Beta. Reconlio does not yet have a separately registered legal entity (a UAE Freezone company is in the process of being formed) and this policy has not yet been reviewed by an attorney. It is published now, in this form, so we can be transparent about our real data practices during our early-access period rather than publishing nothing at all. It will be superseded by a finalized version once our legal entity is registered and the document has had a legal review. Questions in the meantime: [email protected].

Reconlio Privacy Policy

Effective date: August 22, 2026 · Last updated: August 22, 2026

This Privacy Policy explains what personal data Reconlio collects, why, and what you and your organization can do about it. It applies to reconlio.com and the Reconlio application (together, the “Service”), currently operated by Reconlio (“we,” “us”) — see the Beta notice above regarding our legal entity status.

Reconlio is a business-to-business product built for managed service providers (MSPs). Because of that, this policy describes two different relationships, and they matter for different reasons:

1. Information We Collect

1.1 Account and billing information. Name, work email, company name, and role, collected at registration. Payment details are collected and processed directly by our payment processor (Paddle or, for some existing accounts, Stripe) — Reconlio does not store your card number.

1.2 Customer Data you upload or connect.

  • Invoice files (PDF, CSV, or XLSX) you upload for parsing.
  • Roster data: employee/user email addresses, display names, department, and active/inactive status — either uploaded as a CSV or synced automatically from a Microsoft 365 or Google Workspace directory you (or your client, via our self-serve connection-link flow) authorize us to read.
  • If you connect Microsoft 365 or Google Workspace, we store an OAuth access/refresh token for that connection so we can perform the sync you requested. These tokens are encrypted at rest and are never visible in plaintext, including to Reconlio staff, outside of the running application's own decryption at the moment of use.

1.3 Usage and audit data. We log account actions (logins, uploads, plan changes, and similar state-changing actions) with the acting user, timestamp, and IP address, for security, audit, and troubleshooting purposes.

1.4 Cookies. We use two first-party cookies for authentication: a session cookie that is not readable by JavaScript and carries no information beyond an opaque session token, and a separate, non-sensitive display cookie carrying only your name/email/role so the interface can render correctly. We do not use third-party advertising or tracking cookies.

2. How We Use Information

We use the information above to: provide and operate the Service (parsing invoices, running reconciliations, syncing rosters, generating reports); authenticate you and protect your account; process payments (through our payment processor); send transactional email (account confirmations, password resets, billing notices) via our email provider, Postmark; respond to support requests sent to [email protected]; and maintain the security and integrity of the Service, including the audit log described in Section 1.3.

We do not sell personal data, and we do not use Customer Data to train AI models beyond the specific parsing call described in Section 3 below.

3. AI-Assisted Invoice Parsing

When you upload an invoice, its content is sent to a third-party large-language-model API — currently one of Anthropic, OpenAI, or Groq, depending on which provider Reconlio is configured to use — solely to extract structured line-item data (vendor, quantities, pricing) from the document. This is a per-request API call, not a fine-tuning or model-training relationship; the invoice content is not used by Reconlio, or knowingly permitted to be used by that provider, to train models outside of that provider's own standard API terms, which you can review directly from the relevant provider. We recommend avoiding uploading invoices containing information beyond what's needed for licensing reconciliation.

4. Who We Share Information With

We share information only as needed to run the Service, with the following categories of third-party processors (our full, current list is available on request at [email protected]):

  • Cloud hosting and storage: invoice files are stored in encrypted object storage (S3-compatible) with a defined retention period (Section 5); the application itself runs on cloud infrastructure operated by our hosting provider.
  • AI/LLM providers: Anthropic, OpenAI, or Groq (whichever is active), as described in Section 3.
  • Payment processing: Paddle (which, for most subscriptions, is the merchant of record for your subscription and processes your payment information under its own privacy policy) or, for some pre-existing accounts, Stripe.
  • Transactional email: Postmark, to deliver account and billing emails.
  • Legal requirements: we may disclose information if required by law, subpoena, or similar legal process, or to protect the rights, property, or safety of Reconlio, our customers, or others.

We do not share Customer Data across tenants — every account's data is isolated from every other account's, enforced at the database query level.

5. Data Retention

  • Invoice files are retained in storage for 90 days by default lifecycle policy, after which they are automatically expired. Extracted line-item data and reconciliation results are retained as part of your account's history until you delete them or close your account.
  • Audit logs (Section 1.3) are retained for up to 2 years, in line with standard security-recordkeeping practice.
  • Account data is retained for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, or dispute-resolution obligations, after which it is deleted or anonymized.
  • OAuth tokens are deleted when you disconnect an integration or close your account.

6. Your Rights and Choices

Depending on where you and your organization are located, you may have rights to access, correct, export, or delete the personal data we hold about you, or to object to or restrict certain processing. To exercise any of these rights, contact us at [email protected]. If the data in question is roster/client data uploaded by an MSP on behalf of their own client (see “Who Controls What” above), we will generally direct that request to the MSP, since they — not Reconlio — control that relationship, unless law requires otherwise.

You can delete your account at any time from Settings, or by writing to us; this removes your account data and Customer Data from active systems, subject to the retention exceptions in Section 5 and any copies retained in backups until they age out of the backup cycle.

7. International Data Transfers and Regional Storage

Reconlio's infrastructure currently runs in a single hosting region (Saudi Arabia Central, Riyadh), and we do not currently offer a dedicated EU-resident storage option. If you or your organization are located in, or process personal data of individuals located in, the European Economic Area, the United Kingdom, or another jurisdiction with data-residency requirements, please contact us at [email protected] before uploading personal data so we can discuss whether Reconlio is presently suitable for that use case. This is an active gap we intend to close, not a permanent design decision.

8. Security

We apply a defense-in-depth approach appropriate to the sensitivity of the data involved: passwords are hashed (never stored in plaintext), OAuth integration tokens are encrypted at rest, data in transit is encrypted via TLS, invoice files are stored with encryption at rest, and access to customer data is isolated per account and logged. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. As of this policy's date, Reconlio has completed an automated security baseline scan (OWASP ZAP) with no critical- or high-severity findings, but has not yet completed an independent, manual third-party penetration test.

9. Children's Privacy

The Service is intended for business use by adults acting on behalf of their organization and is not directed at, or knowingly used to collect data from, children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide reasonable notice of material changes (for example, by email to your account's registered address or a notice within the Service) before they take effect.

11. Contact

Questions about this policy, or requests regarding your data: [email protected].

Terms of Service · Back to Reconlio