Data security and hosting
Last updated: July 24, 2026
Where your data is hosted, how it is encrypted, how long it is kept, and who can access it.
Hosting
Website and app (frontend): Vercel, in the United States.
API (backend) and PostgreSQL database: Render, Oregon (US-West) region, United States.
Encryption
In transit: all communication is encrypted via HTTPS / TLS 1.2 or higher.
At rest: the PostgreSQL database is encrypted with AES-256 by Render, as are its replicas and its backups. Storage disks and their daily snapshots are encrypted at rest as well.
AI processing
To extract data from your documents, their content is sent to OpenAI through its API. OpenAI does not use API data to train its models and keeps it only for as long as strictly necessary to process the request.
Document retention and deletion
The documents you upload are not archived. They are written to temporary storage for the duration of the extraction, then deleted as soon as processing ends — at the latest 30 minutes afterwards, and in any case within 2 hours if a job fails. Only the extracted accounting data (vendor, amounts, journal entries) is kept in the database so that you can find it again and export it.
You can request deletion of your documents and account at any time by writing to badreddine@comptyx.com.
Backups
The database is backed up automatically every day by Render, encrypted at rest, with point-in-time recovery. Backups are retained for 7 days.
The export files you generate are deleted from the server 24 hours after they are created.
Access control
Access to production data is restricted on a least-privilege basis: only the publisher, the service's sole administrator, has access, and only for technical operation and support.
Access to your account is password-protected; we recommend a unique, strong password.