Legal
Privacy Policy
This Policy explains what data PODetect(“PODetect”, “we”) collects when you use the Service, how we use it, who we share it with, and the choices you have. It applies to the PODetect web application and the service-related email we send on behalf of the team.
Effective date: 2026-08-19
1. Introduction & Scope
This Privacy Policy applies to PODetect (the “Service”) operated byPODetect. It covers personal data we collect through the Service and excludes any third-party sites we link to (such as accounting integrations or our payment processor), which are governed by their own policies.
In this Policy, “personal data” means information that identifies or could reasonably identify an individual. “Customer Content” means business documents you upload to the Service (invoice PDFs/images, vendor master files, ledger extracts), which may incidentally contain personal data.
2. Information We Collect
We collect the following categories of information:
- Account information: your name, work email, and organization name that you provide when creating an account.
- Customer Content: invoice PDFs and images, vendor-master files, ledger extracts, and any other documents you upload; data returned through OAuth grants you approve (currently QuickBooks Online, Xero, and Sage Intacct).
- Usage & device information: feature-usage events, IP address, browser type, referrer, and timestamps. This is used to operate the Service, detect abuse, and debug production issues.
- Payment information: billing email and the last four digits of your card. Full card numbers are handled directly by Stripe and are not stored on our infrastructure.
We do not collect postal addresses or telephone numbers at signup. We do not knowingly collect personal data from children under 16.
3. How We Use Information
We use the information we collect to:
- Operate, maintain, and improve the Service.
- Extract structured fields from uploaded invoices and surface audit exceptions (vendor-master drift, duplicate recurring charges, sales-tax anomalies, etc.).
- Process payments for paid plans through Stripe on behalf of the team.
- Communicate with you about the Service: transactional notifications (signup confirmation, payment receipts, security alerts), support replies, and product updates that materially affect how the Service works.
- Detect, prevent, and respond to abuse, fraud, security incidents, and violations of our Terms.
We do not sell personal data, and we do not share personal data with third-party advertisers or advertising networks.
4. AI Processing
To extract structured fields from Customer Content and classify audit exceptions, we route Customer Content to large-language-model tooling through the Polsia AI proxy — a hosted LLM routing layer operated by our infrastructure vendor. No Customer Content is sent directly to any third-party model provider; the proxy is the only outbound integration our application uses for AI inference.
Customer Content is not used to train third-party foundation models. Model providers are contractually restricted from retaining or using Customer Content for model-training purposes. Aggregated, anonymized telemetry (such as “X invoices processed today”) may be used to improve the Service.
5. Sharing & Sub-Processors
We do not sell personal data. We share information only with the categories of recipients listed below, and only as necessary to operate the Service:
- Platform vendor:Polsia — hosting, database, file storage, email proxy, AI proxy, and error monitoring.
- Payment processor:Stripe — subscription billing through Stripe Connect.
- Accounting integrations:Intuit (QuickBooks Online), Xero, and Sage Intacct — only when you choose to connect them, using scoped, post-only OAuth credentials.
- Transactional email: routed through the Polsia email proxy.
We may also disclose information when required by law, in response to a valid legal process, or to protect the rights, property, or safety of PODetect, our users, or others.
6. Cookies & Local Storage
We use a small number of cookies and similar storage, none from advertising networks:
- Session cookie: issued by our authentication provider to keep you signed in. Required for the Service to function.
- Locale preference cookie:remembers your language preference so the next page-render doesn’t flash in the wrong language.
- Theme preference: stores light/dark theme choice locally so it survives reloads.
7. Data Retention
Customer Content is retained while your account is active and for up to thirty (30) days after account closure to allow restoration. Backups are purged on a rolling thirty-day window after closure. Aggregated, anonymized telemetry (which cannot reasonably be linked back to an individual or Customer) may be retained longer for product analytics.
You can request earlier deletion of Customer Content at any time by emailing podetect@polsia.app.
8. Security
We protect Customer Content with encryption in transit, encryption at rest for uploaded content, role-based access controls, audited production access, and routine vulnerability scanning. No system is 100% secure; if we discover a material incident affecting your personal data, we will notify you and the applicable regulators in accordance with applicable law.
9. Your Rights & Choices
PODetect is a B2B service. The principal point of contact for the personal data of end-users within a Customer organization is the Customer’s workspace owner or admin — please contact them first. If you are a direct end-user (for example a controller visiting from the EEA or UK), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Receive a portable copy of your personal data.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email podetect@polsia.app. We will respond within thirty (30) days.
10. International Data Transfers
PODetect is hosted and operated in the United States. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (or, where available, an adequacy decision) to provide an adequate level of protection for that data. By using the Service, you acknowledge that your personal data may be transferred to and processed in the United States.
11. Children's Data
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at podetect@polsia.app and we will delete it.
12. Changes to this Policy
We may update this Policy. For material changes we will provide at least thirty (30) days’ notice by email and an in-app banner before the change takes effect. Non-material changes (clarifications, typo fixes) will be posted with an updated effective date. The current effective date is shown at the top of this page.
13. Contact
Questions about this Policy or our handling of your data? Reach us at podetect@polsia.app.
PODetect, Inc.
548 Market St, San Francisco, CA 94104