Privacy
Privacy policy
A practical description of how AuditExport handles information. This is a product policy, not a compliance certification.
Effective September 27, 2026. Last updated September 27, 2026.
Who operates AuditExport
AuditExport operates the service at auditexport.com. This policy describes how we handle information when you use the website, free public tools, and the authenticated product. It is a practical product policy, not a certification or a claim that counsel has reviewed it.
Information you provide
You may give us a name, email address, organization name, workspace and client labels, support messages, and the spreadsheets or CSV files you choose to upload. You decide what to put in those files. We use what you submit to operate the service you asked for.
Account information
If you create an account we store authentication identity (email and, for email/password accounts, a hashed password managed by our auth provider), your display name, organization membership, and role. We use this to sign you in, enforce permissions, and send account email.
If you choose Continue with Google, sign-in is processed by Google and Supabase Auth. The next section describes how we access, use, store, and share that Google user data.
Google user data
AuditExport uses Google Sign-In only to authenticate you. We request the standard OpenID scopes `openid`, `email`, and `profile`. We do not request Gmail, Google Drive, Google Calendar, Contacts, YouTube, or other Google API access. We do not request offline access.
How we access Google user data: after you grant consent on Google’s screen, Google returns identity information to our authentication provider (Supabase Auth). AuditExport then reads the verified email address, a stable Google account identifier, your display name, and a profile photo URL if Google includes one. We do not receive or store your Google password.
How we use Google user data: we use it only to create or sign in to your AuditExport account, show your name in the product, send account email to the verified address, and enforce organization permissions. We do not use Google user data for advertising, remarketing, credit decisions, or sale to data brokers.
How we store Google user data: the email, display name, Google subject identifier, and optional avatar URL are stored with your AuditExport user record in our application database hosted by Supabase. Session cookies keep you signed in. AuditExport application tables do not store Google access tokens, refresh tokens, or your Google password.
How we share Google user data: we do not sell Google user data and we do not share it with advertisers. It is processed by Google (for the sign-in itself) and by Supabase (Auth and the application database). Support staff may see your email and name when you contact us. We do not send your Google profile to OpenAI, PostHog, or Sentry as a Google user-data export.
AuditExport's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve user-facing authentication and account features.
You can stop future Google sign-in by removing AuditExport from your Google Account permissions. That does not delete your AuditExport workspace files. To delete an AuditExport account, use contact or the in-product deletion path when your role allows it.
Uploaded files and spreadsheet data
Authenticated uploads are business records. We process them to provide mapping, matching, exception review, reports, and related workflows. Source files stay in private storage for your organization. We do not sell uploaded files or their contents.
Free public tools are different. Anonymous tool uploads are processed in memory for one short request and are not written to authenticated tenant storage. They are discarded when the request ends. Do not treat a public tool as a system of record.
We do not say that authenticated application files are never retained. Retention is configurable per organization, and files remain until a retention or deletion path removes them.
Billing and payment information
Paid plans are billed through Dodo Payments. AuditExport stores plan, interval, subscription status, and provider references needed to apply entitlements. We do not collect or store payment card numbers on AuditExport servers. Card details, if collected, are entered on the payment provider’s hosted checkout.
Usage and analytics data
We may record product events such as page views, checkout started, or a public-tool run completing. Analytics is limited to an allowlisted event set. Events must not include financial cell values, payroll amounts, formulas, signed URLs, source file contents, or AI prompts.
PostHog
When PostHog is configured, we send only allowlisted product events (for example marketing page views, signup clicks, or tool-run completed). We use this to understand which public pages and workflows are used. Cell values, bank details, payroll figures, formulas, and signed URLs are out of bounds.
Sentry
When Sentry is configured, we send sanitized error reports so we can fix failures. Events are processed to strip secrets, signed URLs, and sensitive financial payloads. We do not use browser session replay on AuditExport.
Email / Resend
When outbound email is enabled we use Resend to send account, notification, and support messages. The contact form delivers to support@auditexport.com and uses your address only as the reply-to. You cannot nominate an arbitrary destination.
AI providers
Assistive AI is optional and only runs when the feature is enabled for your organization and a provider is configured. Today that provider may be OpenAI in production configurations. AI may receive limited structured context (for example column headers or exception codes) after redaction. It is not given entire workbooks, signed URLs, or unrestricted payroll contents.
AI may suggest or explain. It does not calculate authoritative amounts, approve matches, or write official financial results. Provider-side retention depends on that provider’s contract. We do not claim that prompts are never sent to a model when AI is turned on.
How information is used
We use information to authenticate you, isolate tenants, process files you upload, apply plan limits, send email you would expect from the product, fix errors, and understand coarse product usage. We do not sell customer files or use them to train a public model.
Service providers
We use other companies to run the product. The current architecture includes:
- Supabase — authentication, application database, and private file storage
- Vercel — hosting the web application
- Google Cloud / Cloud Run — background job and file-processing workers
- Dodo Payments — hosted checkout and subscription billing
- Resend — transactional and support email when enabled
- Sentry — sanitized error monitoring when enabled
- PostHog — allowlisted product analytics when enabled
- OpenAI — optional assistive AI when that feature is enabled and configured
Retention
Authenticated files, datasets, reports, and audit events are kept according to organization retention settings and legal or accounting holds we implement in the product. Audit history is designed to outlive casual cleanup. Organization deletion is delayed and can be canceled. We do not promise a specific deletion clock in this policy unless a product control shows one.
Anonymous public-tool files are not persisted to tenant storage.
Your control and deletion
Security measures
AuditExport is designed around organization isolation, PostgreSQL row-level security, role checks on the server, private storage, and short-lived signed download URLs. Transport and storage encryption are provided by the hosting and database vendors we use. See Security for the public description. We do not claim SOC 2, ISO, HIPAA, or PCI certification.
International processing
Providers may process data in the United States and in other regions where they operate. We do not publish a single guaranteed residency region on this page. If you need a contractual residency commitment, ask us before sending regulated files.
Children and intended use
AuditExport is a business tool for finance and accounting work. It is not directed at children. Do not create an account for anyone you know is under 16.
Changes to this policy
We may update this policy as the product changes. The effective date and last-updated date on this page will change when we do. This version is effective September 27, 2026 and was last updated September 27, 2026.
Contact
Privacy questions: support@auditexport.com or the contact form.