Private testing · Version 2026-09-21-private-pilot-v1

Your information
in BEV.

This notice covers BEV’s approved private pilot. BEV operates under the project name Seamless Inc., based in Victoria, Australia. Contact contactbirdseyeview@gmail.com.

What we collect and why

We receive your account identifier, email and sign-in details needed to create and secure your BEV account. You may enter accounts, transactions, commitments, goals, assets, debts, notes and corrections. We use this information for the views and calculations you request.

If you connect a bank, we receive the account details, balances and transaction records covered by your separate sharing choice. We process these records to organise activity, find recurring patterns and calculate forecasts. Transaction descriptions can reveal sensitive personal matters: choose carefully which accounts to share and avoid unnecessary detail in notes.

We also retain consent choices, security and request metadata, and messages you send to support. Refusing bank access leaves manual features available. Without sign-in information we cannot provide a personal account; you can still explore the sample. We do not sell financial information or use it for advertising.

Bank sharing is a separate choice

Biza Pty Ltd provides openfeed. Your consent there controls its bank collection; a separate instruction controls disclosure to BEV. BEV is not represented as an accredited CDR recipient or a CDR representative. Once disclosed to BEV, information is handled under this notice and applicable Australian privacy obligations.

Review openfeed’s terms and provider policy information during its consent flow. Its independent records and retention are governed by that provider’s arrangements. In BEV, disconnect to stop syncing and remove our access credentials. Also withdraw BEV sharing in openfeed. Previously imported BEV records remain until you delete them; BEV deletion does not delete your independent openfeed or bank account.

Storage and service providers

BEV uses a backend, not just your device. Authorised services and administrators can access records where needed for the service, security, support or deletion. This is not an end-to-end encrypted service in which only you can read all records.

  • Google Firebase and Google Cloud: financial database, file storage, calculations and background tasks are configured in Sydney, Australia. Firebase Authentication processes identity data in the United States. App Check/reCAPTCHA Enterprise, hosting and operational security services use Google’s global infrastructure; operational logs are not restricted to Australia. Other processing and support can involve countries listed in Google’s Firebase privacy and location information. An Australian database does not make all service processing Australia-only.
  • openfeed/Biza: receives your bank consent and provides the data you choose to share. BEV stores encrypted access credentials to refresh authorised records. BEV does not receive your bank password.
  • Replit: hosts the browser preview and its application assets. Browser requests expose connection metadata such as IP address to its hosting services. Financial API requests go directly to BEV’s Firebase backend. Replit hosting is not represented as Australian-only; see Replit’s privacy information.
  • Google Gmail: handles messages sent to our support address. Include only what is needed; never email bank passwords, verification codes or full account details. The inbox is not represented as Australian-only.

Browser financial views are held in memory, without a persistent financial database. Sign-in uses browser-session storage. App Check assesses browser integrity; BEV does not send bank transactions to reCAPTCHA. If you export records, the destination’s storage and privacy controls apply. Anyone who can access your unlocked browser may see your account; sign out when finished.

Features disabled in this pilot

External OpenAI processing, AI receipt extraction, document uploads and automated financial actions are disabled. Your bank records are not sent to OpenAI by this configuration. Enabling external AI later requires a published explanation of the actual data, processing locations and retention, plus your separate choice. Preview analytics and crash-report collection are not enabled. This notice does not pre-authorise future processors.

Sharing with another person

Your personal space is private to you and authorised service processing. Household sharing requires your explicit selection of accounts and recipients with appropriate authority. Do not share someone else’s records without permission. Revocation blocks further access through BEV; it cannot recover exported copies or screenshots. Private notes and attachments are not automatically shared with an account.

How long records remain

Account records, imported history, corrections, notes and saved results remain for your account until removed using the applicable deletion controls. Disconnecting a bank alone does not delete its history.

Export downloads stop after 24 hours; export files become eligible for cleanup after one day. Completed request/job records and ordinary operational logs use 30-day retention. Minimal app command audit records expire after one year. Google’s mandatory infrastructure audit logs have separate provider retention. Obsolete calculation records are eligible for cleanup after 30 days, while current views and saved results remain.

Backups and point-in-time recovery cover seven days. Completed deletion records are kept for 30 days to prevent deleted data reappearing during recovery; the separate deletion ledger has an additional seven-day soft-deletion window. Pending deletion records remain until resolved. Cleanup runs asynchronously and may occur after the eligibility date.

Support messages are used to resolve your request. Ask us to remove them when no longer needed; we will explain any remaining legal or security need. Bank and openfeed records follow their own retention and deletion processes.

Access, correction, deletion and complaints

Use BEV’s export, correction and deletion controls, or contact contactbirdseyeview@gmail.com. We verify requests proportionately. Corrections in BEV do not alter your bank’s source records; source-data disputes should also go to your bank or openfeed. Account deletion stops BEV account access and processing, then removes records through a tracked cleanup process. External failures may delay completion. See deletion instructions.

For a privacy complaint, explain what happened and the outcome you seek. We will investigate and explain our response or any restriction on your request. openfeed privacy/CDR complaints can be sent to complaints@biza.io. You can also consult the Office of the Australian Information Commissioner’s complaint process where applicable.

We will publish material changes and obtain fresh permission where required before introducing new uses or recipients. You can request an accessible copy by email.

Effective 21 September 2026. Version 2026-09-21-private-pilot-v1.
BEV · A Seamless Inc. project · Victoria, Australia.