Pavora

Last updated: August 30, 2026

Privacy policy

This policy describes how Pavora (the service at pavora.se), owned and operated by org. no. 559189-2897, processes personal data under the EU General Data Protection Regulation (GDPR).

See for yourself

  • No analytics or ad telemetry loads on pavora.se.
  • No third-party tracking pixels.
  • Only the cookies required for sign-in and language.

Where the books live

Production books live with Fortnox, Visma, Kleer, or Bokio — they are the statutory archive. Pavora stores no readable copy of the books: vouchers we fetch for reports are encrypted with AES-256-GCM in your browser, as are private chats and receipts in the vault. Choose encrypted cloud and we hold a copy we cannot open.

Private chats are visible only to you — colleagues cannot even see that they exist. When you share a chat with selected members, content is end-to-end encrypted: a key is generated in your browser and unlocked individually for each invitee — we only ever store ciphertext and cannot open it, not even for support.

Exception: receipts emailed to the org inbox are held encrypted for 30 days so every member can pull them into their vault. We hold that key — we can open the transit copy, unlike the vault. After 30 days it is deleted.

In our database, Pavora Huvudbok (the demo environment), agent proposals, OCR extractions, audit logs, and notifications are envelope-encrypted per organization (AES-256-GCM) — we can technically open them with the same server-held key. If any bookkeeping in the demo environment is older than 24 hours, the entire demo environment for that organization is wiped automatically every night. What stays readable is account structure, status, dates, and integration metadata (connected systems — not token or key values; those are client-encrypted ciphertext in the org vault). SIE and snapshot files in export/import history are stored as client-encrypted ciphertext in object storage (same org vault DEK) — we cannot read file contents at rest; metadata in the audit log is envelope-encrypted. Stripe integration keys for nightly sync are an exception: server-encrypted so cron can run without a signed-in user.

OAuth tokens, BYOK keys, and masked LLM text pass our server in flight per request (X-Pavora-Vault header or proxy to bookkeeping/Claude). “We do not store plaintext” is not the same as “we never see it.”

Controller

The controller is org. no. 559189-2897, which owns and operates Pavora (pavora.se). Contact us at kontakt@pavora.se.

What data we process

  • Account details: name, email address, and password (stored hashed).
  • Payment and credit: subscription status, balance, and transaction history. Card details are handled by Stripe — we do not store full card numbers.
  • Usage: chat messages, uploaded documents (e.g. receipts and invoices), AI suggestions, approvals, and technical logs.
  • Receipt inbox: attachments emailed to the organisation’s inbox address. Held encrypted with us for 30 days so every member can pull them into their vault, and read by AI when they arrive.
  • Integrations: connections to bookkeeping systems (e.g. Fortnox, Kleer, Bokio; Visma coming soon). OAuth and API tokens and SIE/snapshot history are stored client-encrypted in the organisation's shared org vault (AES-256-GCM ciphertext with us). On each API call your browser decrypts the token and sends it in flight via the X-Pavora-Vault header; we use it in memory for that call.
  • Session and device data needed for sign-in and desktop linking.

Purposes and legal bases

  • Contract — to provide the account, AI assistant, bookkeeping features, and support.
  • Legal obligation — bookkeeping and accounting of our own business transactions.
  • Legitimate interest — to protect the service against abuse, troubleshoot, and improve the product (in a way that does not override your rights).

AI — which model and what they retain

By default, chat and document analysis go through Anthropic's API with Pavora's key. They do not train on API data. Default retention is 30 days (flagged prompts up to 2 years). We have no Zero Data Retention agreement.

On Pro you can connect your own key (Anthropic, OpenAI, Mistral, or Google); then that provider's terms and any ZDR agreement you have apply, and Pavora tokens are not deducted.

Auto-masking is on by default: personal ID numbers, company registration numbers, IBANs, email, phone, bank account numbers, addresses, person names, and supplier and customer names are replaced with random placeholders before anything is sent to the model.

When the agent reads the ledger through tools, it pauses — the tool result goes back to your browser, is masked there, and only then does the agent continue.

On Pro the organisation owner can connect their own key (Anthropic, OpenAI, Mistral, or Google). It is stored client-encrypted in the same shared org vault as OAuth tokens — ciphertext with us, key material only on devices that can unlock the vault. Everyone in the organisation uses it for chat. On each call the browser decrypts the key and sends it in flight (X-Pavora-Vault); we use it in memory and do not store plaintext. Removing the key in Pavora only deletes our ciphertext — rotate or revoke the key at the provider if you want to shut off access.

ModelProviderTrains on API dataRetentionPurpose
Claude Sonnet 5AnthropicNo30 daysChat and document analysis
Claude Haiku 4.5AnthropicNo30 daysTopic filter before the main model runs

Provider data retention

Processors

We share data with providers needed to run the service, including: Bookkeeping providers you connect yourself (Fortnox and others; Visma when support launches)

ProviderRoleRegion
SupabaseDatabase and file storageEU
VercelHosting, serverless functionsEU (Stockholm)
StripePaymentsEU / US with SCC
AnthropicAI models (Claude) — default, or your own keyUS with SCC
OpenAIAI models — only if you connect your own keyUS with SCC
MistralAI models — only if you connect your own keyEU
GoogleAI models (Gemini) — only if you connect your own keyUS/EU with SCC
Fortnox / Visma / Kleer / BokioBookkeeping you connect yourselfPer their terms
PostmarkTransactional email and any receipt inboxUS with SCC

Some providers may process data outside the EU/EEA. In that case appropriate safeguards are used, e.g. the European Commission’s standard contractual clauses, where required.

Cookies and sign-in

We only use necessary cookies. No analytics, no ads, no third-party telemetry in the browser. You can verify this in DevTools.

NameWhereContentsPurposeTTL
redovis_sessioncookieOpaque session keyKeep you signed in30 days
NEXT_LOCALEcookiesv | enLanguage preference1 year

How long we keep data

DataPeriodBasis
Account and profileWhile the account is activeContract
Inactive account24 months without activity, then email and deletion after 30 days. Active subscriptions are excluded.Storage limitation (GDPR art. 5)
Chat and receipts in the vaultOn your device, AES-256-GCM. The server holds empty stubs, or ciphertext if you chose encrypted cloud. Conversations from before the vault existed are migrated into it automatically the first time you open the app with it unlocked — the server is zeroed for those too.Contract
Receipt inbox (transit)Up to 30 days after the email arrives. Encrypted with us using a key we hold, so every organisation member can pull a copy into their vault. The transit copy is then deleted. What is already in the vault follows the row above.Contract
Conversation titleGenerated locally from your own first message, not by the server. The server never sees the content it comes from.Contract
Shared chatsEnd-to-end encrypted (AES-256-GCM), key held only by invited devices — we cannot open it. Kept until the conversation is unshared or deleted.Contract
Bookkeeping system connection (Fortnox, Visma, Bokio, Kleer)Client-encrypted in the organisation's shared org vault (AES-256-GCM ciphertext with us). OAuth for Fortnox and Visma; API tokens for Bokio and Kleer. Decrypted in the browser and sent in flight per call (X-Pavora-Vault). Kept until you disconnect or the organization is deleted — disconnecting deletes our ciphertext, not the token at the provider (rotate there if you want to shut off access).Contract
SIE / snapshot history (export, import, pre-clear backup)File bytes client-encrypted in object storage with the org vault DEK (AES-256-GCM) — we cannot open contents at rest. Metadata (filename, period) envelope-encrypted in the audit log. Kept until the organization is deleted.Contract
Own AI key (BYOK)Client-encrypted in the same org vault as OAuth tokens. The organisation owner saves the key under Settings → Language model; all members use it. Sent in flight per call (X-Pavora-Vault). Kept until the owner removes it — then our ciphertext is deleted; rotate or revoke the key at the provider separately.Contract
Reports from Fortnox and othersIn your on-device vault. No readable copy with us.Contract
AI usage (tokens, amounts, model — not prompt text)As long as billing requires, then anonymizedContract / our own accounts
Our own payment records (Stripe)7 yearsSwedish Bookkeeping Act
Session30 daysSecurity
Anthropic (prompt + completion)30 days at AnthropicTheir API terms

Your rights (GDPR)

You have the right to:

  • receive information about and access to your personal data
  • request correction of inaccurate data
  • request erasure ("the right to be forgotten")
  • request restriction of processing
  • object to processing based on legitimate interest
  • receive data in a portable format (data portability)
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se imy.se

Download your data

You can download a copy of your personal data under Account (/app/account/konto) when signed in — the "Download my data" button. That is the primary way. If you need help, email kontakt@pavora.se from the account address.

Delete account

You can delete your account and related personal data at any time. Do it primarily under Account (/app/account/konto) when signed in. If you cannot access the account, email from the address linked to the account to kontakt@pavora.se with the subject line "Delete my Pavora account". We confirm and carry out deletion without undue delay, normally within 30 days, unless law requires certain data to be kept longer (e.g. payment records).

Contact

Questions about personal data, your rights, or this policy: kontakt@pavora.se. Terms of use and the bookkeeping disclaimer are under Terms of use. Terms of use.

Back to homepage