Security & privacy
Last updated August 2026
This page describes how the application handles your financial documents today. It reflects the current implementation, not aspirational goals. Where a protection has limits, we say so.
Your documents are private by default
Uploaded files are stored in a private storage bucket that is never publicly accessible. Files are organized under a path prefixed with your account identifier, and database row-level security policies restrict every project, document, metadata, duplicate, and export record to the account that created it. One account cannot read, list, or download another account’s files.
Access requires authentication
Every project workspace requires a signed-in account. Server operations independently verify your session token before returning data or generating downloads — access is not granted by the browser alone. Temporary download links for previews and export packages are signed and short-lived (minutes), then expire automatically.
Your originals are never modified
The application never overwrites or alters your uploaded files. Proposed filenames, organized copies, and index files are generated as new derivatives. Renaming and reorganization happen only inside the export package you download.
Upload validation
Uploads are checked for file type, size, and account ownership. On the server, a file’s actual content signature is verified before it is processed, so a file whose contents do not match a supported type (PDF, JPEG, PNG, or WEBP) is rejected rather than processed.
Automated extraction is assistive, not authoritative
Document classification and metadata extraction are produced by an automated model and are presented with confidence indicators. They can be wrong. You review, correct, and approve each document before it is finalized. We do not claim guaranteed classification, legally sufficient records, tax compliance, or audit protection.
Deletion and retention
You can delete individual documents, entire projects, or your account. Deleting a project removes its documents and the corresponding stored files; if a storage cleanup step fails, the application surfaces the failure rather than silently reporting success. Export packages are retained temporarily and their download links expire; regenerate an export at any time.
What we do not do
The application is a document organization and intake tool. It is not accounting software, a transaction ledger, a tax-filing product, or a permanent financial vault. It is not a substitute for professional advice from an accountant, attorney, or adjuster.
Reporting a concern
To report a security or privacy concern, email support@fabianmeyerconsulting.com.