Privacy Policy

Last updated: 19 September 2026

1. Who we are

[LEGAL ENTITY NAME], registered in [COUNTRY] under company number [NUMBER], operating InputFeed. For anything in this policy, including a request about your data, write to support@inputfeed.com.

2. The two roles we play

This distinction determines your rights, so it comes first.

For the contents of documents you upload, we are a processor. Invoices and receipts routinely contain personal data — a supplier contact’s name, an email address, a bank account, sometimes a sole trader’s home address. You decide why that data is processed; we only act on your instructions. If you are an individual whose details appear on an invoice someone else uploaded, we are not the right people to ask — the business that uploaded it is, and we will help them respond to you.

For your own account, we are a controller. Your name, email, company details, billing records and usage belong to our relationship with you, and we decide how those are handled.

3. What we hold

Documents you upload and what we read from them. The original file, and the extracted supplier, dates, amounts, tax, currency, line items and payment terms. Also every correction anyone makes to those fields, with who made it and when — an audit trail your own accounting obligations are likely to require.

Account and organisation data. Names, email addresses, hashed passwords, roles and division access. Company name, registration number, country, currency and contact address. Where you sign in with Google or Microsoft, the account identifier and verified email they return — never your password.

Connected storage. Where you connect Google Drive or SharePoint, encrypted access and refresh tokens, the identifier of the folder you selected, and a record of what was imported. Scope is limited to the folder you choose; for Google we request drive.file, which grants access only to files you explicitly select.

Billing. Plan, subscription status, volume used and overage confirmations. Card details are handled entirely by Stripe and never reach our servers.

Operational records. Server logs, error reports, and token counts and estimated cost per extraction, used to run and price the service.

4. What we do with it, and why

PurposeDataBasis
Reading and structuring your documentsUploads and extracted fieldsContract
Letting you review, correct and exportExtracted fields, audit trailContract
Running accounts and access controlAccount dataContract
Taking payment and enforcing plan limitsBilling and usageContract
Keeping the service secure and availableLogs, security eventsLegitimate interests
Diagnosing failures and improving reliabilityError reports, usage metricsLegitimate interests
Service emails (verification, invitations)Email addressContract

What we do not do. We do not sell your data. We do not use it for advertising or profiling. We do not use your document contents to train artificial-intelligence models — neither ours nor anyone else’s. We do not send marketing email without your consent.

5. Artificial intelligence, specifically

To read a document, its contents are sent to Anthropic’s API, which operates the model that performs the extraction. This is the one place your document leaves our infrastructure, so it deserves a plain statement:

  • Documents are sent for extraction only, and only when you upload one or a connected folder provides one.
  • Anthropic processes them as our subprocessor under contract, and not to train models.
  • A document may be processed twice where the first reading is uncertain, to improve accuracy.
  • We retain token counts and estimated cost per document; we do not retain the model’s raw output beyond what is stored as your extracted invoice.

If sending document contents to a third-party AI provider is not acceptable to you, InputFeed is not a service you can use — it is how the product works, not an optional feature.

6. Who else touches your data

Only the subprocessors below, each under contract and only to provide the service. We do not otherwise disclose your data except where legally compelled, in which case we will tell you unless prohibited from doing so.

SubprocessorWhat it doesData it seesWhere
AnthropicReads uploaded documents and returns structured fieldsFull document contentsUnited States
RailwayApplication hosting, database, file storage, backupsEverything storedUnited States
StripeSubscription billingBilling contact and payment details. Card data never reaches usUS / EU
ResendVerification and invitation emailsRecipient name and emailUnited States
CloudflareDNS for inputfeed.comDNS queries only — traffic is not proxied through itGlobal
GoogleSign-in, and Drive folder import if you connect oneAccount identifier and email; files in the folder you selectUnited States
MicrosoftSign-in, and SharePoint/OneDrive import if you connect oneAccount identifier and email; files in the folder you selectUnited States

Google and Microsoft are subprocessors only if you choose to use them — they see nothing for an account that signs in with a password and uploads manually.

7. Where your data is

Currently stored in the United States, including invoice files, the database and backups. [IF SELLING INTO THE EU: state the transfer mechanism — Standard Contractual Clauses — or move hosting to an EU region]

8. How long we keep it

  • Documents and extracted data: until you delete them or close your account. We impose no retention period, because your accounting obligations — not ours — determine how long you need them.
  • Exported files: kept so past exports stay downloadable.
  • Audit trail: kept for the life of the invoice it belongs to; it is only meaningful alongside the record it describes.
  • After account closure: deleted within [30/60/90] days, except anything we must retain for tax or legal reasons.
  • Backups: may persist for a short period after deletion until rotated out.

9. Security

Passwords are hashed with bcrypt and never stored in readable form. Connected-storage tokens are encrypted at rest with AES-256-GCM. Traffic is served over HTTPS. Access is scoped server-side by organisation and division — enforced in the API, not merely hidden in the interface. Accounts lock after repeated failed sign-ins, and sign-in and registration are rate-limited.

What we do not claim. We hold no ISO 27001, SOC 2 or ISAE certification, and no independent audit has assessed these measures. Uploaded files are not currently scanned for malware. We would rather state this plainly than imply assurance we cannot evidence.

10. Your rights

Where GDPR or comparable law applies, you may request access to, correction of, deletion of, or a portable copy of your personal data, object to processing based on legitimate interests, and complain to your data protection authority.

For your account data, write to support@inputfeed.com and we will respond within one month.

For personal data inside documents another organisation uploaded, that organisation must handle your request; we will assist them promptly.

Being straight with you: InputFeed does not yet have a self-service export. A portability or deletion request is handled by us manually, on request. We consider this a gap and intend to close it.

11. Cookies

We set a small number of strictly necessary cookies: a session cookie to keep you signed in, short-lived cookies to secure sign-in flows, and — while the service is in limited release — an access cookie. We use no analytics, advertising or tracking cookies, so there is no consent banner because there is nothing to consent to.

12. Children

InputFeed is a business tool, not directed at children, and we do not knowingly collect their data.

13. Changes

We will update this policy as the service changes and revise the date above. Material changes affecting your rights will be notified by email or in the application.

14. Contact

support@inputfeed.com