Legal
Privacy Policy.
last updated · June 2026
Bank statements are about as sensitive as data gets. This policy says exactly what Obsrv Technologies LLP collects, what happens to a statement after you upload it, and when it is deleted. The short version: statements are processed in India, raw files are deleted after analysis by default (your organization may opt into a retention vault), and your data is never sold or used to train models.
What we collect
- Account data, your email address, organization name, sign-in timestamps, and the team members you invite.
- Statements, the PDF/CSV files you upload, including any password you provide to open a protected PDF (held only while the job runs, then erased).
- Derived reports, the extracted ledger, computed metrics, and verdict for each statement you analyze.
- Billing records, an append-only ledger of credit grants and debits. We never see or store card or bank credentials; payments are handled by a payment provider.
How statements are processed
Uploaded files are encrypted in transit and at rest and processed in India (AWS ap-south-1, Mumbai). AI is used to transcribe the document; every amount is then re-checked deterministically against the running balance. Statement content is used to produce your report, nothing else. It is not used to train models, not shared between customers, and not sold to anyone.
When data is deleted
- Raw statement files. By default, deleted immediately after a successful analysis (24-hour backstop for jobs that fail or stall). If your organization enables the retention vault, originals are kept until you delete them; a deletion you request is held briefly for compliance, then permanently purged. You can download or delete a retained file at any time.
- Partially processed documents, kept up to 7 days so you can top up and resume the remaining pages, then deleted. This is the one disclosed exception.
- PDF passwords, erased the moment a job reaches a final state.
- Reports and the credit ledger, retained for your account so past analyses stay auditable; deleted within 30 days of account closure (statutory accounting records may be kept longer where law requires).
Applicant data and your responsibilities
When you upload an applicant's statement, you are the data fiduciary under India's Digital Personal Data Protection Act, 2023, and Obsrv processes the data on your instructions. You are responsible for having the applicant's consent or another lawful basis. If an applicant writes to us directly, we will verify and route the request to you, and assist with erasure of anything we still hold.
Who else touches the data
We use a small set of subprocessors, each only for what is listed:
- Amazon Web Services (India region), compute, storage, queueing, and AI model inference (Amazon Bedrock).
- Supabase (AWS Mumbai region), managed Postgres database hosting.
- Zoho, transactional email: sign-in codes and team invites.
- Vercel, hosting for this website (not for statement processing).
We disclose data to authorities only when legally compelled, and we tell you unless the law forbids it.
Cookies and tracking
The console stores your session token and preferences in your own browser's local storage. We do not run third-party advertising trackers. If we add product analytics, it will be first-party and disclosed here first.
Your choices
- Export any report as PDF or JSON at any time.
- Ask for your account and its data to be deleted, email us; deletion completes within 30 days.
- Rotate API keys yourself; sessions expire after 7 days.
Changes and contact
Material changes to this policy are announced to your account email before they take effect. Privacy questions and requests → [email protected].