Reconlio Privacy Policy

Effective date: September 20, 2026 · Last updated: September 20, 2026

This Privacy Policy explains what personal data Reconlio collects, why, and what you and your organization can do about it. It applies to reconlio.com and the Reconlio application (together, the “Service”), operated by Reconlio (“we,” “us”).

Reconlio is a business-to-business product built for managed service providers (MSPs). Because of that, this policy describes two different relationships, and they matter for different reasons:

1. Information We Collect

1.1 Account and billing information. Name, work email, company name, and role, collected at registration. Payment details are collected and processed directly by our payment processor (Paddle or Stripe) — Reconlio does not store your card number.

1.2 Customer Data you upload or connect.

  • Invoice files (PDF, CSV, or XLSX) you upload for parsing.
  • Roster data: employee/user email addresses, display names, department, and active/inactive status — either uploaded as a CSV or synced automatically from a Microsoft 365 or Google Workspace directory you (or your client, via our self-serve connection-link flow) authorize us to read.
  • If you connect Microsoft 365 or Google Workspace, we store an OAuth access/refresh token for that connection so we can perform the sync you requested. These tokens are encrypted at rest and are never visible in plaintext, including to Reconlio staff, outside of the running application's own decryption at the moment of use.

1.3 Usage and audit data. We log account actions (logins, uploads, plan changes, and similar state-changing actions) with the acting user, timestamp, and IP address, for security, audit, and troubleshooting purposes.

1.4 Cookies. We use two first-party cookies for authentication: a session cookie that is not readable by JavaScript and carries no information beyond an opaque session token, and a separate, non-sensitive display cookie carrying only your name/email/role so the interface can render correctly. We do not use third-party advertising or tracking cookies.

Language preference is stored in a first-party cookie for one year and in local storage to synchronize tabs. It contains only en, ar or es; no customer data is sent to a translation service.

2. How We Use Information

We use the information above to: provide and operate the Service (parsing invoices, running reconciliations, syncing rosters, generating reports); authenticate you and protect your account; process payments (through our payment processor); send transactional email (account confirmations, password resets, billing notices) via our email provider, Postmark; respond to support requests sent to [email protected]; and maintain the security and integrity of the Service, including the audit log described in Section 1.3.

We do not sell personal data, and we do not use Customer Data to train AI models beyond the specific parsing call described in Section 3 below.

3. AI-Assisted Invoice Parsing

When you upload an invoice, its content is sent to a third-party large-language-model API — currently one of Anthropic, OpenAI, or Groq, depending on which provider Reconlio is configured to use — solely to extract structured line-item data (vendor, quantities, pricing) from the document. This is a per-request API call, not a fine-tuning or model-training relationship; the invoice content is not used by Reconlio, or knowingly permitted to be used by that provider, to train models outside of that provider's own standard API terms, which you can review directly from the relevant provider. We recommend avoiding uploading invoices containing information beyond what's needed for licensing reconciliation.

Limited Use compliance (Google Workspace / Microsoft 365 data). The AI-assisted parsing described above is the only point at which any AI or machine-learning model touches product data, and it operates exclusively on the invoice files you upload directly (Section 1.2). Roster data synced from a connected Google Workspace or Microsoft 365 directory — names, work email addresses, department, and active/inactive status — is used solely to build and reconcile your license roster and is never sent to, or accessible by, any AI or LLM provider. In line with the Limited Use requirements of the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, data Reconlio obtains through a connected Google Workspace directory will not be used, transferred, or sold to develop, improve, or train generalized or foundational AI or machine-learning models, whether in raw, aggregated, or derived form.

4. Who We Share Information With

We share information only as needed to run the Service, with the following categories of third-party processors (our full, current list is available on request at [email protected]):

  • Cloud hosting and storage: invoice files are stored in encrypted object storage (S3-compatible) with a defined retention period (Section 5); the application itself runs on cloud infrastructure operated by our hosting provider.
  • AI/LLM providers: Anthropic, OpenAI, or Groq (whichever is active), as described in Section 3.
  • Payment processing: Paddle (which, for most subscriptions, is the merchant of record for your subscription and processes your payment information under its own privacy policy) or, for some pre-existing accounts, Stripe.
  • Transactional email: Postmark, to deliver account and billing emails.
  • Legal requirements: we may disclose information if required by law, subpoena, or similar legal process, or to protect the rights, property, or safety of Reconlio, our customers, or others.

We do not share Customer Data across tenants — every account's data is isolated from every other account's, enforced at the database query level.

5. Data Retention

  • Invoice files are retained in storage for 90 days by default lifecycle policy, after which they are automatically expired. Extracted line-item data and reconciliation results are retained as part of your account's history until you delete them or close your account.
  • Audit logs (Section 1.3) are retained for up to 2 years, in line with standard security-recordkeeping practice.
  • Account data is retained for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, or dispute-resolution obligations, after which it is deleted or anonymized.
  • OAuth tokens are deleted when you disconnect an integration or close your account.

6. Your Rights and Choices

Depending on where you and your organization are located, you may have rights to access, correct, export, or delete the personal data we hold about you, or to object to or restrict certain processing. To exercise any of these rights, contact us at [email protected]. If the data in question is roster/client data uploaded by an MSP on behalf of their own client (see “Who Controls What” above), we will generally direct that request to the MSP, since they — not Reconlio — control that relationship, unless law requires otherwise.

You can delete your account at any time from Settings, or by writing to us; this removes your account data and Customer Data from active systems, subject to the retention exceptions in Section 5 and any copies retained in backups until they age out of the backup cycle.

7. International Data Transfers and Regional Storage

Reconlio's infrastructure runs in a single hosting region (Saudi Arabia Central, Riyadh). For more information, contact us at [email protected].

8. Security

We apply a defense-in-depth approach appropriate to the sensitivity of the data involved: passwords are hashed (never stored in plaintext), OAuth integration tokens are encrypted at rest, data in transit is encrypted via TLS, invoice files are stored with encryption at rest, and access to customer data is isolated per account and logged. Reconlio has completed an automated security baseline scan (OWASP ZAP) with no critical- or high-severity findings, and we continue to monitor and strengthen these protections — though no method of transmission or storage is ever 100% secure.

9. Children's Privacy

The Service is intended for business use by adults acting on behalf of their organization and is not directed at, or knowingly used to collect data from, children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide reasonable notice of material changes (for example, by email to your account's registered address or a notice within the Service) before they take effect.

11. Contact

Questions about this policy, or requests regarding your data: [email protected].

Terms of Service · Back to Reconlio