Private storage
Documents are stored in a private object bucket. They are not publicly listable, and access requires authentication or a time-limited signed URL.
Security & privacy
We treat financial documents as sensitive data. Access controls, tenant isolation, and explicit sharing rules are built into the architecture — not bolted on afterward.
Documents are stored in a private object bucket. They are not publicly listable, and access requires authentication or a time-limited signed URL.
Row-level security policies restrict projects, documents, tax items, and evidence links to their owner. Database queries cannot cross tenant boundaries.
Individual file downloads use short-lived signed links. Package generation runs under your authenticated session and copies linked records without altering originals.
Tax Proof Link runs on its own Supabase project with a separate identity boundary, storage bucket, and secrets — not shared with unrelated applications.
Project shares are token-based and revocable. Grantees receive read-only access after accepting an invite. Owners control expiration and can revoke access at any time.
When you delete a document, the storage object is removed before the database row. Account deletion workflows follow documented retention policies in our Privacy Policy.
Your responsibility
Tax Evidence Package Builder organizes supporting documents. It does not provide tax, legal, or accounting advice and does not prepare or file tax returns.
You control who receives share invitations. Only send links to trusted professionals and revoke access when collaboration ends.