Privacy Policy
What Midbench is
Midbench keeps a company's accounting records: it connects to the financial services a customer authorizes (banks, payment processors, billing and payroll platforms), reads their activity, and maintains governed, auditable books from it.
What we store
- Financial records. Transactions, balances, invoices, bills, and payroll summaries read from the providers a customer connects, plus the accounting records derived from them. These are the product — they are retained as ledger records for as long as the customer keeps an account, and audit history is retained as required for financial record-keeping.
- Provider credentials. When a customer connects a provider, the credential (an API key or OAuth token) is captured on a dedicated page over TLS, encrypted immediately, and stored only in ciphertext. Credentials are never shown back to anyone — including us — and are used solely to read the data the customer authorized. Read-only scopes are used wherever the provider offers them.
- Contact details. The name and email used to communicate with us.
- Early access requests. If you request early access on this site, we store the email address you submit and when you submitted it — nothing else. We use it only to contact you about early access, and delete it on request (info@midbench.com).
- Account sign-in data. If you take up a Midbench account, our identity provider (Amazon Cognito) holds your email address and your passkey's public key — never a password you must remember, and never on Midbench's own servers. Midbench itself stores only the revocable link between your account and your business's books.
Bank connections through Plaid
For banks without a direct integration, Midbench connects your account through Plaid Inc. You link the account in Plaid's own window — your bank credentials go to your bank or to Plaid, never to Midbench. Midbench receives only a read token and the resulting account and transaction data. By linking an account through Plaid, you grant Plaid the right to access and transmit your personal and financial information as described in the Plaid End User Privacy Policy. Disconnecting the account at Midbench also removes Midbench's access at Plaid.
What we don't do
- We do not sell personal or financial data, and we do not share it with third parties for their own purposes.
- We do not run advertising on this site, and we do not use advertising cookies, remarketing, or cross-site tracking. Google's advertising signals are switched off by default in our tag configuration.
- We do not place analytics of any kind on the product surfaces where your books are shown. Measurement is limited to these public marketing pages.
Service providers
Midbench runs on infrastructure from Amazon Web Services (including Amazon Cognito for account sign-in) and ClickHouse Cloud, which process data on our behalf under their own security and confidentiality commitments. Data is encrypted in transit and at rest. Transaction descriptions are processed through Anthropic's Claude API to propose accounting categories for review; that data is not used to train AI models. Bank connections may be made through Plaid, as described above.
On these public marketing pages only, we use Google Analytics (via Google Tag Manager) to count visits and see which pages people read, so we know whether the site is working. It sets a first-party cookie holding a random identifier, records the pages you view, your approximate location from your IP address, and your browser and device type. We do not use it to identify you, we do not link it to any customer account or to any financial data, and advertising and personalization signals are switched off.
If you are visiting from the United Kingdom, Switzerland, or the European Economic Area, nothing loads until you say so: we ask first, and if you decline, no analytics runs and no cookie is set. Everywhere else it is on by default and you can switch it off here. We also honor Do Not Track and Global Privacy Control: if your browser sends either signal, analytics never loads, wherever you are. Your choice is kept in your own browser's storage, never on our servers, so it is per browser and per device. You can also opt out of Google Analytics everywhere with Google's browser add-on.
Deletion
Customers can disconnect a provider at any time, which stops all further reads; stored credentials for it are revoked. To close an account or request deletion of data not subject to financial record-keeping obligations, email us. Closing your account also removes your sign-in identity at our identity provider; the record that an authorization existed and was revoked remains in your books' audit trail.
Changes
If this policy changes materially, we will post the updated version here with a new effective date.
Contact
info@midbench.com · Midbench Inc., 60 Broad Street, New York, NY 10004