Privacy Policy
Last updated: August 30, 2026
KeyGlance (“KeyGlance”, “we”, “us”) makes software for Canadian accounting firms. It reads the client paperwork a firm uploads — slips, receipts, statements — and turns it into data the firm’s tax software can import. This policy explains what information passes through KeyGlance, where it goes, and what we will and will not do with it. Questions go to support@keyglance.ai.
Two kinds of information
Your firm’s information — the account details, billing records, and usage data created when your firm uses KeyGlance. We are responsible for this information.
Your clients’ information — the documents your firm uploads, and the values read from them. These belong to your clients and are entrusted to your firm; under Canadian privacy law (PIPEDA) your firm remains accountable for them, and KeyGlance processes them only on your firm’s instructions to provide the service.
What we collect
- Account information: your name, work email, password (stored only as a hash), an optional profile photo, and your firm’s name and settings.
- Uploaded documents: the tax paperwork your firm uploads. These routinely contain sensitive personal information — names, Social Insurance Numbers, income, medical and donation records.
- Extracted data and the audit trail: the values read from each document, every edit and approval, and who made it and when. The audit trail exists so that years later a firm can answer “who entered this number”.
- Billing information: processed by Stripe. Card numbers go directly to Stripe and never touch our servers; we keep records of what was purchased.
- Technical data: server logs and error reports, used to keep the service running and secure.
What we use it for
To provide the service: reading documents, flagging low-confidence values for review, building import files, billing, support, and security. That is the list. We do not sell personal information, we do not use it for advertising, and we never use your clients’ documents or the values read from them to train AI models — ours or anyone else’s.
Where the data lives, and where it is processed
Documents and data are stored at rest in Canada (our database and file storage are hosted in the Canadian ca-central-1 region).
To read a document, its content is sent to Anthropic, our AI provider, and processed in the United States. This happens under a zero data retention arrangement: Anthropic does not store the document or the response after processing completes, and does not use either for training. While a document is being processed in the United States it is subject to United States law.
Wording your firm may use with clients: “Documents you provide may be processed by software that uses a third-party AI service located in the United States. The service does not keep your documents after processing and does not use them for training. Your documents are otherwise stored in Canada.”
Service providers
Each provider receives only what its job requires:
- Anthropic (United States) — AI document reading, under zero data retention.
- Supabase (Canada) — database and document storage.
- Stripe — payment processing.
- Vercel — application hosting and delivery.
- Sentry — error monitoring, so failures are found and fixed.
How long we keep it
- Documents and extracted data are kept while your firm’s account is active, or until your firm deletes them. Deleting a client permanently removes their documents from storage.
- The audit trail is kept for the life of the account — it is the record a reassessment asks for.
- Billing records are kept as long as tax and accounting law requires.
- The AI provider keeps nothing: under zero data retention there is no copy to delete.
Security
Data is encrypted in transit and at rest. Every firm’s data is isolated from every other firm’s at the database layer. Access within a firm follows the roles the firm assigns. Two-factor authentication is available on every account. Every change to extracted values is recorded in the audit trail.
What KeyGlance never does
KeyGlance never files or transmits anything to the Canada Revenue Agency. There is no e-file capability in the product, by design. The output of KeyGlance is a file your firm reviews and imports into its own tax software.
Your firm’s responsibilities
By uploading documents, your firm confirms it has the authority and any consents needed to do so, and that using a service processing data as described here is consistent with its obligations to its clients. The wording above is provided so informing clients does not require inventing it.
Access, correction, and deletion
Firms can access, correct, and delete their data directly in the product. For anything the product does not expose, or to close an account and have its data deleted, write to support@keyglance.ai. Individuals whose information was uploaded by a firm should contact that firm first — it controls the relationship — and we will support the firm in responding. Complaints about our handling of personal information can also be directed to the Office of the Privacy Commissioner of Canada.
If something goes wrong
If a breach of security safeguards creates a real risk of significant harm, we will notify affected firms and the Privacy Commissioner as PIPEDA requires, without unreasonable delay.
Changes to this policy
If this policy changes in a way that matters, firms are notified in the product or by email before the change takes effect. The date at the top is the date of the current version.
