Security
Last updated: July 12, 2026
At smyat.ai, protecting your information is a core part of how we build and operate the Service.
Security is not a single feature—it is an ongoing process involving infrastructure, software development, access controls, monitoring, and continuous improvement.
While no internet service can guarantee absolute security, we are committed to applying appropriate technical and organizational measures to protect the information entrusted to us.
Our Security Principles
Our security approach is based on five principles:
- collect only the data that is necessary;
- protect data throughout its lifecycle;
- limit access to authorized personnel;
- continuously improve our systems;
- respond quickly to security issues.
Data Protection
We use industry-standard security measures to protect information while it is transmitted and stored.
These measures include, where appropriate:
- encrypted network communication (HTTPS/TLS);
- authenticated access to protected resources;
- secure cloud infrastructure;
- infrastructure monitoring;
- access logging;
- regular software updates.
Authentication
User authentication is handled through Clerk, a trusted authentication platform.
Authentication features may include:
- secure account management;
- modern authentication standards;
- session management;
- account recovery;
- protection against unauthorized access.
Passwords are not stored directly by smyat.ai.
Receipt Security
Receipt images are uploaded only for the purpose of processing the requested bill.
To reduce long-term storage of personal information:
- uploaded receipt images are automatically deleted no later than 7 days after upload;
- only the processed bill information required for the Service is retained;
- users may delete their own bills and accounts.
This approach follows the principle of data minimization.
AI Processing
Receipt recognition uses trusted AI services to transform receipt information into structured bill data.
AI providers process information solely for the purpose of delivering the requested functionality.
Users should always review AI-generated results before relying on them.
Access Control
Access to production systems is limited to authorized personnel with a legitimate operational need.
Access permissions are granted according to the principle of least privilege and are reviewed as operational requirements evolve.
Third-Party Providers
To deliver the Service, we rely on carefully selected providers that maintain their own security programs.
Current providers include:
- Clerk
- Convex
- OpenAI
- Vercel
- Firebase Crashlytics
- PostHog
- Google Play Billing
Each provider is responsible for securing the services it operates on our behalf.
Monitoring
We continuously monitor the health and stability of the Service.
Monitoring may include:
- application performance;
- infrastructure availability;
- crash diagnostics;
- operational alerts;
- service reliability.
This information helps us identify and resolve technical issues as quickly as possible.
Responsible Disclosure
We appreciate reports of potential security vulnerabilities.
If you believe you have discovered a security issue affecting smyat.ai, please contact us at:
support@smyat.ai Please include as much relevant information as possible to help us investigate the issue.
We ask that you avoid actions that could compromise user privacy, disrupt the Service, or access data that does not belong to you.
User Responsibilities
Security is a shared responsibility.
Users can help protect their accounts by:
- keeping login credentials secure;
- using trusted devices;
- reviewing bills before sharing them;
- reporting suspicious activity;
- installing application updates when available.
Incident Response
If we become aware of a security incident affecting personal information, we will investigate the issue promptly.
Where required by applicable law, we will notify affected users and relevant supervisory authorities within the legally required timeframes.
We continuously review incidents to improve our systems and reduce the likelihood of similar events in the future.
Continuous Improvement
Security is an ongoing effort.
We regularly improve our infrastructure, software, monitoring, and operational practices as new technologies, risks, and industry standards evolve.
Our goal is to maintain a level of security appropriate to the nature of the Service and the information we process.
Questions?
Contact us at support@smyat.ai