Privacy Policy

Effective August 28, 2026

This page describes the data categories and integrations present in Wevora and the controls that remain under release verification. Current access is a pre-production evaluation, not an approved production service. Do not submit real financial, tax, identity, or bank data.

1. What we collect

  • Account data β€” name, email, password hash (bcrypt, 12 rounds), preferred language.
  • Company data β€” business name, type (LLC, S-Corp, etc.), industry, EIN (optional), fiscal year start.
  • Transaction data β€” transaction records you submit through currently enabled import workflows, including date, merchant, amount, and category.
  • Documents β€” receipts and other files stored and explicitly linked through currently enabled workflows. Automatic extraction and fiscal W-9 collection are unavailable.
  • Plaid integration β€” integration code exists, but Plaid connections are temporarily unavailable. Do not submit real-bank data.
  • Operational metadata β€” selected actions can create audit records and diagnostic events. Complete action coverage and retention are not yet verified.
  • Cookies / sessions β€” authentication and session cookies plus request metadata needed to operate the application.

2. What we use it for

  • Providing currently enabled features for transaction and receipt organization and review.
  • Displaying unreconciled bookkeeping views that are not suitable for tax filing or financial decisions.
  • Delivering non-fiscal notifications where enabled and configured.
  • Recording selected audit events and investigating operational errors.

The current product design does not include an advertising-data sale workflow. It does not establish verified anonymization or vendor model-training behavior. Provider commitments depend on the terms and written agreements actually in force. Redaction and log-scrubbing coverage remain under release verification.

3. Where your data goes

The codebase contains the integrations below. Actual processing depends on deployment configuration, the enabled workflow, and the release gates described here:

  • PostgreSQL β€” primary application persistence in the private Coolify network.
  • OpenAI β€” integration code exists, but external AI workflows and customer-managed API keys are unavailable in the current release. Input minimization, provider retention, and training terms require deployment-specific verification before enablement.
  • Plaid β€” bank-linking and synchronization code exists, but connections are temporarily unavailable in every environment.
  • Coolify β€” application hosting, private object storage, scheduling, and diagnostic logging.
  • Stripe β€” existing subscription administration. New paid upgrades are unavailable.
  • Inngest β€” background-job orchestration code is present; event payload controls remain subject to release verification.
  • DigitalOcean Spaces β€” encrypted, private, versioned database backup storage when configured.
  • Resend β€” optional transactional email when configured; fiscal W-9 and tax-notification workflows remain unavailable.

4. Data retention

Record-specific retention, deletion, backup, and provider schedules are still being documented and tested as release gates. A deletion request may be limited by applicable law or a provider's verified retention requirements; we will explain the applicable scope when responding to a request.

5. Your rights

Subject to applicable law, you may ask us to:

  • Access β€” identify account data associated with you.
  • Correct β€” correct inaccurate account or bookkeeping records.
  • Delete β€” delete eligible data, subject to verified legal or operational retention requirements.
  • Portability β€” provide data in a machine-readable form where technically available and legally required.
  • Restrict or object β€” limit eligible processing where applicable law provides that right.

Submit a request to privacy@usewevora.com. We will verify identity and communicate the applicable scope and timing; this page does not promise a shorter deadline than the law requires.

6. International transfers

Configured service providers may process data in the United States or other locations identified in their current terms. Before production use, the deployment-specific data-location and transfer inventory must be verified. Use from another country may involve cross-border processing.

7. Children

The Service is not intended for users under 18. If you believe a minor submitted data, contact privacy@usewevora.com; the request will be assessed under applicable law and the verified deletion workflow available at that time.

8. Changes

Updates will be reflected on this page with a revised effective date, together with any additional notice required by applicable law. Continued use after the effective date constitutes acceptance.

9. Contact

Privacy questions: privacy@usewevora.com