Privacy

How your data is handled

You are uploading bank statements and debtor ledgers. This page states plainly what happens to them.

Last updated 31 August 2026

What is collected

  • Account details — your email address and a password hash. Passwords are never stored in readable form.
  • Files you upload — the bank statement, receivables ageing and payables ageing you choose to analyse, plus an optional settings file.
  • Generated reports — the forecast, diagnostic, risk ranking and brief derived from those files.
  • Activity records — which account uploaded, ran or downloaded what, and when, with the originating IP address. This exists so you can see who touched your financial data.

If you sign in with Google, Google shares your email address and name. No access to your Google account, files or contacts is requested or granted.

Where it is stored

Account records and uploaded files are held in Supabase (PostgreSQL and object storage). Analysis runs on a container hosted in Frankfurt, Germany, with a persistent disk. Everything is encrypted in transit over HTTPS and encrypted at rest by the hosting providers.

Who can reach it

Access is enforced by the database itself, not by the interface. Every row and every stored file carries an owner, and PostgreSQL refuses to return anything the requesting account does not own. Changing a URL, guessing another customer’s folder name, or calling the API directly with a valid session all return nothing.

Operators of the service can access data only through an administrative key that is never sent to a browser, and such access is used for support and incident response, not routine review.

What is never done with it

  • Your files and figures are never sold or shared with advertisers.
  • They are never used to train machine-learning models.
  • They are never combined with another customer’s data.
  • No third-party analytics or advertising trackers run on this site.

How long it is kept

Uploaded files and generated reports are retained while your account is open, so that each run can be compared against the last. Uploads are grouped into dated folders and are not overwritten, which is what makes a figure traceable back to the exact file that produced it.

Delete an individual run at any time from the Runs page. Close your account and all files, reports and records are removed.

Your rights

You can request a copy of everything held about you, correction of anything inaccurate, or complete deletion. Deletion requests are actioned within 30 days and confirmed in writing.

Contact: rilwan.sorunke@gmail.com

Processors used

Supabase (authentication, database, file storage), Render (analysis, Frankfurt), Vercel (website hosting), and Brevo (transactional email). Each processes data only to deliver the service.

A note on status

This page describes what the software actually does, verified against the running system. It is a factual data-handling statement, not legal advice, and it has not been reviewed by a solicitor. Before signing a contract with a client who requires a formal privacy notice or a data processing agreement, have it reviewed.

Why CashLensTerms of use