Security and privacy
This page answers the question behind most of the questions we get: is my business data safe with you, and who else can see it.
It is written in plain language. The binding documents are the Privacy Policy and the Terms of Service, and where this page summarises them, they win.
How your data is protected
Encrypted, and stored privately. Everything moves over encrypted connections, and your data is encrypted at rest. Receipts, invoices, and statements sit in a private store that is never publicly reachable. They are served only through short-lived signed links that expire in minutes.
Isolated to your business. Every request is authorization-checked against your business membership before a record is read or written, and that check is guarded by an automated regression suite. One business can never see another business's books. Inside your business, access is role-based, so an employee sees their own claims rather than the company ledger.
The AI works on a short leash. The agent runs under short-lived, downscoped, per-user permissions, never a master key, and it asks you to confirm before any action that moves money. The language model never touches the numbers. A deterministic engine computes, validates, and posts every entry, so an accounting record is never the output of a text prediction.
Records kept for the period that applies. Malaysia financial and tax records are generally kept for seven years. Singapore financial and tax records are generally kept for at least five years. Supporting documents follow the record they belong to. Other personal data is deleted or anonymised when it is no longer needed, unless a legal hold or another legal requirement applies.
Your data is yours. Export it at any time, both a personal copy and a full business export. Ask us to delete your account and we anonymise or delete data that is no longer needed. Where we must retain a financial record, we keep only the information needed to preserve that record. You are never locked in.
The question we get asked most
You say you share my data with third parties. Doesn't that mean my data isn't secure?
It is a fair question and it deserves a real answer rather than reassurance. "Third party" is a legal term, not a security rating, and the sentence that worries people is one we are required to write.
Three different things that get mixed up
Most of the confusion comes from treating these as the same event. They are not.
Sharing with a processor. We use another company to perform a specific job for us: storing files, sending an email, charging a card. They act on our instructions, for our purposes, under a contract. They cannot decide to do something else with the data. We also offer separate, optional analytics and advertising measurement on Groot Solo pages. Those technologies stay off unless the visitor chooses Accept all, and the Privacy Policy explains their narrower data boundary.
Selling data. Handing personal information to someone who then uses it for their own purposes, usually advertising, usually in exchange for money. The other company decides what happens next. We do not do this, and we have never done it.
A breach. Someone takes data without permission. This is a failure, not an arrangement.
Every privacy policy in the world has to disclose the first one. Almost nobody reading it separates the first from the second. So a company that uses ordinary infrastructure ends up sounding like a company selling your information, and the two are opposites.
The comparison that usually settles it
If you run a business in Malaysia or Singapore, your financial records already pass through other hands. Your accountant sees your ledger. Your bank sees every transaction. Your auditor sees the lot. When you file, your tax agent sees more than any software does.
None of that is a leak. It is how the work gets done, and each of those relationships is governed by professional duty and contract.
Software is the same shape. The question was never whether other companies are involved. It is which ones, what each can see, and what they are contractually forbidden from doing. Those are answerable questions, so here are the answers.
Who is involved, and what each one can see
We use the providers listed below. None of them receives everything, and each has a defined job.
| Provider | What it does for us | What it can see |
|---|---|---|
| Amazon Web Services | Stores files, runs compute, sends email | Receipt images, uploaded files |
| Convex | The application database | Your records and documents |
| Clerk | Signs you in | Email, name, login tokens |
| Stripe | Takes payment | Billing details |
| Google Gemini | Reads receipts, categorises expenses | Document contents you upload |
| Modal | Runs the chat assistant | Chat messages |
| Resend | Sends transactional email | Email address and message |
| Sentry | Reports crashes so we can fix them | Error traces |
| Vercel | Serves the website and app | Traffic data |
| Google Analytics | Measures Groot Solo traffic after consent | Page, campaign, market, persona, and sanitized funnel events |
| Meta Pixel | Measures Groot Solo advertising after consent, when configured | Page, campaign, market, persona, and sanitized funnel events |
Two things follow from that table that are worth saying out loud.
Your card number never reaches us. Payment details go directly to Stripe, which states it is certified to PCI DSS Level 1. We could not leak a card number we never hold.
Specialisation is the security argument, not a compromise of it. Amazon and Stripe employ large dedicated security teams and are audited continuously. A small company that decided to store card numbers itself, or write its own login system, would be substantially less safe. Using these providers is the more cautious choice, not the cheaper one.
What we never do
- We do not sell your data. Not to anyone, not in any form.
- We do not send contact details, financial records, health-check answers, pricing answers, or free-text research notes to advertising providers. Optional Groot Solo measurement loads only after Accept all, can be withdrawn through Privacy choices, and uses sanitized funnel outcomes rather than those details.
- We do not train AI models on your data. We use Google's Gemini API on a paid tier, where Google's terms state prompts and responses are not used for model training. Google retains them for up to 30 days for abuse detection. Modal deletes inputs and outputs within 7 days.
- We do not give any provider access beyond the single job it performs for us.
Where your data physically sits
In the United States, in Amazon's us-west-2 region. Not in Malaysia, not in Singapore.
We would rather say this plainly than let you discover it later. If you need data to remain in your own country for policy reasons, that is a real constraint and we are not the right fit today.
Transfers out of Malaysia and Singapore are covered by consent and by data processing agreements with each provider, which is what the PDPA in both countries requires. Sections 8, 11, and 12 of the Privacy Policy set out the detail and your rights.
What we do not claim
This is where we differ from most pages of this kind, and it is deliberate.
Groot holds no security certifications. We are not SOC 2 certified, not ISO 27001 certified, and not PCI certified. Some of the providers above hold certifications of their own, and that is a fact about them, not about us. A company that blurs the two is doing the exact thing this page exists to argue against.
We describe our practices as aligned with the PDPA in Malaysia and Singapore. We do not describe ourselves as "PDPA compliant", because compliance is a determination about a business and its records, not a badge a software vendor can hand over.
We also cannot promise nothing will ever go wrong. No one honestly can. Section 9 of the Privacy Policy says so in the formal wording.
How to check any of this
Do not take our word for it. Every provider above publishes its own privacy terms, and Section 4 of the Privacy Policy links to each one directly. If something here does not match what you find, tell us and we will fix the page.
Questions about your own data, or a request to export or delete it, go to admin@hellogroot.com. Your rights and how to exercise them are in Sections 11 through 13 of the policy.