AES-256
Customer data is encrypted at rest using industry-standard AES-256
Security and data privacy
Your financial data is encrypted, access is limited to what ClearSpend needs, and connected accounts remain under your control.
Last reviewed September 2026
Core controls
Customer data is encrypted at rest using industry-standard AES-256
Data in transit is protected with TLS 1.2 or higher encryption
Only the permissions required for each workflow
Customer data isn't used to train general AI models
Internal access is restricted
Connections can be revoked when customers choose
Review materials
Start with the policies and documentation behind ClearSpend AI's security and data-handling practices.
How personal and financial data is collected, processed, transferred, retained, and deleted.
Customer data ownership, third-party processing, safeguards, and termination terms.
Setup, permissions, and connection behaviour.
Request current security, privacy, compliance, or procurement information.
Integration permissions
ClearSpend requests only the permissions required for the workflows you enable.

Finding billing messages and collecting invoice or receipt attachments for matching.
ClearSpend can
ClearSpend cannot
Connection type
Read-only OAuth access for relevant billing messages and attachments.
Collecting supported invoices and receipts from locations a customer connects.
ClearSpend can
ClearSpend cannot
Connection type
Read-only OAuth access to supported files in selected locations.Retrieving supported transaction information for matching and reconciliation.
ClearSpend can
ClearSpend cannot
Connection type
Read-only transaction access authenticated through Plaid and the financial institution.
Sending reviewed charges and their matched invoices from ClearSpend to Xero.
ClearSpend can
ClearSpend cannot
Connection type
Scoped write access for a user-initiated, one-way sync from ClearSpend to Xero.
Supporting transaction reconciliation and returning completed records to QuickBooks.
ClearSpend can
ClearSpend cannot
Connection type
Scoped accounting access approved during the QuickBooks connection flow.Data handling
Four principles limit how customer information is collected, processed, accessed, and retained.
ClearSpend processes information required for the workflows customers enable.
Only information required for the requested task is processed.
Customer information is available only to authorized people and systems that require it.
Customer information is retained and deleted according to documented policies and applicable requirements.
AI & customer data
AI helps ClearSpend extract and structure information from invoices, receipts, and other financial documents. Your customer data does not become general AI training data.
Request subprocessor informationClearSpend does not use personal, financial, or Google user data to train its own or third-party general AI models.
When an AI provider is required for a supported workflow, only the information required for that task is processed.
AI subprocessors handle customer information according to ClearSpend's applicable contractual data-processing requirements.
Operational security
Only currently verified operational practices are included here.
Regular vulnerability scans and internal security assessments help identify potential security issues.
Internal access is restricted to authorized people and systems that require it.
Data lifecycle
An authorized user approves the integration and requested permissions.
ClearSpend processes the information required for the enabled workflow.
Information is encrypted and access is restricted during extraction, matching, and reconciliation.
Customers can disconnect integrations, revoke future access, and use available deletion controls.
Disconnecting an integration stops future access. Existing data is handled according to ClearSpend AI's Privacy Policy and applicable retention requirements.
Subprocessors
ClearSpend works with selected providers for infrastructure, authentication, integrations, AI processing, and supporting services.
Request subprocessor informationAssurance
Privacy
The Privacy Policy explains how personal data is collected, processed, transferred, retained, and deleted.
View Privacy PolicySOC 2
ClearSpend does not currently represent itself as SOC 2 certified. Contact our team for the latest status of our compliance program and available security-review materials.
Request security informationEnterprise FAQ
No. Gmail access is read-only and limited to relevant billing messages and attachments for the enabled workflow.
ClearSpend processes supported documents from connected locations. It cannot edit or delete Drive files or access unrelated locations outside the workflow.
No. Plaid provides read-only transaction information. ClearSpend cannot initiate payments or transfers.
ClearSpend can send user-approved charges and matched invoices. Nothing is pushed until a user chooses Sync to Xero.
ClearSpend can return reviewed, completed records within the supported reconciliation workflow. Actions remain limited to approved scopes.
No. ClearSpend does not use personal, financial, or Google user data to train its own or third-party general AI models.
Access is restricted to authorized people and systems that require it. Google user data has additional restrictions described in the Privacy Policy.
Personal data may be processed in the United States or other countries where ClearSpend or its subprocessors operate. Required EEA and UK transfers use recognized safeguards.
ClearSpend uses selected providers for infrastructure, authentication, integrations, AI processing, and supporting services. Request current subprocessor information for a review.
Disconnecting stops future access and synchronization. Existing data is handled under the Privacy Policy and applicable retention requirements.
Customers can use available product controls, close the account, or submit a verified deletion request.
Personal data is kept while an account is active or when required for legal or audit purposes. Verified erasure requests are completed within 90 days under the Privacy Policy.
A DPA is not currently published on this page. Contact ClearSpend to ask about current availability and procurement materials.
ClearSpend does not currently represent itself as SOC 2 certified. Contact the team for current compliance-program status and available review materials.
Request current information about integration permissions, privacy, subprocessors, retention, and the compliance program.
Use the Contact Us route and provide enough context for investigation without sending unnecessary sensitive data.
If you believe you've identified a security vulnerability or privacy concern, contact ClearSpend so the issue can be investigated.
Enterprise security review
Security, IT, legal, and procurement teams can request details on permissions, data handling, privacy, and compliance