Data & Security

Last updated July 12, 2026
Pay applications contain sensitive financial figures. PayAppCheck is built to keep only what it needs, for as short a time as it needs it, and to keep each account’s data separated.

Where your data lives

Your account, database, and uploaded files are hosted in the United States. Every request is served over HTTPS, so your data is encrypted in transit. The service providers we rely on are listed with their roles in our Privacy Policy: Railway (hosting and database), Google (extraction, sign-in, fonts), Cloudflare (DNS), Resend (transactional email), and Paddle (payments).

Account isolation

Every document, extraction, and export is scoped to your account. Our API authorizes each request and returns only records that belong to you; one customer can never read another’s documents.

Data minimization & retention

Your uploaded source files are deleted within 7 days by default (configurable in your account settings from “immediately after processing” up to a 30-day maximum). We never hold your original PDFs or spreadsheets indefinitely.
Your extracted results and history are kept for 90 days by default (configurable from 30 days up to a 1-year maximum), then deleted. You can revisit your work without us storing it forever. You can also delete any document yourself, and export anytime.
We do not use your documents to train our own models, and our extraction provider is prohibited under its API terms from using your content to train its models.

How extraction handles your documents

Extraction uses a third-party vision model (Google Gemini) that reads a document to return its figures for your request. The reconciliation engine, the part that checks the math and flags errors, runs on our own servers with deterministic logic; it does not send your numbers to any third party. Every figure the model returns is passed through reconciliation before you see it, so extraction mistakes are caught rather than silently trusted.

Authentication

Passwords are stored only as salted hashes, never in plain text. Access to the app requires a valid, account-scoped token.

Payments

Payments are handled by Paddle as merchant of record. We do not store full card numbers on our servers.

Reporting a vulnerability

If you believe you have found a security issue, please email [email protected] with details. We appreciate responsible disclosure and will respond promptly.
PayAppCheck is software, not legal or tax advice. You review and confirm every number.
Billing and payment inquiries are handled by Paddle, our merchant of record.
AIA, G702, and G703 are marks of The American Institute of Architects. PayAppCheck is not affiliated with, endorsed by, or sponsored by AIA.