Security & Privacy

Your data belongs to you.

We built IFRS Buddy for professionals who handle sensitive financial information. Here is exactly how we handle your data.

Data handling

What we collect

Your email address (to send a magic login link), conversation history (to display your chat history), and query count (to enforce plan limits).

What we do not collect

Passwords, payment card numbers (handled exclusively by Stripe), or any financial data from your questions.

Training

Your conversations are never used to train or fine-tune any AI model — ours or third parties'.

Retention

Conversation data is retained for as long as your account is active. You can delete your account and all associated data at any time from your account settings.

Infrastructure

Hosting

EU-based virtual server (Germany). No data leaves the European Economic Area in transit.

Transport

All traffic is served over HTTPS with TLS 1.2+. HTTP is automatically redirected to HTTPS.

Database

PostgreSQL with encrypted storage. Backups are encrypted and stored in Cloudflare R2 (EU jurisdiction).

Authentication

Passwordless magic links only. Tokens are single-use and expire after 15 minutes.

Third-party services

We use a small number of carefully selected services. No advertising networks. No data brokers.

Anthropic (Claude API)

Processes your query to generate answers. Queries are sent without personally identifiable information. Anthropic's API does not train on API data by default.

Stripe

Handles all payment processing. We never see or store your card details.

Resend

Sends transactional emails (magic links, receipts). Only your email address is shared.

Cloudflare

DNS and DDoS protection. Acts as a reverse proxy — does not store conversation content.

Found a security issue?

Please report it responsibly. We review all security reports and respond within 48 hours.

Contact us →