RecovraBack to platformGet Started
Legal

Privacy Policy

What we collect, why, where it lives, and the controls that keep each organization's data isolated.

Last updated 2026-09-13 · Operated by Recovra

1. Who this covers2. Data we collect3. How we use it4. Document transcription by AI models5. Who we share it with6. Security7. Retention8. International transfers9. Your rights10. Cookies11. Contact and changes

1. Who this covers

This Privacy Policy explains how Recovra (“we”) handles personal data when you visit our websites, create an account, or use the Recovra platform (the “Service”). For data inside a customer’s workspace (invoices, contracts, shipment records) we act as a processor on the customer’s instructions; for account, billing and website data we act as a controller.

2. Data we collect

  • Account data: name, work email, hashed password or sign-in tokens, organization membership and role.
  • Customer Data you upload: invoices, rate sheets, contracts and operational files. These are commercial records and may incidentally contain names, addresses or contact details of vendor or shipping personnel.
  • Activity and audit logs: who uploaded, verified, approved, submitted or closed each item, with timestamps. These logs exist so financial decisions are traceable and cannot be disabled by users.
  • Technical data: IP address, browser and device information, and diagnostic logs needed to run and secure the Service.

We do not sell personal data and do not use Customer Data to train machine-learning models.

3. How we use it

  • To provide the Service: store documents, compute findings, run approval workflows and display dashboards to authorised members of your organization.
  • To secure the Service: authentication, tenant isolation, abuse and fraud prevention, incident investigation.
  • To operate our business: billing, support, service notices and legally required record-keeping.
  • With your consent or where permitted: product updates and marketing, which you can opt out of at any time.

4. Document transcription by AI models

When a customer enables PDF transcription, the PDF is sent to the configured model provider (Anthropic or OpenAI, under our API agreement with them) solely to convert the printed content into structured rows. The provider name, model and read confidence are stored with the document, and findings derived from transcribed rows are marked for human verification. API-based providers process the content to return the result and, under their API terms, do not use it to train their models. Spreadsheet uploads are parsed entirely within our infrastructure and never leave it.

5. Who we share it with

  • Infrastructure providers: database, authentication and file storage on Supabase (AWS us-east-1, United States); application hosting and edge network on Vercel (United States).
  • Model providers: only for PDF transcription as described above, only when enabled by the customer.
  • Email and payment processors when those features are enabled for your account.
  • Authorities where required by law, after review and, where lawful, notice to you.

We do not share one customer’s data with another. Every business object is scoped to a single organization and enforced with database row-level security.

6. Security

Data is encrypted in transit (TLS) and at rest. Files live in a private bucket with per-organization folder policies; database access is governed by row-level security and role checks; only owners and admins can delete records. Secret keys are never shipped to browsers. Every automated decision and every human workflow step is written to an audit log. Our database provider takes daily backups, and restores are tested as part of our operations runbook. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.

7. Retention

Customer Data is retained while your organization uses the Service and deleted from production within 60 days of account closure or a verified deletion request, subject to backup rotation (up to 30 additional days) and legal obligations. Audit logs relating to financial approvals may be retained for up to 7 years where required for accounting or tax purposes, in which case they are restricted to that purpose.

8. International transfers

Our infrastructure is located in the United States. If you access the Service from other regions, your data is transferred to and processed there. Where required we rely on standard contractual clauses or an equivalent lawful mechanism and will enter into a data processing agreement on request.

9. Your rights

Depending on where you live you may have rights to access, correct, delete, restrict or port your personal data, or to object to certain processing. Workspace members can update their own profile and password in Settings; organization admins can remove members and delete documents. For anything else, or if you are a vendor employee whose details appear in a customer’s invoice, contact us and we will respond within 30 days or refer the request to the relevant customer where we act as processor.

10. Cookies

We use strictly necessary cookies to keep you signed in and protect against cross-site request forgery. We do not run third-party advertising trackers. Aggregate, privacy-preserving analytics may be enabled by the hosting platform to measure page performance.

11. Contact and changes

Privacy questions and requests: alaidaroosawad@gmail.com. We may update this policy; material changes are announced inside the Service or by email, and the date at the top reflects the latest revision. See also our Terms of Service.

© 2026 RecovraTerms of ServicePrivacy Policyalaidaroosawad@gmail.com