Legal / Privacy

Privacy policy

Last updated: 29 September 2026

Who operates Proof Entry

Proof Entry is operated by Qualascend FZ LLE, registered in Fujairah, United Arab Emirates. Our registered address is Office 1309, Fujairah Creative Tower, 4422, Fujairah, UAE. Contact us at hello@proofentry.app.

We administer account, billing, support and security information. You determine what business records you submit and must have authority to share information about clients, suppliers and other people.

Information we handle

  • Account details: name, email, verification status, authentication identifiers and sessions. Password authentication stores a password hash.
  • Ledger content: income, expenses, categories, clients, projects, tax details, notes, receipt files and forwarded-email content.
  • Optional AI activity: chat messages, extraction results, proposals, review actions and usage counters.
  • Billing references, subscription and payment status. Stripe handles payment details on its hosted checkout and billing pages.
  • Support correspondence and technical records used to operate and protect the service, such as request metadata, errors and security logs.

Google sign-in

If you choose Google, we request only your basic identity: an account identifier, email and verification status, and profile information such as your name and picture. We use this to create or authenticate your Proof Entry account and link eligible verified accounts. When Google verifies ownership of an existing unverified account, we preserve its ledger and replace its previous sign-in and agent access.

Google sign-in does not grant access to Gmail, Drive, Calendar or your contacts. We store authentication records needed for sign-in; provider access and refresh tokens, when stored, are encrypted. You can revoke access in your Google Account. Revocation does not by itself delete your Proof Entry account or ledger.

Why information is used

We use information to provide the ledger and requested capture features, authenticate users, administer subscriptions, respond to support requests, prevent abuse and meet legal obligations. Depending on the applicable law and relationship, these purposes rely on providing the requested service, legitimate interests in its operation and protection, or legal obligations. Consent is used where required for optional processing.

We do not sell ledger content or Google sign-in information or use them for advertising. This policy does not authorize training general AI models on your records.

Providers and optional integrations

Cloudflare hosts the application, database, files and hosted AI features. AWS SES delivers account emails. Google provides optional sign-in, and Stripe processes payments. Support email is hosted by Zoho. These providers receive information needed for their respective functions.

When you use hosted chat or receipt extraction, relevant content is sent to the configured AI provider. The current hosted provider is Cloudflare Workers AI. When you connect your own agent, it can receive ledger information through the access you authorize; its provider has its own terms and privacy practices. Review agent proposals before confirming.

Processing may take place outside your country, including through distributed infrastructure. We do not promise country-exclusive hosting. Contact us for information about applicable processing arrangements and transfer safeguards. We may disclose records when legally required or necessary to protect the service and people.

Storage, cookies and deletion

Session cookies support authentication and security. Browser storage remembers preferences such as your theme. Blocking necessary cookies can prevent sign-in.

Ledger and receipt records remain available for the service unless removed. Production cleanup targets agent-action snapshots older than 180 days, chat messages older than 365 days and deleted ledger entries older than 30 days. Cleanup runs in batches; these are not promises of immediate deletion of every related file, log or backup.

Receipt files and raw extraction objects have separate storage and are not automatically erased by the database cleanup above. Account, billing, support and security records may need to be retained for service operation, legal obligations or dispute handling. Contact us to request account closure or discuss deletion of related records.

Your choices and rights

You can correct ledger entries and export reports in the app. Depending on applicable law, you may also request access, correction, deletion, portability or restriction, object to processing, withdraw consent or complain to a competent data-protection authority. Legal exceptions may apply. Send requests to hello@proofentry.app; we may verify your identity and authority. Do not send passwords or API keys.

The service is intended for adults managing business records. Contact us if a child's information was submitted improperly. We will date policy revisions and provide notice of material changes as required.