Last updated: August 30, 2026
Frequently asked questions
Straight answers about data, AI, and deletion. If your question is not here, email kontakt@pavora.se.
Data and storage
What data do you collect?
Account (name, email, hashed password), payment status and token balance via Stripe, one session cookie, and the bookkeeping data the service needs to answer you. No ad tracking. No analytics telemetry in the browser.
Where do my books live?
With your accounting provider. If you have connected Fortnox, Visma, Kleer, or Bokio, that system is the statutory archive under Swedish bookkeeping law (7 years). Pavora keeps no readable copy of production books — vouchers we fetch to render reports are encrypted into your on-device vault. Pavora Huvudbok in our database is the demo environment for trying the AI — envelope-encrypted in the database, not stored in plaintext. If any bookkeeping in the demo environment is older than 24 hours, the entire demo environment is wiped every night.
How long is demo environment data kept?
Pavora Huvudbok is stored envelope-encrypted in our database — not in the client vault. If any bookkeeping in the demo environment is older than 24 hours, the entire demo environment for that organization is wiped every night (cron): vouchers, invoices, bank, payroll, chart of accounts, and fiscal years — including manual entries and imports. It is not an archive for production books — connect Fortnox etc. when you go live.
What is the vault, and what lives in it?
Chat, receipts, the reports we build for you, and the mask maps are encrypted with AES-256-GCM in the browser before anything is written. Choose “This device only” and it all stays local. Choose “Encrypted cloud” and we hold a copy we cannot open — the key never leaves your device. Private chats are invisible to colleagues. Shared chats (when you invite selected members) are end-to-end encrypted: a key is generated in your browser and unlocked only for the people you invite — Pavora cannot open the content even if we wanted to. OAuth tokens (Fortnox, Visma, Bokio, Kleer), the organisation's own language model key (BYOK), and SIE/snapshot files in export/import history live client-encrypted in the shared org vault — ciphertext with us, key material on devices that can unlock the vault. The owner saves BYOK under Settings → Language model; everyone in the organisation uses it. On each call the browser sends decrypted secrets in flight (X-Pavora-Vault).
What is a shared chat?
You can create a shared chat and invite colleagues in your organisation. Content is end-to-end encrypted: each invitee gets their own encrypted copy of the key, and we cannot open it — the same thing already true of private chats. Removing someone's access rotates the key, so they lose access to anything after that point; a copy they already pulled to their device is not automatically deleted. The agent only replies when someone writes @Pavora — otherwise it's just the two (or more) of you talking, and nothing goes to the AI model.
What happens to receipts I email to the inbox?
Postmark receives the email. We hold the attachment encrypted for 30 days so everyone in the organisation can pull it into their own vault — we hold that key, unlike the vault. AI reading runs when the email arrives and is drawn from the organisation’s token balance. After 30 days the transit copy is deleted. Once you have pulled the receipt it lives in your vault under “This device only” or “Encrypted cloud”.
Can Pavora read my books?
Not what is in the personal vault or org vault — we do not have the key to the ciphertext. But OAuth tokens, BYOK keys, and masked LLM text pass our server in flight per request: Fortnox and Visma require a confidential OAuth client, so the browser sends the token via X-Pavora-Vault and we proxy the API calls. “We do not store plaintext” is not the same as “we never see it.” We never store card numbers.
AI and language models
Which AI model do you use, and how long do they keep the data?
By default Claude (Anthropic) through their API — Claude Sonnet 5 for chat and receipt reading, Claude Haiku 4.5 as a topic filter. They do not train on API traffic. They retain prompts and completions for 30 days (flagged material up to 2 years). Zero Data Retention requires a separate contract we do not have. The model name comes from the running configuration and is shown under Settings → Language model.
Can I use my own API key?
Yes, on Pro and above. Under Settings → Language model the organisation owner connects Anthropic, OpenAI, Mistral, or Google. Chat, receipt reading, and the topic filter then run on your key — Pavora tokens are not deducted — and retention/ZDR follows the agreement you have with that provider. The key is stored client-encrypted in the organisation's shared org vault; all members use it. On each call the browser decrypts the key and sends it in flight (X-Pavora-Vault). Removing the key deletes our ciphertext — rotate or revoke the key at the provider if you want to shut off access. We still have no Zero Data Retention agreement of our own for Pavora's key.
How do I scrub data before it reaches Claude?
Auto-masking is on by default. Before anything is sent to the model, personal ID numbers, company registration numbers, IBANs, email, phone, bank account numbers, addresses, person names, and supplier and customer names are replaced with placeholders — in your messages, filenames, and receipt extraction, and in tool results from ledger reads. The agent pauses after each tool call: the result goes back to your browser, is masked there, and only then does the agent continue. The placeholders are random rather than derived from the value, so they cannot be worked backwards. Your chat always shows the originals — the mapping lives in your vault. Turn on “Ask before send” to review each time.
What does Claude see when I send an image?
The pixels. We can mask text and filenames, not the contents of a photographed receipt. That is why we warn before images go out.
Deletion and GDPR
How do I delete my account?
Primarily under Account in the app (/app/account/konto) — you can also download your data there. Alternatively email kontakt@pavora.se from the account address. We remove the account, sessions, and — if you are alone in the organization — its data. Payment records we are required to keep under Swedish bookkeeping law stay with Stripe for 7 years.
Are inactive accounts deleted automatically?
GDPR sets no fixed deadline, but it does require that we not keep data longer than necessary. The policy: 24 months without activity → email → deletion after 30 days if you do not sign in. Active subscriptions (and manually assigned plans) are exempt, because the contract is still running. It runs as a scheduled job.
What happens if I switch computers or clear my browser?
With “Encrypted cloud” on: sign in on the new computer and unlock the vault with the recovery key under Settings → Vault. With “This device only”: chat and receipts existed only there and are gone. Your books at Fortnox and Visma are unaffected either way.
What if I lose the recovery key?
Then that vault stays shut — we hold no copy of the key and cannot recreate it. Under Settings → Vault you can wipe it and start a new one; chat and receipts in the old vault are gone. Books at Fortnox and Visma are unaffected. Write the new key down before you lock again.
About us
Are you ISO 27001 certified?
No. ISO 27001 is a management system — policy, risk, audit — not an encryption switch. The product work (data minimization, masking, retention, DPA) is evidence that counts the day we certify. Certification typically takes 6–18 months with outside help.
Why should I trust you?
We do not sell your data. You pay for tokens and plans, which makes data a liability for us rather than a product. Read the tables on the privacy and security pages, look at the cookies in your browser, and email kontakt@pavora.se if something does not add up.