Privacy
Last updated: August 8, 2026
Alavira is a service offered to United States residents only. If you’re visiting from elsewhere, please don’t use the service.
What we collect
When you connect or upload a credit-card or bank statement, we extract the transaction data and store it under your account. We retain all parsed transactions until you delete your account, plus a 30-day soft-delete grace window during which you can cancel the deletion and recover your data.
How statements are processed
When you upload a statement, we extract the text, remove personal identifiers (account numbers, full names, addresses, SSN, email, phone), and send the remaining text to our AI provider (Anthropic) for parsing. Anthropic retains API request data for up to 30 days for abuse review per their terms; content their safety systems flag may be retained longer, up to two years, under their policy. This retention is outside our control.
The original PDF is never written to durable storage on our servers. It lives in memory during processing and is discarded once the parser returns.
Conversations with Ask Alavira
We do not read your conversations. The only exceptions are the answers you report with Report this answer, and users who turn on Share my conversations in Settings, which is off unless you switch it on. Even then, names and account numbers are removed before anyone at Alavira sees the text.
Conversation data is deleted 90 days after the conversation was last active, and you can delete any conversation yourself at any time from the history panel. Your questions are sent to our AI provider under the same 30-day retention described above.
Account deletion
When you click Delete account in settings, we schedule your account for permanent deletion 30 days later. Within that window you can cancel the deletion from the pending-deletion page and your account snaps right back. After 30 days, your data is permanently removed and cannot be recovered.
Data sent to our AI provider in the past 30 days cannot be recalled and will expire from their systems within 30 days, except content their safety systems have flagged, which their policy may retain longer.
Backups
We keep daily snapshots of our database for 14 days and continuous point-in-time recovery covering the trailing 7 days, both encrypted at rest by our database provider. When your account is permanently deleted, residual copies may persist in these backups for up to 14 days before aging out. Backups are used only for disaster recovery, never to restore deleted accounts to the live service.
Audit log
We keep an append-only audit log of account actions (subscription changes, deletion requests, data exports). After hard deletion we retain a hashed, one-way reference to your prior account in this log so we can investigate any post-deletion incident (chargebacks, abuse reports). Your original account identifier is removed; the hash is not reversible.
Encryption
All data we store lives in a database whose storage is encrypted at rest with AES-256 by our database provider, and everything moves over TLS in transit. Your custom redaction terms carry a second, application-level layer of AES-256-GCM encryption. Parsed transactions and account details do not carry that second application-level layer; access to them is gated by authenticated requests scoped to your account. Raw statement text is not stored at all: once parsing completes we keep only the parsed results, the file name, and a cryptographic fingerprint of the text.
Data export
You can download a full copy of your data from the settings page at any time. The export contains JSON and CSV files covering the data stored under your account.
Analytics & session replay
We use a single first-party analytics provider, PostHog (US Cloud), on our public marketing pages: the home page, the legal pages, and this privacy page. PostHog stores an anonymous identifier in your browser so we can measure unique visits, see where in the signup flow visitors drop off, and understand which sections of the marketing site people interact with. The data PostHog receives does not contain your name, email, or any financial information.
On those marketing pages, PostHog also records an anonymized session replay: mouse movements, clicks, scroll position, and page navigations. Form inputs and password fields are masked by default. Session replay is strictly scoped to public marketing pages. Once you are signed in, it does not run on any authenticated surface (the dashboard, accounts, transactions, onboarding, account settings, or any other page where you are signed in). PostHog never loads on those pages and no recording of any kind takes place there.
California residents can opt out of PostHog analytics and session replay using the Do Not Sell or Share My Personal Information link in our website footer. We also honor the Global Privacy Control browser signal automatically; if your browser sends GPC, PostHog is never initialized on your visits. Both controls also apply to the cookies described in our Cookie Policy.
Sub-processors
We rely on a small number of third-party services to operate Alavira. Each is bound by their own terms and may process some of your data on our behalf:
- Clerk: identity and session management. Receives your email, sign-in events, and any factors you set up (e.g. OTP, authenticator app).
- Anthropic: AI provider. Receives the redacted statement text we extract during parsing, and the transaction summaries we send when generating your insights. Anthropic retains API request data for up to 30 days for abuse review per their terms; content their safety systems flag may be retained longer, up to two years, under their policy.
- Stripe: payments and subscription billing. Receives the email and payment information needed to process your subscription. Alavira does not see, store, or have access to your card number.
- Vercel: application hosting. Receives the requests you make to Alavira (URLs, IP, user-agent) for the duration needed to serve them, under their data-processing terms.
- Neon: our database provider. Stores all application data described in this policy in managed Postgres, encrypted at rest, in the United States.
- Sentry: error monitoring. Receives error reports with personal identifiers scrubbed before sending; no financial data and no session recordings.
- Resend: transactional email. Receives your email address and the content of the emails we send you, which for digest and read emails includes your financial summary.
- PostHog (US Cloud): analytics and session replay on public marketing pages only. Receives an anonymous identifier, page navigations, CTA clicks, and an anonymized recording of marketing-page interactions (mouse, clicks, scroll). Form inputs and password fields are masked. PostHog does not load on any signed-in surface; see Analytics & session replay above for the full scope. We also record three server-side product events (account created, first statement imported, first read generated) keyed to your account id; these are erased when your account is deleted.