How we handle your information
Privacy Policy
This policy explains how Second Horizon, LLC ("Second Horizon", "we", "us") handles information in connection with our software products: the hub at secondhorizon.app, our hosted web products at secondhorizon.app subdomains, and our Mac apps (together, the "Services"). It is written in plain English because that is how we would want to read it. If anything is unclear, email us and we will answer.
Our current web products are ShiftPilot, CasaLedger, Kindred Ledger, Sift, NorthStar CRM, Ledger, and Expense Horizon. Our current Mac apps are Readout and Brightness Controller. This policy applies to each of them and to any successor or renamed edition. Our marketing website at secondhorizon.studio has its own, narrower policy.
1. What we collect
Account information. When you sign up or accept an invitation we store your name, email address, the workspace you belong to, and your role in it. If you sign in with a password or a sign-in link, we store what is needed to make that work; passwords are stored only as salted hashes.
Content you put into the products. This is whatever your workspace uploads or creates: receipt images and PDFs, expenses and mileage, ledger entries and bank data, contacts and pipeline notes, documents submitted for extraction, schedules, and similar. This content may include personal information about you, your staff, your customers, or your vendors. Your workspace controls what goes in.
Billing information. If you pay us by card, Stripe handles the card details; we see the last four digits, the billing name, and invoices, not the full card number.
Technical information. Our hosting provider keeps standard server logs (IP address, request path, timing, user agent) for a short period for security and reliability. Products set cookies only for signing you in and remembering preferences. The public pages of this hub (secondhorizon.app, my.secondhorizon.app and logo.secondhorizon.app) count page views with Vercel Web Analytics, which sets no cookies, does not identify visitors, and reports only totals; the signed-in products do not run it. We do not run advertising pixels or third-party ad tracking.
Support and email. If you email us or reply to a product email, we keep the correspondence so we can help you and remember what was said.
2. How we use it
To provide the Services: storing and displaying your data, extracting fields from documents you submit, generating reports, sending the transactional email the product needs (invitations, weekly summaries, receipts inbox, sign-in links), and syncing to third-party services you have connected.
To keep the Services secure and working: detecting abuse, debugging, and measuring reliability.
To bill you and to communicate about your account.
We do not sell personal information, do not share it for advertising, and do not use your content to train public AI models. We do not add you to a marketing list because you use a product.
3. AI processing
Some products send a document you choose to process (for example a receipt photo or a page of a document stack) to a large language model provider so that fields such as vendor, date, amount, and category can be extracted. Only the document being processed is sent, together with the minimal instructions needed to read it. We use provider terms under which the provider may not use the content to train its models. Extraction results are shown to you for review; you remain responsible for confirming them.
Providers we currently use for this purpose are listed under Subprocessors below.
4. QuickBooks Online
Where a product offers a QuickBooks Online integration, a workspace owner or administrator can connect the product to a QuickBooks company by signing in with Intuit and granting access. We request the accounting scope (com.intuit.quickbooks.accounting) and nothing else.
What we read: your QuickBooks company name and identifiers, your chart of accounts, your vendors, and the purchases and journal entries the product itself created, so that we can present mapping choices, avoid duplicates, and keep the two systems in step.
What we write: purchases and journal entries that a user in your workspace has approved for sync, and later amendments or deletions to those same records when you change them in the product. We do not write anything you have not approved, and we do not touch records we did not create.
How access is stored: the OAuth tokens Intuit issues are encrypted at rest with a key held outside the database, are used only from our servers, and are never displayed to users or staff. Access is per workspace: one workspace cannot see another workspace's QuickBooks connection.
Disconnecting: you can disconnect at any time from the product's Integrations settings, or by revoking access from your Intuit account. Disconnecting revokes and deletes the tokens we hold and stops all sync immediately. Records already written to QuickBooks remain in your QuickBooks company under your control; we do not delete them.
We use QuickBooks data only to perform the sync you configured. We do not use it for advertising, do not sell it, and do not share it with anyone other than the subprocessors needed to run the Services. QuickBooks and Intuit are trademarks of Intuit Inc.
5. Where it is stored and who processes it
We host in the United States. The companies below process data on our behalf, only as needed to run the Services and under contracts that restrict their use of it:
- Vercel (application hosting, server logs, and file storage for uploaded receipts and documents)
- Neon (Postgres database hosting)
- Resend (transactional email delivery)
- Intuit (QuickBooks Online, only for workspaces that connect it)
- OpenAI, Google, and Anthropic (large language model providers used for document extraction, only for the document being processed)
- Stripe (payment processing, for paid workspaces)
7. How long we keep it
We keep your workspace's data for as long as the workspace is active. After a workspace is cancelled or closed we keep its data for 30 days so it can be exported or reactivated, then delete it from live systems; encrypted backups roll off within a further 30 days. Server logs are kept for a short period (typically under 30 days). Support correspondence and billing records are kept as long as we need them for accounting and legal purposes.
You can ask us to delete specific data or a whole workspace sooner, and we will confirm when it is done.
8. Security
Data is encrypted in transit (TLS) and secrets such as integration tokens are encrypted at rest. Each workspace's data is isolated by tenant identifier at the application layer, and every data access carries that identifier. Access to production systems is limited to the people who operate them. No system is perfectly secure; if we learn of a breach affecting your data we will notify affected workspace owners without undue delay.
9. Your choices and rights
You can ask what personal information we hold about you, ask us to correct it, export your workspace's data, or ask us to delete it, at any time, by emailing hello@secondhorizon.studio. We will confirm when it is done. Where a workspace holds information about you but you are not its owner, we may need to refer your request to the workspace owner, who controls that data.
You can opt out of non-essential product email using the link in the message. You cannot opt out of email that is required to operate your account, such as sign-in links.
10. Children
The Services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe we have, email us and we will delete it.
11. Users outside the United States
The Services are operated from and hosted in the United States. If you use them from elsewhere, your information is transferred to and processed in the United States, where privacy law may differ from your own.
12. Changes
If this policy changes, the date at the top will change with it. Material changes will be noted here in plain language and, where they affect how we use your data, communicated to workspace owners before they take effect.
13. Contact
Second Horizon, LLC, Little Rock, Arkansas, United States. Email hello@secondhorizon.studio.