Security & retention
Your invoice data has an expiry date.
Invoice files and results are kept for a limited time. Billing records, service records, accounting-entity discovery IDs, and fingerprints used for duplicate detection follow separate retention rules below.
Your file goes straight to private storage without passing through the public API server.
Kept in private storage with a 24-hour default expiry. Physical cleanup can follow expiry.
Seven days from completion by default. The API response gives the result-expiry timestamp.
API access ends and stored results are cleared. File deletion is attempted immediately and retried if needed.
Delete a document through the APISource and intermediate expiry is measured from each stored object's creation; unconfirmed uploads expire 24 hours after document creation. Result expiry ends API access to the result; physical cleanup can follow while processing recovery or storage-deletion retries complete. Document deletion also clears document fields. The separate records and provider-log limits below still apply.
Never in application logs
Invoice content is never written to normal application logs.
- Source bytes and raw OCR text
- Invoice values: totals, vendor names, invoice numbers
- Extracted invoice content
- Full prompts and model responses
- Signed upload URLs and tokens
- Provider response bodies
Service diagnostics and platform logs
Application logs and Sentry receive service diagnostics that exclude invoice content. Their identifiers can still relate to your account. These diagnostics include:
- Account, document, and run identifiers with statuses
- Request IDs and typed error codes
- Processing timings and page counts
Vercel's separate platform logs may retain request URLs, query parameters, browser and referrer information, callback destinations, and related error logs. These can contain sensitive data. Document deletion does not delete those logs; they follow Vercel's separate retention policy. See the Privacy Notice's retention and deletion details.
Retention beyond invoice content
Service records have their own retention rules. Deleting a document does not remove every record associated with your account.
- Operational recordsApproximately 90 days
- Processing records and service diagnostics generally expire after 90 days. Idempotency records last 7 days. Security records may be kept longer where required.
- Duplicate fingerprintsUntil explicit deletion
- Tenant-keyed document and invoice-identity fingerprints are pseudonymous, not anonymous or plaintext invoice identifiers. Explicit document deletion removes them from duplicate matching. They have no automatic expiry. Disabling duplicate detection on a submission skips matching and stores no new duplicate entry.
- Accounting-entity discovery IDsActive account lifetime
- Customer-supplied accounting-entity IDs and first/last-seen timestamps are kept in a separate account-scoped discovery index for usage views. These raw identifiers survive document deletion and have no automatic expiry. Their removal requires coordinated account closure. See the Privacy Notice for closure requests.
- Billing recordsRetained as required
- Earned usage, billing records, and any pseudonymous entity attribution remain as required for financial integrity, including after document deletion. The 90-day limit does not apply to these records. They contain no raw invoice content or raw accounting-entity ID.
Manage the copies in your own systems
Temlavo cannot delete copies in your n8n history, callback storage, CLI output, CI logs, or databases. Save what you need before processing.result_expires_at.
Account-scoped document access
Clerk authenticates people in the account app; server integrations use API keys. Document access is account-scoped: a document ID alone does not grant access. Keep API keys and signed upload URLs secret.
Service providers
We require provider zero-data-retention controls for OCR and model processing. Temlavo's own retention windows are shown above.
- Invoice processing
- Mistral OCR and OpenRouter-routed model endpoints
- Infrastructure and storage
- Vercel and Supabase
- Accounts, billing and diagnostics
- Clerk, Stripe and Sentry
Privacy Notice's service-provider tableProvider purposes and the data each service handles.
Data Processing Addendum (DPA)Customer-data processing terms and the contractual subprocessor schedule.
Responsible disclosure
Report a security issue privately.
If you believe you found a vulnerability or security issue affecting Temlavo, send a concise report to security@temlavo.com. Please do not include customer invoice content, API keys, signed upload URLs, authentication tokens, or other secrets in the initial report.
Helpful report details
- Affected URL, endpoint, or page
- Clear reproduction steps using synthetic or your own test data
- Observed and expected behavior
- Potential impact and any safe supporting screenshots
Do not access another customer's data, disrupt service, perform destructive testing, or retain data obtained unintentionally.