Legal
Your Xero financial data is fetched live for the purpose of analysis and is never written to a permanent database. Scan results live in server memory for up to 2 hours and are then automatically discarded.
When you use XeroClarity we collect:
We do not store the full contents of your Xero transactions, invoices, or journals. That data is fetched on demand for each scan and held in server memory only for the duration of your session (maximum 2 hours).
OAuth tokens are encrypted using AES-256-GCM before being written to the database. All connections use HTTPS/TLS. Server access is restricted to authorised personnel only.
You may disconnect your Xero organisation at any time from the XeroClarity landing page. To request account deletion or a copy of your stored data, contact us at support@thereconciliator.com.
We may update this policy. Changes will be posted on this page with a revised effective date. Continued use of the service constitutes acceptance of the updated policy.