Security & retention

Your invoice data has an expiry date.

Invoice files and results are kept for a limited time. Billing records, service records, accounting-entity discovery IDs, and fingerprints used for duplicate detection follow separate retention rules below.

UploadUpload directly to private storage

Your file goes straight to private storage without passing through the public API server.

24 hoursSource + processing intermediates

Kept in private storage with a 24-hour default expiry. Physical cleanup can follow expiry.

7 daysStructured result

Seven days from completion by default. The API response gives the result-expiry timestamp.

On requestDelete a document

API access ends and stored results are cleared. File deletion is attempted immediately and retried if needed.

Delete a document through the API

Source and intermediate expiry is measured from each stored object's creation; unconfirmed uploads expire 24 hours after document creation. Result expiry ends API access to the result; physical cleanup can follow while processing recovery or storage-deletion retries complete. Document deletion also clears document fields. The separate records and provider-log limits below still apply.

Never in application logs

Invoice content is never written to normal application logs.

  • Source bytes and raw OCR text
  • Invoice values: totals, vendor names, invoice numbers
  • Extracted invoice content
  • Full prompts and model responses
  • Signed upload URLs and tokens
  • Provider response bodies

Service diagnostics and platform logs

Application logs and Sentry receive service diagnostics that exclude invoice content. Their identifiers can still relate to your account. These diagnostics include:

  • Account, document, and run identifiers with statuses
  • Request IDs and typed error codes
  • Processing timings and page counts

Vercel's separate platform logs may retain request URLs, query parameters, browser and referrer information, callback destinations, and related error logs. These can contain sensitive data. Document deletion does not delete those logs; they follow Vercel's separate retention policy. See the Privacy Notice's retention and deletion details.

Retention beyond invoice content

Service records have their own retention rules. Deleting a document does not remove every record associated with your account.

Operational recordsApproximately 90 days
Processing records and service diagnostics generally expire after 90 days. Idempotency records last 7 days. Security records may be kept longer where required.
Duplicate fingerprintsUntil explicit deletion
Tenant-keyed document and invoice-identity fingerprints are pseudonymous, not anonymous or plaintext invoice identifiers. Explicit document deletion removes them from duplicate matching. They have no automatic expiry. Disabling duplicate detection on a submission skips matching and stores no new duplicate entry.
Accounting-entity discovery IDsActive account lifetime
Customer-supplied accounting-entity IDs and first/last-seen timestamps are kept in a separate account-scoped discovery index for usage views. These raw identifiers survive document deletion and have no automatic expiry. Their removal requires coordinated account closure. See the Privacy Notice for closure requests.
Billing recordsRetained as required
Earned usage, billing records, and any pseudonymous entity attribution remain as required for financial integrity, including after document deletion. The 90-day limit does not apply to these records. They contain no raw invoice content or raw accounting-entity ID.

Manage the copies in your own systems

Temlavo cannot delete copies in your n8n history, callback storage, CLI output, CI logs, or databases. Save what you need before processing.result_expires_at.

Account-scoped document access

Clerk authenticates people in the account app; server integrations use API keys. Document access is account-scoped: a document ID alone does not grant access. Keep API keys and signed upload URLs secret.

Service providers

We require provider zero-data-retention controls for OCR and model processing. Temlavo's own retention windows are shown above.

Invoice processing
Mistral OCR and OpenRouter-routed model endpoints
Infrastructure and storage
Vercel and Supabase
Accounts, billing and diagnostics
Clerk, Stripe and Sentry

Responsible disclosure

Report a security issue privately.

If you believe you found a vulnerability or security issue affecting Temlavo, send a concise report to security@temlavo.com. Please do not include customer invoice content, API keys, signed upload URLs, authentication tokens, or other secrets in the initial report.

Helpful report details

  • Affected URL, endpoint, or page
  • Clear reproduction steps using synthetic or your own test data
  • Observed and expected behavior
  • Potential impact and any safe supporting screenshots

Do not access another customer's data, disrupt service, perform destructive testing, or retain data obtained unintentionally.