Security and Privacy
Documents contain sensitive data. They include business relationships, prices, and bank connections. This section describes what happens to them with us.
In Brief
- Transmission is encrypted. Access to accounting (tokens and keys) is stored encrypted.
- Documents are separated by accounts; no one can see others'. Only those you invite can view the shared folder.
- Deleted means deleted, including originals — after the trash is emptied or after seven days.
- We do not need your accounting password; integration runs via OAuth or an API key, which you can revoke at any time.
Who Can Access the Data
From our side, only the operator can access it when addressing a reported issue. The administrator sees the list of accounts, tariffs, and number of documents; they can only access the content of documents directly in the database and storage.
Processors
The processing of documents involves subcontractors:
- OpenAI — the model that reads documents. Images of sides and text of the document are sent to it for processing; according to its API terms, the data is not used for training models.
- Supabase — database and login via Google.
- Cloudflare — file storage (R2) and email reception.
- Hetzner — server on which the application, OCR, and document previews run.
- Stripe — payments. Telegram — bot, if you are using it.
The VIES register and the ARES register only receive the DIČ, and possibly the IČO or company name.
Reporting Bugs
Have you found a security flaw? Let us know before you publish it.