AsOfPrivacy Policy

Privacy Policy

Last updated: 9 October 2026

1. Introduction

This Privacy Policy explains how AsOf ("we", "us", "our") collects, uses, stores, and protects personal data when you use the AsOf platform. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

AsOf is the data controller for personal data processed through the platform. For data enquiries, contact us at jono@asof.xyz.

3. Data We Collect

3.1 Account Data

  • ●Email address (used for authentication, communications, and account recovery).
  • ●Name, if provided during registration.
  • ●Connected-application grants, account access entitlements and scan-spending settings.

3.2 Workspace Data

  • ●Saved wallet addresses and labels, scan requests and results, and connected accounting company identifiers. Historical workspace records may remain until deletion is requested.
  • ●Blockchain wallet addresses submitted for scanning.

3.3 Scan Data

  • ●Scan requests, dates, and parameters.
  • ●Scan Results (token balances, USD valuations, verification metadata).

3.4 Technical Data

  • ●IP address, browser type, and device information (collected via server logs).
  • ●Session data and authentication tokens.

3.5 Connected Accounting Data (AsOf Accounting)

If you connect QuickBooks Online (or Xero) to AsOf Accounting, AsOf has read-only access to the company you authorise. It cannot create, change, or delete anything in your accounting file. We store only:

  • ●The OAuth tokens that let AsOf read that company, encrypted at rest (AES-256-GCM). They are never shown to you, to your browser, to Google Sheets, or in logs.
  • ●The company's display name, and its QuickBooks company identifier (realm ID), which is stored encrypted.
  • ●Connection metadata: which AsOf entity connected it, when, its status, and usage counts used for rate limiting.

AsOf does not store the accounting records and reports you request (accounts, invoices, bills, reports and so on). They are fetched from QuickBooks when you ask, shown to you in AsOf, or returned to an AsOf-enabled Google Sheet you have bound to your entity, and are not kept by AsOf afterwards. Once data is in your Google Sheet it is held by Google under your own Google account and settings.

Who can see it: the AsOf account that connected the company, and Google Sheets workbooks explicitly bound to that account. Anyone who can use the enabled workbook can read that company, so share workbooks carefully. We do not read or mirror QuickBooks user roles.

Separate from the LLM connector: the optional AsOf connector for LLMs (such as Claude) reads blockchain holdings. It does not have access to your QuickBooks or Xero data, and connecting one does not connect the other.

3.6 Google User Data (AsOf for Google Sheets™ add-on)

The AsOf for Google Sheets™ add-on asks Google for three permissions: to see and edit only the spreadsheet it is opened in, to show the AsOf sidebar, and to connect to AsOf's own service at mcp.asof.xyz. It does not read your Google account email, your contacts, or any other file in your Google Drive™.

Data accessed. In the spreadsheet you open AsOf in, the add-on reads only:

  • ●the spreadsheet's ID, the ID of the tab, and the address of the cell you insert a formula into;
  • ●the values of the cells you choose as inputs to an AsOf formula, such as a range of wallet addresses, and the arguments of AsOf formulas;
  • ●the spreadsheet's timezone, used as the default reporting timezone.

It writes only AsOf formulas and their results into cells you choose, and asks before replacing a cell that already has content. It saves a connection credential and your reporting-timezone choice in Google's add-on storage for that spreadsheet.

How we use it. Only to provide the add-on's features: connecting the spreadsheet to your AsOf account, answering the formulas you enter (wallet holdings, historical prices, block numbers and dates), quoting and running the wallet scans you approve, and showing your scan history and credits in the sidebar.

Sharing. We do not sell Google user data or share it with advertisers or data brokers. Wallet addresses and dates from your formulas are sent to the blockchain data providers listed in section 5, solely to look up those balances and prices; they receive no other spreadsheet content and no personal identifiers. Our infrastructure providers (Google Cloud, Supabase) store and process this data for us under their data processing agreements. We may also disclose it where required by law.

Protection. All requests travel over HTTPS. The add-on can only contact mcp.asof.xyz. Stored data is isolated per AsOf account in a database with row-level security, and the spreadsheet's connection credential is stored on our side only as a hash.

Retention and deletion. AsOf stores the link between a spreadsheet ID and your AsOf account, and each wallet-holdings request with its spreadsheet, tab and cell, for as long as your account is in use, so results and history can be shown again. One-time sign-in links expire after 15 minutes. Other spreadsheet contents are not stored. To delete this data, email jono@asof.xyz; we delete it within one calendar month. You can remove the add-on's access to your Google account at any time at myaccount.google.com/connections.

AI and machine learning. We do not use Google user data to develop, improve or train AI or machine-learning models, and we do not transfer it to third-party AI services.

Limited Use. AsOf's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Sheets™ and Google Drive™ are trademarks of Google LLC.

3.7 Data We Do Not Collect

  • ●We do not collect private keys, seed phrases, or transaction signing credentials.
  • ●We do not collect personal identification documents.
  • ●We do not access or control funds in any wallet.

4. Legal Basis for Processing

We process personal data under the following legal bases:

  • ●Contractual necessity (Art. 6(1)(b)): Account data, workspace data, and scan data — necessary to provide and manage the service.
  • ●Legitimate interests (Art. 6(1)(f)): Technical data — for security, debugging, and service improvement.
  • ●Legitimate interests (Art. 6(1)(f)): Communications — for service updates and support.

5. Data Sharing

We do not sell personal data. We share data only in the following circumstances:

  • ●Blockchain data providers: Wallet addresses are transmitted to third-party blockchain data providers solely to perform balance queries. These providers receive wallet addresses only — no account data or personal identifiers are shared.
  • ●Infrastructure providers: We use third-party cloud infrastructure and authentication services. These providers process data under their own data processing agreements. They include Google Cloud (hosting of the AsOf Accounting service, in London), Supabase (database and authentication), and Vercel (website hosting).
  • ●Accounting providers: When you connect QuickBooks Online, AsOf exchanges data with Intuit (the provider of QuickBooks) to authorise access and read your company's data, and with Xero if you connect Xero. AsOf sends them only what is needed for that request. Blockchain data providers never receive your accounting data.
  • ●Google Sheets: If you use AsOf in Google Sheets, the data you request is delivered into your own spreadsheet, which Google processes under your account.
  • ●Payment processor: A third-party payment processor handles billing. We do not store credit card details.
  • ●Legal obligations: We may disclose data where required by law, regulation, or court order.

6. International Data Transfers

Some of our infrastructure providers may process data outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions, as required under UK GDPR.

7. Data Retention

  • ●Account data: Kept while your account is in use. Email jono@asof.xyz to request deletion; cancellation alone does not automatically delete the account.
  • ●Scan Results: Kept for retrieval while your account is in use. Request deletion at jono@asof.xyz; cancellation does not automatically delete scan evidence.
  • ●Technical logs: Retained for a maximum of 12 months.
  • ●QuickBooks and Xero tokens: When you disconnect a company in AsOf, AsOf deletes the stored tokens for it straight away and asks the provider to revoke access. That revocation request is skipped if another AsOf entity has separately connected the same company, because revoking would cut that entity off, and it can fail if the provider is unavailable. In either case AsOf's own copy of the tokens is still deleted, and you can revoke AsOf's access at any time inside QuickBooks or Xero. Please disconnect companies before deleting your account; if you did not, email us and we will remove the remaining connection data within one calendar month.
  • ●Connection records: The company display name, encrypted company identifier and connection history are kept until you ask us to delete them. Email jono@asof.xyz and we will delete them within one calendar month. AsOf does not currently delete them automatically.
  • ●Accounting records you read: Not retained by AsOf (see 3.5). Structured service logs record request outcomes, provider reference IDs and status codes, never tokens or accounting data, and follow the 12-month log retention above.

Account closure and data deletion currently require a request to jono@asof.xyz. We will confirm the scope and timing, including connection records and any billing records we must retain by law. Cancelling a subscription is separate from requesting deletion; there is no automatic 90-day purge of all records.

8. Your Rights

Under UK GDPR, you have the following rights:

  • ●Access: Request a copy of the personal data we hold about you.
  • ●Rectification: Request correction of inaccurate or incomplete data.
  • ●Erasure: Request deletion of your personal data (subject to legal retention obligations).
  • ●Restriction: Request that we restrict processing in certain circumstances.
  • ●Portability: Request your data in a structured, machine-readable format.
  • ●Objection: Object to processing based on legitimate interests.
  • ●Withdraw consent: Where processing is based on consent, withdraw at any time.

To exercise any of these rights, contact us at jono@asof.xyz. We will respond within one calendar month.

9. Security Measures

We implement appropriate technical and organisational measures to protect your data, including:

  • ●Row-level security enforcing tenant isolation at the database level.
  • ●Authentication with session management.
  • ●CORS origin allowlisting on API endpoints.
  • ●No storage of private keys, seed phrases, or wallet-signing credentials.
  • ●API key and secret redaction from error responses and logs; logs never contain provider tokens or accounting data.
  • ●Read-only provider access, encrypted storage of provider tokens and QuickBooks company identifiers, and responses containing accounting data marked as not cacheable.
  • ●HTTPS encryption in transit for all data.

10. Browser Storage and Cookies

AsOf stores your sign-in session in your browser's local storage so you can stay signed in across Billing, Accounting, Google Sheets connection pages, and OAuth flows. We do not use marketing, analytics, or tracking cookies.

11. Children

The platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect.

13. Complaints

If you are not satisfied with our handling of your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

14. Contact

Email: jono@asof.xyz

© 2026 AsOf. All rights reserved.