Data security and hosting

Last updated: July 24, 2026

Hosting

Website and app (frontend): Vercel, in the United States.

API (backend) and PostgreSQL database: Render, Oregon (US-West) region, United States.

Encryption

In transit: all communication is encrypted via HTTPS / TLS 1.2 or higher.

At rest: the PostgreSQL database is encrypted with AES-256 by Render, as are its replicas and its backups. Storage disks and their daily snapshots are encrypted at rest as well.

AI processing

To extract data from your documents, their content is sent to OpenAI through its API. OpenAI does not use API data to train its models and keeps it only for as long as strictly necessary to process the request.

Document retention and deletion

The documents you upload are not archived. They are written to temporary storage for the duration of the extraction, then deleted as soon as processing ends — at the latest 30 minutes afterwards, and in any case within 2 hours if a job fails. Only the extracted accounting data (vendor, amounts, journal entries) is kept in the database so that you can find it again and export it.

You can request deletion of your documents and account at any time by writing to badreddine@comptyx.com.

Backups

The database is backed up automatically every day by Render, encrypted at rest, with point-in-time recovery. Backups are retained for 7 days.

The export files you generate are deleted from the server 24 hours after they are created.

Access control

Access to production data is restricted on a least-privilege basis: only the publisher, the service's sole administrator, has access, and only for technical operation and support.

Access to your account is password-protected; we recommend a unique, strong password.