The short version
AccraDocs reads a folder of messy documents, pulls out a few fields, and hands back cleanly named files. To do that we have to read each document. Then we let go of it.
- We don’t store your documents. They are held in memory only — never written to a database — for up to an hour after you upload them, so you can review and download without re-uploading. They are then automatically deleted. The one exception is a scan or phone photo, which is written to a temporary file on the server while it is converted to text, and automatically deleted as soon as that finishes.
- We don’t keep the data we extract. The vendor names, dates and amounts exist only long enough to build your filenames and the optional CSV you download.
- Your documents are never used to train AI models.
- There is no history tab, because there is no history. An hour after you upload, your documents are automatically deleted — there is nothing left for us to lose, be subpoenaed for, or leak.
AccraDocs is deliberately a transformation tool, not a document repository.
How your data flows
- Upload. You add documents over an encrypted connection (HTTPS/TLS).
- Count. We read the page count from each file before any processing starts, so you know what a batch will cost before it runs.
- Process in memory. Each file is held in memory only. We read embedded text; for scans and photos we run OCR on our own server to make the image legible.
- Extract. To identify the vendor, date and amount, the document is sent to our AI subprocessor (Anthropic) for field extraction. Under Anthropic’s commercial API terms this data is not used to train AI models.
- Review and return. You see what was extracted, correct anything flagged, and download a ZIP of renamed files plus an optional transactions CSV.
- Drop everything. Your documents and everything extracted from them are held only in memory and are automatically deleted within an hour of upload — sooner if our server restarts.
What we keep, and what we don’t
We do not keep
- Your uploaded files, or the text and images inside them
- The fields we extract — vendor, date, amount, document number, document type
- The renamed files or the transactions CSV we generate
We do keep — and only this
- Your email address and a hashed password. Raw passwords are never stored or logged.
- Account and access metadata: your plan, page balance, when you last signed in, when a batch was last run, and how many files you have processed.
- If you enable multi-factor authentication, an encrypted authenticator secret and your one-time recovery codes.
- Billing records held by Stripe. We never receive or store full card numbers.
- If you asked us to contact you, the email address and role you gave us.
- If you reached us through an advertisement or a search result, how you got here — the campaign parameters in the link you followed (including a Google click identifier, where present) and the page you landed on. We use it to tell which advertising is worth paying for. It is stored alongside the email address you gave us, it is never sold or shared for advertising, and it is deleted with your account.
That is the whole of it. It contains no document contents and no information about your clients.
Encryption
- In transit: all traffic between your browser and AccraDocs travels over HTTPS/TLS.
- At rest: documents are held in memory and are never written to a database, so there is no document data at rest. The single exception is a scanned or photographed page, written to a temporary file while it is converted to text and automatically deleted immediately afterwards. The only persistent data — your hashed credentials and account metadata — is stored on encrypted infrastructure at our hosting provider.
Our subprocessors
We use a small set of vetted providers. We keep this list current and will give notice before adding a new one that would process customer data.
| Provider | Role | What it may process | Location |
|---|---|---|---|
| Anthropic, PBC (Claude API) |
AI field extraction — reads each document to identify vendor, date, amount and document type | Document contents, during processing only. Commercial API terms: not used for model training. | United States |
| Render Services, Inc. | Application hosting and the encrypted account store | Account data only (hashed credentials, access and billing metadata). No documents are persisted. | United States |
| Stripe, Inc. | Payment processing | Billing details, name, email, payment method. We never receive full card numbers. PCI-DSS Level 1. | United States |
| Postmark (Wildbit / ActiveCampaign) |
Transactional email — address verification, password reset, multi-factor and billing notices | Your email address and the contents of those messages. No document data. | United States |
Scope note: document contents are only ever exposed to Anthropic, and only in memory during the extraction call. Render, Stripe and Postmark never receive document contents.
Cookies and analytics
In the app
The application sets only strictly necessary cookies: a signed session cookie so you stay logged in, a short-lived cookie during multi-factor sign-in, and — if you choose “remember this device” — a device cookie so you are not asked for a code every time. There is no advertising or profiling in the application.
On this website
Our marketing pages use Google Analytics 4 to understand which pages people find useful and which advertising brings them here. It sets cookies and records page views, referrer and approximate location. We do not send Google Analytics any document data — it never touches the application where your files are processed.
While we are running advertising campaigns, our marketing pages also load the Reddit advertising pixel. To be clear about its scope: it runs on every visit to these pages, whatever brought you here — not only on visits from a Reddit ad. It records the page visit and any click through to sign-up, and it receives your IP address, browser details and the address of the page you are on. We use it to tell which of our Reddit ads are working, and to show follow-up ads on Reddit to people who have visited this site. Like Google Analytics it runs on the marketing pages only, it never receives document data, and it is not present in the application.
You can block these cookies in your browser, or install Google’s opt-out add-on, without affecting the service. Reddit’s own advertising controls live in your Reddit account settings.
Retention and deletion
Documents and extracted fields are held in memory only while you work on a batch. They are automatically and permanently deleted one hour after you last download the batch, or 24 hours after upload, whichever comes first. Once you have downloaded, the review screen shows you exactly how long remains, and downloading again resets it. They are never written to a database, and we keep no history of them. Your account record is kept while your account is open. Close your account, or email us, and we will delete it; billing records are kept as long as tax and accounting law requires.
Because we do not store your documents, there is nothing to request, export or delete beyond your account record.
Your rights
You may ask us to access, correct, export or delete the account data we hold about you, and to tell you who we have shared it with. Email hello@accradocs.com and we will respond within 30 days. We do not sell your personal information, and we never use your account data or your documents to target advertising. One thing to be plain about: the Reddit advertising pixel described above lets Reddit show follow-up ads to people who have visited our marketing pages, which some state privacy laws treat as “sharing” for cross-context behavioural advertising. That applies to marketing-page visitors only — never to your account record and never to anything you upload. If you are a California resident, the CCPA gives you these rights explicitly and the right not to be discriminated against for using them.
Supporting your compliance obligations
If you prepare taxes, keep books, or do accounting work, you are treated as a “financial institution” under the Gramm-Leach-Bliley Act, and the FTC Safeguards Rule requires you to maintain a Written Information Security Plan and to oversee the service providers who touch client data. AccraDocs is built to make that straightforward:
- We act as your service provider, processing your data solely to provide the service you asked for — not for any other purpose.
- Data minimization by design. The nothing-stored model means there is very little client data in our custody at any moment.
- Tax-return information (IRC §7216). Where your documents contain tax-return information, we process it only to perform the service you engaged us for, and do not disclose or use it for any other purpose.
- Documentation on request. We can provide a data processing addendum, this subprocessor list, and answers to your vendor-security questionnaire so you can document your diligence.
We don’t claim to make you “compliant.” Compliance is your firm’s responsibility. AccraDocs is built to support your Safeguards and WISP obligations, not to replace them.
Security incidents
If we became aware of a security incident affecting data you processed through AccraDocs, we would notify you without undue delay and no later than 72 hours after becoming aware, with the information you need to meet your own obligations — including the FTC’s 30-day rule.
Children
AccraDocs is a professional tool and is not directed at anyone under 18. We do not knowingly collect personal information from children.
Changes to this page
We will revise this page as AccraDocs evolves, and update the date at the top. If a change materially affects how we handle your data, we will tell you by email before it takes effect.
Contact
West Merch, LLC d/b/a AccraDocs
Privacy and general: hello@accradocs.com
Security and vendor diligence: security@accradocs.com
Related: Terms of Service