Security & privacy

Tax records deserve careful handling.

We treat financial documents as sensitive data. Access controls, tenant isolation, and explicit sharing rules are built into the architecture — not bolted on afterward.

Private storage

Documents are stored in a private object bucket. They are not publicly listable, and access requires authentication or a time-limited signed URL.

RLS tenant isolation

Row-level security policies restrict projects, documents, tax items, and evidence links to their owner. Database queries cannot cross tenant boundaries.

Signed URLs

Individual file downloads use short-lived signed links. Package generation runs under your authenticated session and copies linked records without altering originals.

No cross-app backend

Tax Proof Link runs on its own Supabase project with a separate identity boundary, storage bucket, and secrets — not shared with unrelated applications.

Sharing model

Project shares are token-based and revocable. Grantees receive read-only access after accepting an invite. Owners control expiration and can revoke access at any time.

Retention and deletion

When you delete a document, the storage object is removed before the database row. Account deletion workflows follow documented retention policies in our Privacy Policy.

Your responsibility

Tax Evidence Package Builder organizes supporting documents. It does not provide tax, legal, or accounting advice and does not prepare or file tax returns.

You control who receives share invitations. Only send links to trusted professionals and revoke access when collaboration ends.

Create a secure project