Security
What happens to your data, stated exactly.
Public-finance work means confidential government and donor records. This page is the record of how they are protected: the practices, the named service providers, and the documents we will sign. It is written for the person filling in a procurement questionnaire, and every claim on it can be confirmed in writing.
Updated 8 August 2026
At a glance
- ✓Everything is encrypted in transit and at rest, with row-level security scoping every request to the account that made it.
- ✓Uploaded documents live in private, per-account storage. No other customer can reach them, and they never join the shared search index or the public demonstration corpus.
- ✓We never train any AI model on your content, and the call that carries your documents is routed only to providers that do not retain or train on it. If no such provider is available, the request stops.
- ✓You can delete any document, with its extracted text, at any time. Closing your account removes your documents with it.
- ✓A short, named list of service providers processes data on our behalf. It is published below and kept current in the Privacy Policy.
- ✓Storage and compute regions, and anything else specific to your jurisdiction, are stated in the security schedule provided with your agreement.
Data protection
Data travels over encrypted connections and is encrypted at rest. The database enforces row-level security, so a request can only ever reach the rows and files belonging to the account that made it; uploaded documents sit in private storage scoped to that account. On our side, only authorised administrators can reach stored content, and only for support and abuse-prevention. We do not browse customer documents in the ordinary course.
Content you submit stays yours and stays separate. The text of an uploaded document is used only to answer your own questions, in the conversation where you uploaded it. It is never added to the shared search index other answers draw on, never placed in the public demonstration corpus, and never used to train any model.
AI processing, stated exactly
To answer a Desk question, your question, the source material retrieved for it, and any documents you attached are sent through OpenRouter to a language-model provider. For every call that carries an uploaded document, routing is restricted to providers that do not retain or train on the content, and this is enforced, not aspirational: if the configured model has no such provider available, the call fails rather than send your content to one that would keep it.
Scanned or photographed uploads are first read by optical character recognition (Mistral AI) in the European Union (Paris) to extract their text. On our paid plan that content is not used to train any model and is deleted within 30 days. We run no model training of our own, on anything.
One honest limit, named before you ask: model inference runs on the infrastructure of the named AI providers. A deployment can anchor your database and documents to a jurisdiction; it cannot put the language model there. Where inference location matters to you, it is handled contractually, and we will say so plainly rather than imply otherwise.
Retention and deletion
Documents and conversations are retained while your account is active so you can return to them; there is no separate expiry imposed on your content. You can delete any uploaded document, together with the text extracted from it, at any time, and closing your account removes your documents as well. Automated housekeeping clears any stray file left by an interrupted upload.
The application database is covered by nightly managed backups retained for seven days, held with the same provider and under the same encryption as the database itself.
Residency, per deal and in writing
Storage and compute regions are stated in the security schedule that accompanies each agreement, alongside the current subprocessor list and backup posture. We keep region details out of marketing pages deliberately: a signed schedule you can hold us to is worth more than a webpage claim, and it is re-verified against the running systems before signature.
For organisations that require in-country handling, a dedicated deployment in a nominated jurisdiction is available as a configuration of the same product. The model-inference limit above applies there too, and we will name it in the schedule.
Service providers (subprocessors)
| Provider | Role | What it receives |
|---|---|---|
| Supabase | Database, authentication, and document storage | Account data, conversations, uploaded documentsRow-level security; private per-account storage; encrypted in transit and at rest. |
| Vercel | Hosting and first-party analytics | All traffic in transit; request logs; aggregate, cookieless usage countsAnalytics sets no cookies and builds no cross-site profile. |
| OpenRouter and the model providers it routes to | Generating Desk answers | Desk questions, retrieved source material, attached document textDocument-bearing calls are routed only to providers that do not retain or train on the content; if none is available the call fails rather than fall back. |
| Mistral AI | Optical character recognition for scanned uploads, in the EU (Paris) | Pages of scanned or photographed uploads, as transient image dataOn our paid plan the content is not used to train any model and is deleted within 30 days. |
| AWS Textract | Contingency OCR engine | Same as Mistral AI, only when the contingency engine is active |
| OpenAI | Text embeddings for search | Text to be embedded |
| Stripe | Payments and tax | Billing details; card data is entered directly with Stripe and never stored by us |
| Resend | Transactional email | Recipient address and message content |
This list is kept current in the Privacy Policy as providers change. Each processes data on our behalf under its own terms.
Answers you can audit
Every Desk answer cites the authoritative sources it was built from, down to the paragraph, so a reviewer can check the claim against the standard rather than take our word for it. Behind that sits a recurring internal audit that re-verifies citations against the source corpus, and a documented quality process we can share under NDA.
Trust pages usually end with a badge wall. Ours ends with this: ask us a public-finance question in the demonstration, follow a citation to its paragraph, and judge the answer against the source. That is the audit that matters.
What we will put in writing
On request: a Data Processing Addendum; a security schedule stating regions, subprocessors, and backup posture for your agreement; written confirmation of the current data-handling and retention settings of each provider used; and a summary of how your data is handled, for your compliance file. Write to support@pfmexpert.net and name the documents your procurement needs.