Privacy Policy
Last updated: 6 July 2026
What we store
- Your account: email address and a hashed password.
- Your organization's settings: name, inbound address, accountant email addresses, sending preferences.
- The documents you forward or upload, and the emails that carried them (sender, subject, body, attachments), so nothing is ever lost in processing.
- The monthly zip archives and summaries that were sent to your accountant, so you can re-download them.
- Operational logs (delivery attempts, failures) needed to run the service reliably.
Where it lives
Data is stored with Supabase (Postgres and object storage) in the European Union (AWS Paris, eu-west-3), encrypted at rest and in transit. Emails are received and sent through Resend, which processes email content to deliver it under GDPR data-processing terms.
Who can see it
Your documents are visible to the members of your organization and to the accountant addresses you choose to send them to. The platform operator (administrator) is technically able to access tenant data for support and abuse handling, and misrouted email addressed to nonexistent addresses is visible only to the operator. We do not sell data, run advertising, or share data with anyone beyond the processors named above.
How long we keep it
As long as your account exists. If you delete your organization, it is deactivated immediately and permanently purged — documents, emails, archives and account — after a 30-day grace period (in case the deletion was a mistake). You can download your documents as a zip (with a metadata index) at any time before that; for a copy of any other data we hold, contact the operator (see “Your rights”).
Your rights
You can access, export, correct and delete your data yourself from the app. For anything you cannot do yourself (or to exercise other GDPR rights), contact the operator at the address in the footer and we will respond within 30 days.