Privacy principles
Your financial information is private.
Black Scarab is designed around data minimization, explicit authorization, and separation of identifiable practice data from aggregate intelligence.
Private by default
Practice inputs and valuation results are never published. Row-level authorization prevents one account from accessing another account’s practices, reports, or uploads.
Benchmark contribution is opt-in
The setting to allow anonymized practice data to contribute to Black Scarab benchmarks defaults to off. Identifiable data is never sold.
Minimal operational logging
Complete financial payloads are not written to application logs. Security and audit events retain only the metadata required for safe operation.
Local MVP fallback
Without a configured database, the unauthenticated questionnaire saves a versioned draft in your browser. Clearing site storage removes that local draft.
Control
Account architecture includes export and deletion paths. Production deployments should connect these flows to verified identity, retention, and backup policies.