User accounts: for each person you grant access: email address, display name, role (admin / accountant / viewer), an account-active flag, and timestamps (created / last login). Passwords are never stored in plain text. They are hashed with scrypt (a memory-hard key-derivation function) using a per-user random salt.
- Sessions: opaque random session tokens (default 30-day expiry) used to keep signed-in users authenticated.
- Integration credentials: your SimpleFIN access URL/token and your Stripe restricted read keys, if you choose to store them in the app rather than in environment variables. When stored, these are encrypted at rest with AES-256-GCM using a key held outside the database, so a leaked database file alone is not a credential dump.
All of the above lives in your database. We never see it.
On-device / on-server vs. transmitted
- Stays on your infrastructure: everything listed above. The data does not leave your server except where you configure an outbound integration.
- Transmitted to third parties you configure: when you enable an integration, your instance makes outbound, read-only requests to that third party using your credentials (see below). The Software never initiates a money movement. It only reads.
- Transmitted to the publisher: nothing.
Third-party services
BAMF Books can connect to the following services only if you provide credentials. These connections are made by your instance, directly to the third party, under your own accounts, not through us.
| Service | Purpose | Direction | Data involved |
|---|---|---|---|
| SimpleFIN (account aggregation, backed by MX) | Retrieve bank and credit-card transactions and balances | Outbound, read-only | Account identifiers, transaction amounts, dates, descriptions/payees |
| Stripe | Retrieve gross charge, fee, payout, and refund detail | Outbound, read-only | Balance-transaction records for your Stripe account(s) |
Each of these services has its own privacy practices, governed by the agreement between you and that service:
- SimpleFIN: https://www.simplefin.org/
- Stripe: https://stripe.com/privacy
A payroll integration and integration with the BAMF Power ERP are planned; this policy will be updated before either ships if it changes what data is transmitted. BAMF Books contains no analytics, crash-reporting, advertising, or tracking SDKs.
How data is used
Data in your instance is used solely to operate the bookkeeping system: importing feeds, classifying and reconciling transactions, generating reports, authenticating users, and integrating with the services you connect. There is no secondary use, profiling, advertising, or sale of data by the Software or by us.
Data retention
Because the Software is self-hosted, you control retention. BAMF Books keeps records until you delete them. Notes:
- Posted transactions are immutable by design (corrections are made with reversing entries), which preserves an audit trail, so "deletion" of posted history is an operator decision made at the database level, not a per-entry button.
- Expired sessions can be purged; changing a user's password immediately invalidates that user's existing sessions.
- You may export, archive, or destroy your database at any time.
Security
- Passwords are hashed with scrypt + per-user salt and compared in constant time.
- Sessions use opaque, cryptographically random 32-byte tokens with a default 30-day expiry.
- Stored integration secrets are encrypted at rest with AES-256-GCM, with the key kept outside the database.
- Access is gated by role (admin / accountant / viewer); machine-to-machine integration uses a separate service key.
Security also depends on you: keep your host, database, and network secured, set a strong LEDGER_SECRET_KEY, use TLS in front of the app, and restrict who can reach it. No system is perfectly secure, and we cannot secure infrastructure we do not control.
Children's privacy
BAMF Books is business bookkeeping software intended for adults. It is not directed to children under 13, and we do not knowingly collect any information from children. (As noted, the publisher does not collect information from anyone.)
Your privacy rights
Depending on where you live, you may have rights over your personal data, including the right to access, correct, delete, or port it, and to object to or restrict certain processing.
- CCPA/CPRA (California): We do not sell or share personal information and have no data to disclose, because we do not collect any. We do not "sell" or "share" data for cross-context behavioral advertising.
- GDPR/UK GDPR (EEA/UK): For data in a BAMF Books instance, the operator who deployed it is the controller and is the party able to fulfill access/erasure/portability requests. We act only as the software author and hold no such data.
To exercise rights regarding the limited information you may have sent us directly (e.g. a support email), contact support@bamfapps.com. For data inside a BAMF Books instance you do not operate, contact the operator of that instance.
International data transfers
We do not receive or transfer your data, so we perform no international transfers. If you operate an instance, any transfers are determined by where you host it and which third-party services (e.g. SimpleFIN, Stripe) you connect; those are governed by your agreements with them.
Changes to this policy
We may update this Privacy Policy as the Software evolves. We will post the updated version at this URL and revise the "Last updated" date above. Material changes affecting what data is transmitted will be reflected here before the relevant feature ships.
Contact
Questions about this policy or BAMF Books:
BAMF Apps LLC Email: support@bamfapps.com Privacy policy: https://bamfapps.com/apps/bamf-books/privacy