← Back to MonthEndIQ
Privacy Notice
Last updated: 25 June 2025
The short version: MonthEndIQ analyses your financial data in-session to produce variance dashboards and commentary. We do not store your data after your session ends, we do not use it to train AI models, and we do not sell or share it with third parties for their own purposes.
1. Who we are
MonthEndIQ is a financial planning and analysis tool that generates variance dashboards, AI commentary, and management packs from profit & loss data. This notice explains how we handle your data when you use the service.
2. What data we process
| Data type | Source | Purpose |
| Profit & Loss reports |
File upload (CSV/Excel) or Xero API |
Variance analysis, dashboard generation, management pack export |
| Xero OAuth tokens |
Xero OAuth 2.0 flow |
Authenticating API requests to fetch your P&L report |
| Chat messages |
Copilot Q&A feature |
Answering your questions about the financial data |
3. How we use your data
- Variance analysis — your P&L data is processed server-side to calculate period-over-period and budget-vs-actual variances.
- AI commentary — summary data (account names, variance figures) is sent to OpenAI's API to generate written commentary. OpenAI does not use API inputs to train its models (OpenAI Enterprise Privacy).
- Management pack export — your data is used to generate PDF/Excel reports that are returned directly to your browser.
4. What we do NOT do
- We do not use your data to train, fine-tune, adapt, or enhance any AI model.
- We do not sell, rent, trade, or share your financial data with third parties for their own purposes, nor use it for any purpose beyond producing the analysis you requested.
- We do not sell, rent, or share your data with third parties for their own purposes.
- We do not store your Xero password — authentication uses OAuth 2.0 tokens only.
5. Xero integration
When you connect MonthEndIQ to Xero:
- We request read-only access to your accounting reports (
accounting.reports.read scope).
- OAuth tokens are held in server memory for the duration of your session only — they are not written to disk or a database.
- We only fetch the Profit & Loss report for the date range you specify. We do not access invoices, contacts, bank transactions, or any other Xero data.
- You can revoke access at any time from Xero → Settings → Connected Apps.
6. Third-party processors
| Provider | Role | Data shared |
| OpenAI |
AI commentary generation |
Summarised financial figures and account names (not raw files) |
| Render |
Application hosting |
Data in transit and in-memory during your session |
| Xero |
Accounting data source (if connected) |
OAuth tokens for API authentication |
7. Data retention
Session data (your uploaded P&L file, analysis results, and Q&A chat history) is stored in an encrypted SQLite database on the server for up to 30 days from the time of upload, after which it is automatically and permanently deleted. You can delete your session immediately at any time using Settings → Start fresh in the application.
Exported PDF and Excel management packs are generated on-the-fly and delivered directly to your browser — they are not retained on the server after delivery.
Chat history is also stored in your browser's localStorage so that your conversation persists across page reloads. You can clear this at any time using Clear chat in the Q&A Copilot tab.
8. Security
- All connections use HTTPS/TLS encryption in transit.
- Xero authentication uses OAuth 2.0 with PKCE-style state parameters — we never see your Xero password.
- API keys and secrets are stored as environment variables, not in source code.
9. Your rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access — request a copy of any personal data we hold (in practice, we hold none persistently).
- Erasure — request deletion of your data (sessions are automatically ephemeral).
- Portability — export your analysis via the management pack export feature.
- Object — stop using the service at any time; revoke Xero access from your Xero settings.
- Complain — lodge a complaint with the Information Commissioner's Office (ICO).
10. Data Protection Impact Assessment
We have conducted a DPIA for MonthEndIQ, considering:
- Nature of processing — temporary, in-session analysis of financial reports.
- Necessity — processing is limited to what is required to produce the variance dashboard and commentary the user requested.
- Risks identified — data in transit (mitigated by TLS), third-party AI processing (mitigated by OpenAI's enterprise data policy and sending summaries rather than raw files), session data in memory (mitigated by ephemeral storage with no persistence).
- Conclusion — the residual risk to data subjects is low given the ephemeral processing model and limited scope of data accessed.
11. Changes to this notice
We may update this notice from time to time. The "last updated" date at the top will reflect the most recent revision.
12. Contact
For questions about how MonthEndIQ handles your data, contact us at jackclaytonclowes@gmail.com.