Privacy Policy
Last updated 17 August 2026
In short
- Paratiq does not connect to your bank; you decide which income and expense details to add.
- Automatic document reading and web notifications are optional and are used only when you enable them.
- We do not sell your data for advertising. You can export your information or request account deletion from your profile.
1. About this policy
This Privacy Policy explains in plain language what happens to your information when you visit the Paratiq website, create an account, use the personal income and expense tracker, or contact us for support.
This policy is not a request for consent or a service agreement. For the data controller, legal grounds, transfers, and statutory rights under Turkish data protection law, read the KVKK Notice.
2. Information we collect
Information you provide
- Your name, email address, securely hashed password, and optional profile image;
- Income and expense amounts, dates, categories, descriptions, payment parties, and recurring-transaction details;
- Your language, currency, time zone, country, notification, masking, and security preferences;
- Messages you send to support and information needed to resolve your request.
Information generated when you use a feature
- Session records, IP address, browser, operating system, device type, and last-active time;
- Email-verification status, notification-delivery records, and optional web-push subscriptions;
- Plan and entitlement information, data-export requests, and account-deletion status;
- Error, security, and abuse-prevention records.
Documents processed only when you upload them
If you upload a receipt or invoice for automatic reading, we may process the image, fields extracted from it, processing results, and your masking choice in connection with your account. Paratiq does not connect to your bank or import account activity from it.
Descriptions you enter and documents you upload may contain information about other people. Please do not upload identity documents, bank statements, health information, or sensitive personal data that the service does not need.
3. How we use information
We use information to:
- Create your account, verify your email address, and manage authentication and sessions;
- Display your financial records, recurring entries, upcoming payments, summaries, and reports;
- Complete document-reading, data-export, notification, and account-deletion actions you request;
- Protect accounts, show active sessions, limit fraudulent or automated requests, and diagnose technical problems;
- Send email verification, password resets, security alerts, and service notifications you select;
- Answer support requests, meet legal obligations, and establish or protect rights.
We do not use your personal or financial data for behavioural advertising, data brokerage, or unrelated marketing profiles.
4. Optional document reading and masking
You choose whether to start automatic receipt or invoice reading. If you do not use the feature, no document is sent to the document-reading provider, and you can always enter a transaction manually.
Masking is enabled by default for new accounts, but it is optional. When enabled, Paratiq attempts to black out detected fields such as national identifiers, IBANs, and card numbers before sending the image to Groq. Masking is best-effort and cannot be guaranteed to identify every sensitive field. If masking cannot finish, the document is not sent unmasked.
Zero Data Retention is enabled on the Groq account. Groq still processes the document; this setting prevents inputs and outputs from being retained for system reliability or abuse monitoring. Groq continues to retain usage metadata that does not contain those inputs or outputs. Read Document Reading and Privacy for the complete flow.
7. Retention and account deletion
We retain account and financial records while your account is active so that we can provide the service. Documents and transaction attachments may be kept while associated with the relevant record and your account. Inactive session records are removed by a daily cleanup once they are more than 30 days old. Other records are retained only for as long as the purpose and applicable legal obligations require.
A data archive requested from your profile is stored privately for 7 days after it is completed and is then deleted automatically. Its signed download link is shorter-lived.
You can request account deletion from your profile. If you change your mind, you can cancel within 10 days. After that period, your account record and account-owned financial records, sessions, push subscriptions, files, and data archives are submitted for permanent deletion. We retain a limited destruction record to demonstrate the deletion; it uses a keyed digest instead of your email address.
8. Security
Safeguards include encryption in transit, password hashing, access restrictions, optional two-factor authentication, session controls, rate limits, self-hosted bot checks, and malware scanning for uploaded documents.
No internet service can guarantee absolute security. You can help protect your account by using a unique password, enabling two-factor authentication, and terminating any session you do not recognise from your profile.
9. Your choices and rights
- You can correct or delete profile and financial records from within the application.
- You can always use manual entry instead of document reading and manage masking from your profile.
- You can change email and web-notification preferences and revoke web-push permission in your browser.
- You can request a machine-readable archive of the information associated with your account from your profile.
- You can request account deletion or contact us to exercise your rights under the KVKK.
The available KVKK rights and application process are described in the rights section of the KVKK Notice.
10. Changes and contact
This policy took effect on 17 August 2026. If the data flows or services we use change materially, we will update this policy and show the new date on this page.
For privacy questions or requests, contact us at support@paratiq.app.