Privacy policy
Last updated: September 21, 2026
Guardxflow is an accounts-payable application. With your permission, it finds the invoices arriving in your inbox, extracts their amounts and taxes, presents them to you for approval, and then records them in your accounting software. This policy sets out exactly what data we process, why, who it is passed to, how long we keep it, and how you can put a stop to it.
It applies to the guardxflow.com web application and all of its integrations. We do not sell any personal data, and we do not use your data for any advertising purpose.
1. Who is responsible
Guardxflow operates the service. For any question about privacy, about access to your data, or about deleting it, write to support@guardxflow.com. We answer requests within 30 days.
2. What we collect
- Account: email address, display name, and either a hashed password (never stored in plain text) or the identifier of the provider you sign in with.
- Email content: the sender, subject, date, an extract of the message body, and the attachments of messages that carry an accounting document. Messages that carry none are not retained.
- Documents: the PDFs and photos of invoices, credit notes and payment proofs, along with the data we extract from them (supplier, date, number, amounts, taxes, line items).
- Business data you create: entities, suppliers, clients, purchase orders, fixed costs, categories, and the team members you invite along with their permissions.
- Access tokens: the OAuth tokens of the services you connect, kept encrypted and used only for the calls you have authorised.
- Technical data: IP address, browser type and timestamps, in our host's logs, for security and diagnostics.
- Notifications: if you turn them on, your device's notification identifier, so we can tell you about invoices waiting on you.
We collect no payment card data: none is processed on this service. The service is not intended for minors and we do not knowingly collect their data.
3. Google user data
You are never required to connect a Google account. If you do, these are exactly the scopes requested and what we do with them:
gmail.readonlyRead your email in order to find the messages carrying an invoice, credit note or payment proof as an attachment, and import that file into your approval queue. We read your email for no other purpose, and we never send, modify or delete any email.
drive.fileCreate and write into a “GuardXFlow” folder in your Drive to archive a copy of your documents. This scope grants access only to files the application creates itself: we cannot see the rest of your Drive.
userinfo.email / openidKnow which address authorised the connection, so we can show it in Settings and attach the mailbox to the right account.
Guardxflow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In concrete terms, data obtained from Google APIs:
- is used only to provide and improve the features you see on screen: finding invoices, extracting their data, archiving them and recording them in your accounting software;
- is never sold, rented or traded, and is used for no advertising and no advertising profiling;
- is not used to train generalised artificial-intelligence models, or any model independent of your own account;
- is transferred to no one other than the processors listed in section 5, strictly in order to operate the service, except where the law obliges us or where it is necessary to address a security issue or fraud;
- is not read by any human at Guardxflow, except in four cases: you give us express permission for a specific message (for example because you are reporting an extraction problem), it is necessary for security or to investigate abuse, the law requires it, or the data has been aggregated and anonymised so that it no longer concerns anyone;
- can be revoked at any time, from Settings in the application or from your Google account's permissions page. Revoking stops all access immediately.
The same rules apply to data obtained from Microsoft, from Zoho, and from any other service you connect.
4. Why we process this data
- To authenticate you and protect your account.
- To find accounting documents in the mailboxes you connect.
- To extract their amounts, taxes and line items, using artificial intelligence.
- To detect duplicates and match an invoice against a purchase order.
- To present them to you for approval, with an audit trail of who approved what.
- To record approved documents in your accounting software, at your request.
- To archive a copy in your cloud storage, at your request.
- To keep the service secure and to meet our legal obligations.
The legal bases are performance of our contract with you, your consent for each service you choose to connect, and our legitimate interest in keeping the service secure.
5. Processors and transfers
We pass your data only to the providers below, and only for what is stated. Those that depend on a connection you make receive nothing until you have made it.
Supabase
Hosting, database, authentication, file storage
All of your account's data, including invoice PDFs. Hosted in the United States.
Vercel
Web application hosting
Technical request logs (IP address, user agent). No invoice content.
OpenAI
Extracting the data from an invoice or a payment proof
The PDF or image file, only at the moment of extraction. Not retained by OpenAI and not used to train its models (API, not ChatGPT).
Google (Gmail, Google Drive)
Reading invoice emails; archiving a copy in your Drive
With your permission only. Set out in the “Google user data” section below.
Microsoft (Outlook, OneDrive, SharePoint)
Reading invoice emails; archiving into your OneDrive or SharePoint
With your permission only, through Microsoft Graph.
Zoho Mail
Reading invoice emails
With your permission only.
Dropbox
Archiving a copy of your documents
With your permission only. The files you choose to sync.
Amazon S3
Archiving into storage that you provide
Only if you configure your own S3 credentials.
Intuit QuickBooks Online
Accounting sync
The invoices, suppliers and payments you approve.
Xero
Accounting sync
The invoices, suppliers and payments you approve.
Sage Business Cloud Accounting
Accounting sync
The invoices, suppliers and payments you approve.
Our servers and backups are located in the United States, so your data may be processed outside Canada and the European Union. We sell no personal data and pass none to data brokers. If the business were sold or merged, you would be told before any transfer of your data.
6. Retention and deletion
- Your documents and business data are kept for as long as your account exists.
- You can delete a document at any time; it goes to the trash, and deleting it permanently erases it from our database and our storage.
- Disconnecting a mailbox or a storage space immediately deletes the corresponding tokens.
- You can ask for your account to be deleted by writing to support@guardxflow.com. We action it within 30 days; it erases your account and everything in it, with no way back.
- Two things deliberately survive that deletion, because they are not ours: documents already recorded in your accounting software, and files already copied into your own cloud storage. You manage those directly with those providers.
- Our host's technical logs are kept for at most 30 days.
7. Security
- Data is encrypted in transit (TLS) and at rest by our host.
- Each account is isolated in the database at row level (Row-Level Security): a query can only reach the data of its own account.
- OAuth tokens are stored encrypted and are never exposed to the browser.
- Team members you invite receive only the permissions you give them.
- In the event of a data breach affecting your information, we will notify you and the relevant authorities without undue delay.
8. Your rights
You can request access to your data, its correction, its deletion or its portability, withdraw your consent, and object to processing. In Québec, Law 25 additionally gives you the right to be informed of an automated decision; the AI extraction in Guardxflow decides nothing on its own — a person approves every document before it is recorded in the accounts. Write to support@guardxflow.com to exercise any of these rights. If our answer does not satisfy you, you may contact the data protection authority in your jurisdiction.
9. Changes
If we change this policy we update the date above, and where the change is significant we tell you in the application or by email before it takes effect.
