Last Updated: June 2026
Privacy Policy
SabiCFO is built on the principle that your financial data belongs to you — not to us, not to advertisers, and not to any third party. This document explains exactly how your data moves through our system.
Overview
SabiCFO ("we", "us", "our") is a conversational finance platform built for African businesses. This policy explains what data we collect, how we process it, and the protections we put in place to keep your financial information private and secure.
By using SabiCFO — including via WhatsApp message ingestion or the web dashboard — you agree to the practices described here. If you do not agree, please discontinue use and contact us to request data deletion.
Data Ingestion via WhatsApp
SabiCFO receives transaction messages you send through the Meta WhatsApp Business API network layer. When you send a message such as "bought fuel 5k" or "client paid 200k favsys", that message text is routed securely to our system over an encrypted HTTPS transport channel.
We do not intercept, record, or store general WhatsApp conversations. Only messages explicitly directed to your linked SabiCFO number are received and processed. Your broader WhatsApp inbox, contacts, and media remain entirely outside our system.
We collect: — The text content of messages you send to SabiCFO — The WhatsApp number used to send each message (to identify your account) — The UTC timestamp of message receipt
AI-Assisted Financial Parsing
To extract structured financial data from your natural-language messages, SabiCFO forwards message text payloads to a transient LLM inference pipeline (currently powered by Google Gemini AI). This process is designed with strict privacy constraints:
— Message payloads are transmitted over encrypted channels exclusively to parse financial amounts, categories, and descriptions. — Inference is stateless and transient: no message content is retained by the AI provider beyond the duration of a single inference call. — Your messages are never used to train, fine-tune, or improve any underlying language model. — The structured output (amount, category, description, workspace) is stored in our database. The raw message text is discarded after parsing.
We do not use AI to profile you, make credit decisions, or derive inferences beyond the explicit financial classification required to run the product.
Multi-Tenant Isolation & Zero Cross-Contamination
SabiCFO supports multiple isolated financial workspaces under a single account — for example, Personal, Favsys, Lighthouse, and Reckon Lens. Each workspace operates as a fully independent tenant partition.
We enforce absolute Zero Cross-Contamination between workspaces: — Financial records are anchored exclusively to the workspace identifier present at the time of logging. — Workspace boundaries are enforced at the database query layer via Row-Level Security (RLS) policies in Supabase. — No transaction, balance, or insight from one workspace can appear in, or influence, any other workspace's calculations. — Workspace data is never aggregated or co-mingled in analytics, AI context, or reporting pipelines.
Switching between workspaces in the dashboard gives you a fully isolated view with zero leakage from adjacent profiles.
Data Storage & Security
All structured financial data is stored in a Supabase PostgreSQL database hosted on infrastructure with at-rest encryption. Data in transit is encrypted via TLS 1.2 or higher at all points in the request chain.
Access to your data is restricted to: — Your authenticated account session — Automated system processes operating under your account context — SabiCFO engineering staff, only when required to diagnose production issues, subject to internal access controls and audit logs
We do not sell, license, rent, or trade your financial data to any third party. Your data is never used for advertising purposes.
Your Data Rights
You retain full ownership of all financial records logged through SabiCFO. You may exercise the following rights at any time from within the product interface or by contacting us directly:
— Access: View all transactions and workspace data associated with your account. — Correction: Edit or amend any incorrectly logged transaction directly from the dashboard. — Deletion: Permanently and irreversibly delete individual transactions, entire workspace histories, or your full account from the interface with immediate effect. — Portability: Request a structured export of your financial records in a machine-readable format.
Deletion requests are executed immediately. We do not retain soft-deleted records in backup snapshots beyond 30 days.
Third-Party Services
SabiCFO integrates with the following third-party providers to operate the product:
— Meta (WhatsApp Business API): Message ingestion transport. Governed by Meta's own privacy policies. — Google (Gemini AI): Transient LLM inference for financial parsing. No data retention beyond inference. — Supabase: PostgreSQL database hosting and authentication infrastructure. — Vercel: Web application hosting and edge delivery.
We are not responsible for the independent data practices of these providers. We select infrastructure partners on the basis of data minimization and security posture.
Contact
For privacy questions, data deletion requests, or concerns about how your information is handled, contact us at:
privacy@sabicfo.com
We will respond within 5 business days.
© 2026 SabiCFO. Know your money. Always.