Privacy policy
Grubless holds a complete picture of what you own and what you did with it. This page says exactly what we collect, who else sees it, and what you can make us do about it — in the order those questions actually get asked.
Who we are
Grubless is operated by Node Integration Pty Ltd (ABN 37 162 496 979), an Australian company, trading as Grubless. In this policy "we" and "us" mean that company.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you want to raise something under this policy, write to privacy@grubless.io.
What we collect
Everything below is collected because a function of the product needs it. We do not collect information speculatively in case it is useful later.
Because you have an account:
- Your email address, and a password, which is stored only as a scrypt hash with a per-account salt. We never hold your password and cannot recover it — a reset issues a new one.
- Session and API tokens, stored only as SHA-256 hashes. Sessions expire after 30 days, and password reset links after one hour.
- Your subscription tier and which financial years you have access to.
Because you set up an entity: the entity's name, its type (individual, company, SMSF, trust, and so on), its jurisdiction and financial-year start, and its tax settings. Where you invite someone else to an entity, we record their email address and their role.
Because you connected a source:
- Public wallet addresses you add, and the chains you track them on.
- Exchange API credentials where you connect an exchange. These are encrypted with AES-256-GCM before they are written to the database, and are never returned to any client — not to the web app, not to the CLI, not to an administrator.
- Transaction history imported from those sources: amounts, assets, counterparty addresses, timestamps and fees, plus anything derived from them — tax parcels, disposals, gains, income and the reports built on top.
- Files you upload for CSV import, and any labels or notes you add to your address book.
Because we run a service: ordinary server logs, including IP addresses, for security, rate limiting and diagnosing faults.
We never ask for a private key, a seed phrase, or a withdrawal permission, and there is no field anywhere in Grubless that would accept one. Exchange keys should be created read-only. If a page ever appears to ask you for a private key, it is not us — please report it to security@grubless.io.
A note on wallet addresses
A public blockchain address is pseudonymous on its own. Held next to your account it is not: it is linked to a named person and, in this product, to their tax position. We therefore treat wallet addresses and the transaction history behind them as personal information throughout, and give them the same protection as your email address.
We do this because it is the honest reading, not because we are certain a regulator would require it. The alternative — arguing that a public address is not personal information because it is public — is a technicality, and it is not one we want to be standing on if something goes wrong.
What we use it for
Computing your tax position, showing it to you, generating your reports, and running your account — billing, authentication, support and security. That is the whole list.
What we do not do: we do not sell personal information; we do not share it with data brokers, advertisers or analytics networks; we do not use your transaction history to train models; and we do not use it to build any product other than the one you are paying for. Your financial history is what we are hired to organise, not an asset we monetise.
Who else receives it
Running this product means contacting other services on your behalf — a block explorer cannot tell you what an address did without being told the address. Every recipient is listed here, with what actually reaches it. This table is generated from the same list the application itself uses, and a test prevents us from adding a data source, or a payment, email or error-reporting service, without adding it here.
Infrastructure
| Who | What reaches them | Why |
|---|---|---|
| Fly.io (Fly.io, Inc.)Sydney, Australia (data at rest is in the Sydney region) | Everything. Fly hosts the application, the database and the job queue, so all account and transaction data sits on infrastructure they operate. | Application hosting, database, background job queue. |
| Resend (Resend, Inc.)United States | Your email address and the contents of the message being sent — password resets, entity invitations, and account notices. No transaction data is ever put in an email. | Delivering transactional email. |
| Sentry (Functional Software, Inc.)United States | Error reports when something breaks: the fault, where in the code it happened, and the account id it happened to — a random identifier, not your email. Deliberately NOT sent: request contents, uploaded files, your transactions, holdings or figures, addresses, credentials, or your browsing within the app. | Telling us that something failed, and enough to fix it. |
| Stripe (Stripe Payments Australia Pty Ltd)Australia, with processing in the United States | When you pay: your email address, your name and billing address, and your card details, which you enter on Stripe's own page and which never reach our servers. Stripe also receives the plan or financial years being bought and your account id. None of your transactions, holdings or tax figures are sent. | Taking payment, managing your subscription, and calculating GST. |
Blockchain data
| Who | What reaches them | Why |
|---|---|---|
| Alchemy (Alchemy Insights, Inc.)United States | The public wallet addresses you add, and the chains you track them on. Alchemy sees which addresses are being queried and when. | Reading transaction history from Ethereum and other EVM chains. |
| Helius (Helius Technologies Inc.)United States | The public Solana addresses you add. | Reading transaction history from Solana. |
| HyperliquidNot disclosed by the operator | The public addresses you add, queried against Hyperliquid's own API. | Reading trading and transfer history from Hyperliquid, including bridge activity. |
| Blockstream (Esplora)Operated internationally | The public Bitcoin addresses you add. | Reading transaction history from the Bitcoin blockchain. |
| litecoinspace.orgOperated internationally | The public Litecoin addresses you add. | Reading transaction history from the Litecoin blockchain. |
| BlockchairOperated internationally | The public transparent Zcash addresses (t1…/t3…) you add. Never a shielded address or a viewing key. | Reading transparent transaction history from the Zcash blockchain. |
| BlockCypherUnited States | The public Dogecoin and Dash addresses you add. | Reading transaction history from the Dogecoin and Dash blockchains. |
| HaskoinOperated internationally | The public Bitcoin Cash addresses you add. | Reading transaction history from the Bitcoin Cash blockchain. |
| XRP Ledger public servers (xrplcluster.com, Ripple)Operated internationally | The public XRP addresses you add. | Reading transaction history from the XRP Ledger. |
| Stellar Development Foundation (Horizon)United States | The public Stellar account ids you add. | Reading transaction history from the Stellar network. |
| Koios (Cardano)Operated internationally | The public Cardano addresses you add. | Reading transaction history and staking rewards from the Cardano blockchain. |
| Mysten Labs (Sui GraphQL)Operated internationally | The public Sui addresses you add. | Reading transaction history from the Sui blockchain. |
| TronGrid (TRON DAO)Operated internationally | The public Tron addresses you add. | Reading TRX, TRC-20 and TRC-10 transaction history and staking from the Tron blockchain. |
Exchanges you connect
| Who | What reaches them | Why |
|---|---|---|
| Kraken (Payward, Inc.)United States | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade and ledger history back. Kraken already holds this data — connecting Kraken does not send them anything new about you. | Importing your Kraken trading history, at your instruction. |
| CoinSpot (Casey Block Services Pty Ltd)Australia | Nothing we choose. We authenticate with the READ ONLY API key you supply and read your own order, transfer and balance history back. CoinSpot already holds this data — connecting CoinSpot does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your CoinSpot trading and transfer history, at your instruction. |
| BinanceCayman Islands | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Binance already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Binance trading and transfer history, at your instruction. |
| OKXSeychelles | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. OKX already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your OKX trading and transfer history, at your instruction. |
| BybitUnited Arab Emirates | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Bybit already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Bybit trading and transfer history, at your instruction. |
| BitvavoNetherlands | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Bitvavo already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Bitvavo trading and transfer history, at your instruction. |
| BitstampLuxembourg | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Bitstamp already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Bitstamp trading and transfer history, at your instruction. |
| BitfinexBritish Virgin Islands | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Bitfinex already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Bitfinex trading and transfer history, at your instruction. |
| BTC MarketsAustralia | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. BTC Markets already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your BTC Markets trading and transfer history, at your instruction. |
| GateCayman Islands | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Gate already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Gate trading and transfer history, at your instruction. |
| MEXCSeychelles | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. MEXC already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your MEXC trading and transfer history, at your instruction. |
| BitgetSeychelles | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. Bitget already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Bitget trading and transfer history, at your instruction. |
| KuCoinSeychelles | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transfer and account history back. KuCoin already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your KuCoin trading and transfer history, at your instruction. |
| Crypto.com Exchange (Foris DAX)Singapore | Nothing we choose. We authenticate with the read-only API key you supply and read your own trade, transaction, deposit and withdrawal history back. Crypto.com already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Crypto.com Exchange trading and transfer history, at your instruction. |
| Swyftx (Swyftx Pty Ltd)Australia | Nothing we choose. We authenticate with the read-only API key you supply and read your own order, transfer and balance history back. Swyftx already holds this data — connecting Swyftx does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Swyftx trading and transfer history, at your instruction. |
| CoinstashAustralia | We authenticate with the read-only API key you supply and read your own account, transaction history and balances. The key is stored encrypted and is never returned to your browser. | Connecting your Coinstash account and importing its history, at your instruction. |
| Independent Reserve (Independent Reserve Pty Ltd)Australia | Nothing we choose. We authenticate with the Read Only API key you supply and read your own trade, transfer and balance history back. Independent Reserve already holds this data — connecting it does not send them anything new about you, and a read-only key cannot trade or withdraw. | Importing your Independent Reserve trading and transfer history, at your instruction. |
| CoinJar (CoinJar Australia Pty Ltd)Australia | Usually nothing at all: a CoinJar account statement is a file you download and upload here, and importing it contacts nobody. Only if you additionally supply a read-only CoinJar Exchange API key do we call CoinJar, and then only to read your current balances back so we can check them against your imported history. CoinJar already holds all of it. | Checking your imported CoinJar history against the balances CoinJar itself reports. |
| Coinbase (Coinbase, Inc.)United States | As with Kraken: we authenticate with the API key you supply and read your own history back. Coinbase already holds this data. | Importing your Coinbase trading history, at your instruction. |
Banks you connect
| Who | What reaches them | Why |
|---|---|---|
| Wise (Wise Payments Ltd and its regional entities)United Kingdom, with regional entities including Australia | Only if you connect Wise with an API token rather than uploading a statement. Nothing we choose: we authenticate with the read-only token you create and read your own Wise profiles, balances and statements back. Wise already holds this data — connecting does not send Wise anything new about you, and a read-only token cannot move money. An uploaded statement never contacts Wise at all. | Importing your Wise transactions and balances, at your instruction. |
| Up (up.com.au)Australia | Nothing we choose. We authenticate with the personal access token you supply and only read your own Up accounts, balances and transactions back. Up already holds this data — connecting it does not send Up anything new about you. Up has no read-only token: the one you supply could also recategorise and tag transactions and create webhooks, though we never use it to; it cannot move money. | Importing your Up account transactions and balances, at your instruction. |
| Plaid Inc.United States | Only if you connect a bank, card or brokerage through Plaid. You sign in to your institution inside Plaid's own window, so your bank login goes to Plaid and never to us. We send Plaid an internal identifier for you (not your name or email) to start that sign-in, then read back the accounts you chose — balances, transactions, and for a brokerage your holdings and trades. Plaid's access cannot move money. | Importing transactions, balances and investment holdings from banks and brokerages outside Australia, at your instruction. |
| Basiq Pty LtdAustralia | Only if you connect an Australian bank through Basiq. We give Basiq your email address to create your Basiq profile; you then consent to your banks on Basiq's own pages, under the Consumer Data Right, so your bank login never reaches us. We read back the accounts you chose — balances and transactions. Basiq's access cannot move money, and you can withdraw consent at any time. | Importing Australian bank transactions and balances, at your instruction. |
| Fiskil Pty LtdAustralia | Only if you connect an Australian bank through Fiskil. We give Fiskil your email address to create your Fiskil profile; you then consent to your banks on Fiskil's own pages, under the Consumer Data Right, so your bank login never reaches us. We read back the accounts you chose — balances and transactions. Fiskil's access cannot move money, and you can withdraw consent at any time. | Importing Australian bank transactions and balances, at your instruction. |
Accounting software you connect
| Who | What reaches them | Why |
|---|---|---|
| Intuit Inc. (QuickBooks Online)United States | Only if you connect QuickBooks Online. You sign in to Intuit on its own pages; we never see your Intuit password. We send the company you chose the monthly crypto journals you ask us to post — account totals per month, not individual transactions — and, if you add QuickBooks as a source, read back its income and expense transactions. Disconnecting revokes our access. | Posting crypto journals into your books, and importing your business's income and expenses, at your instruction. |
Prices and asset checks
| Who | What reaches them | Why |
|---|---|---|
| CoinGeckoSingapore | Asset identifiers and dates only — 'what was BTC worth on this day'. Never an address, an account, or a quantity you hold.No personal information | Historical and current market prices, and asset metadata. |
| GoPlus LabsOperated internationally | Token contract addresses only. A contract address identifies an asset, not a person, and your own address is never included.No personal information | Checking whether a token appearing in your wallet is a known scam or spam asset. |
DeFi protocol data
| Who | What reaches them | Why |
|---|---|---|
| Jupiter, Kamino, Marinade, Magic Eden, LoopscaleOperated internationally | Asset and protocol identifiers — a pool, a token mint, a validator, an NFT collection. Marinade's validator-bond lookup is queried by validator identity, which is public information about a validator rather than about you.No personal information | Interpreting DeFi positions correctly — pricing a liquidity receipt, recognising a staking settlement, valuing an NFT. |
CSV and bank-statement imports contact nobody. A file you upload is read, parsed and stored, and no third party is involved. If you would rather no external service saw your addresses, importing by CSV is a real alternative and this is us telling you so.
We will also disclose information where the law requires it — a court order, a properly issued notice from a regulator or law enforcement. If that happens, we will tell you, unless we are prohibited from doing so.
Overseas disclosure
Your data is stored in Australia, in Fly.io's Sydney region. That covers the database, the job queue and the backups.
Some recipients in the table above operate outside Australia — principally in the United States (Resend, Sentry, Stripe, Alchemy, Helius, BlockCypher, Stellar Development Foundation, Kraken, Plaid Inc., Intuit Inc., Coinbase) and Singapore (Crypto.com Exchange, CoinGecko). Under Australian Privacy Principle 8 we remain accountable for information disclosed overseas. By connecting a source you are asking us to contact that provider on your behalf, and the alternative is not connecting it — the product works entirely on CSV imports if you prefer. Paying for a plan sends your payment details to Stripe; the free plan involves no payment at all.
How long we keep it
While your account is open, we keep your data — that is the point of it. Tax records are also long-lived by nature: the ATO expects most records to be kept for five years after the return they support, and a capital gains position can depend on an acquisition decades earlier. Deleting your history on a rolling schedule would destroy the very thing you are paying us to maintain.
If you close your account we delete your personal information and your transaction data, except where we are required to keep something — for example, billing records retained under tax law.
Getting your data, and getting rid of it
Access and export. You can export at any time, without asking us: every report is downloadable as CSV, and the full transaction ledger with it. There is no lock-in and no export fee. Choosing Grubless is not a decision you cannot reverse.
Correction. You can edit entities, sources, categories and transactions directly in the app. If something we hold about you is wrong and you cannot correct it yourself, tell us and we will.
Deletion. Under Account in the app you can delete your data, or delete the whole account, yourself. Both take effect immediately rather than after a waiting period, and there is no undo. Deleting your data removes every source and transaction, and everything derived from them, but keeps the account so you can import again; deleting the account removes it along with every entity that only you own. You can also email privacy@grubless.io instead, and we will do it within 30 days.
One thing this cannot do, and we would rather say so: an entity somebody else also owns keeps existing when you delete your account. It is their record too, and closing your account is not our authority to destroy theirs. Your access to it ends.
Complaints. Write to privacy@grubless.io and we will respond within 30 days. If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au — that route exists whatever we say, and we would rather you knew about it.
If something goes wrong
We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suspect a breach we will assess it within 30 days, and where it is likely to result in serious harm we will notify both you and the Australian Information Commissioner as soon as practicable.
How we secure the data in the first place, and how to report a vulnerability you have found, are on the security page.
Cookies
One cookie, and it is the session that keeps you signed in. It is HttpOnly, Secure and SameSite-restricted, so it cannot be read by scripts and is not sent from other sites.
There are no advertising cookies, no tracking pixels and no third-party analytics on this site or in the app. That is why you have not been asked to dismiss a consent banner: there is nothing to consent to. Your theme preference is stored in your own browser and never sent to us.
We do run error monitoring (Sentry, listed above), and it is worth being precise about the difference. It records that something broke — the fault, the line of code, and the account ID it happened to. It does not record what you did, what you looked at, or what you hold. There is no behavioural tracking and no profile of you anywhere in it; it exists so a failure reaches us without you having to report it.
Changes to this policy
If we change this policy materially — a new category of information, a new recipient, a new purpose — we will tell account holders by email before it takes effect, not by silently updating a date at the top of a page. The version and effective date are shown on this page so you can tell what you agreed to.