Legal

Privacy Policy

How Textrion handles account data, uploaded statements, and extraction results, including what we collect, what we share, and how you can delete your account.

Last updated: July 2026

Overview

Textrion (“we”, “us”) processes documents you upload (such as M-PESA statements, bank statements, and invoices) to return structured data for credit review, personal analysis, and related workflows. This policy explains what information we handle, why we handle it, and the choices available to you.

If you use a self-hosted or private deployment operated by another organization, that operator’s policies may also apply. The operator of your instance remains responsible for how they configure retention, hosting, and access.

What we collect

  • Account information: name (if provided), email, phone (if provided), password hashes, and authentication factors such as TOTP when you enable them.
  • Uploaded files: PDFs and other documents you submit for extraction, plus derived results (structured fields, transaction tables, integrity grades, and optional personal-analysis summaries).
  • Usage & billing metadata: page counts, document types, timestamps, API activity, plan and credit balances, and payment references needed to fulfill checkout (for example Paystack or M-PESA references). We do not store full card numbers on Textrion servers when payments are handled by a payment provider.
  • Support & feedback: messages you send through in-product support, and optional feedback when you delete an account.
  • Technical logs: IP addresses, user agents, and error logs used to secure the service and diagnose failures.

How we use data

We use your data to:

  • Provide extraction, dashboards, case/dossier workflows, exports, and add-ons you enable.
  • Authenticate you, enforce roles in team workspaces, and protect accounts against abuse.
  • Apply usage limits, issue invoices/receipts, and process payments.
  • Improve reliability, detect extraction regressions, and respond to support requests.
  • Prevent misuse of welcome or trial offers (for example blocking disposable signup emails).

We do not sell your document contents or extraction results to third parties. We do not use your uploaded statements to train public foundation models.

Documents & financial data

Uploaded statements often contain sensitive personal and financial information (account numbers, counterparties, balances, and transaction narratives). Treat Textrion as a processor of that data on your instructions: you decide what to upload, who on your team can access it, and when to delete it.

Personal analysis and credit-review features summarize patterns from extracted transactions for your review. Outputs are best-effort decision support, not credit bureau scores or lending decisions.

Sharing & processors

We share data only as needed to run the product:

  • Payment providers (for example Paystack or Safaricom Daraja) receive the minimum information required to complete checkout and confirm payment status.
  • Infrastructure providers that host the application, database, and object storage for your deployment.
  • Team members you invite to a workspace, according to the roles you assign.
  • Legal requests when we are required to disclose information by applicable law, or to protect the security and integrity of the service.

Retention & deletion

Extraction runs, uploaded files, and related history are retained while your account (or team workspace) remains active so you can review and export past results. Operators may configure retention windows for their deployment.

You can permanently delete your own account from Settings when eligible (invited corporate members must be removed by a team owner first). Deletion removes account access and associated extraction data we control for that account, subject to residual backups and records we must keep for fraud prevention, billing disputes, or legal compliance (for example welcome-offer abuse claims or payment receipts).

Security

Access to the dashboard and API is authenticated. Protect your password and API keys; enable available two-factor options where offered. Production deployments should use HTTPS and encrypted storage as configured by the hosting operator.

No method of transmission or storage is perfectly secure. If you believe your account or an API key has been compromised, rotate keys and contact support immediately.

Team workspaces

When you join or create a team, workspace owners and admins can see shared cases, runs, and member activity according to product permissions. Leave a team or ask an owner to remove you if you no longer want your account associated with that workspace.

Your rights

Depending on your jurisdiction and how your instance is operated, you may be able to:

  • Access and export extraction results from your dashboard.
  • Correct account profile details in Settings.
  • Delete your account (when eligible) or request deletion via support.
  • Ask questions about how a specific deployment stores or retains your files.

We will respond to reasonable privacy requests through the contact channels below.

Sessions & cookies

We use session cookies (or equivalent browser storage) to keep you signed in and to apply security controls. We do not use third-party advertising trackers on the core product flows described in this policy.

Changes

We may update this policy as the product evolves. The “Last updated” date at the top of the page will change when we do. Continued use of Textrion after an update means you accept the revised policy, to the extent permitted by law.

Contact

For privacy requests on the hosted service, email [email protected] or use in-product support after you sign in. If you use a privately operated deployment, contact that operator first.