Who Guardian is
Guardian (https://guardianbi.com) is a business intelligence product operated by Guardian. Guardian turns uploaded business evidence — receipts, invoices, payments, statements — into a structured, traceable model of how a business actually operates.
Information we collect
Account information. When you create a Guardian account, we collect your email address, and optionally your phone number and full name.
Business/organization information. When you set up an organization, we collect its legal name, display name, country, currency, and business type.
Uploaded evidence. Documents and images you upload — receipts, invoices, payments, bank statements, and similar business records — are stored in Guardian's evidence storage, scoped to your organization.
Financial and business records. Structured business data derived from your evidence: transactions, counterparties (suppliers, customers, people you do business with), and the relationships between them.
Extracted information. When you upload a document, Guardian uses AI to extract structured data from it (dates, amounts, parties, line items). See "AI processing" below for how this works.
Usage and activity information. Guardian keeps an activity log of actions taken in your organization (confirmations, reclassifications, review decisions) — some performed by you, some by Guardian's AI. Guardian also tracks patterns in corrections you make, so it can learn and suggest applying a pattern going forward — this is never applied automatically without your action.
Cookies and session data. Guardian uses cookies to keep you signed in and manage your session, via Supabase Authentication. We do not use cookies for advertising or cross-site tracking.
Device or browser information. Guardian does not currently use any third-party analytics or tracking SDK. Standard technical logs (such as IP address and request metadata) may be generated by our infrastructure providers for security and reliability, as is standard for any web application — Guardian itself does not collect this for profiling or analytics purposes.
How we use information
- To provide the core Guardian service: turning your evidence into a searchable, traceable business record.
- To generate findings, extracted data, and answers to your questions within Guardian.
- To maintain your account, your organization's membership, and access control.
- To keep an audit trail of actions taken on your data, for your own transparency.
- To operate, secure, and improve the reliability of the service.
We do not sell your information, and we do not use your business or financial data for advertising.
AI processing
When you upload a document, Guardian sends that document (as an image or PDF) to Anthropic's Claude API to extract structured data from it — for example, reading a receipt and identifying the amount, date, and vendor. This is how Guardian's core evidence-extraction feature works.
Numerical and arithmetic results derived from extraction are independently verified in Guardian's own code rather than trusted directly from the AI's output, but the underlying extraction — reading what a document says — is AI-assisted and can be imperfect. Guardian's findings and summaries are also AI-assisted.
Third-party processors
The following third parties process data on Guardian's behalf:
- Supabase — our database, file storage, and authentication provider. Your account data, organization data, and uploaded evidence files are stored with Supabase.
- Anthropic — provider of the Claude AI models Guardian uses to extract data from uploaded evidence and to power AI-assisted features like Ask Guardian. Anthropic's own privacy policy governs its processing of that data.
TODO: CONFIRM ANY ADDITIONAL PROVIDERS — for example, if a separate email delivery provider, hosting provider, or error-monitoring tool is added, it must be listed here before this policy is considered complete.
Data storage and security
Your data is stored in Supabase, using row-level access controls scoped to your organization. Uploaded evidence files are stored in a dedicated storage bucket, namespaced by organization so that one organization's files cannot be accessed through another organization's access path.
TODO: CONFIRM SUPABASE PROJECT REGION / HOSTING REGION
No system is completely secure. We take reasonable technical measures to protect your data, but we cannot guarantee absolute security.
Data retention
Guardian retains your organization's data for as long as your organization exists on Guardian. There is currently no automatic time-based deletion of active organizations' data. Data is removed when you delete your organization — see the next section for exactly how that works.
Account and organization deletion
Guardian's deletion is organization-level: from Settings, an organization owner can permanently delete the organization. This removes the organization's database records (transactions, counterparties, findings, activity history) immediately and irreversibly. The organization's uploaded evidence files are then deleted from storage and this is verified rather than assumed — if that verification cannot be confirmed, the file cleanup is marked as needing to be completed later, though the organization's core data has already been removed regardless of that outcome. There is currently no automated retry for a failed storage cleanup.
Deleting an organization affects every member of that organization, not just the person who requests it. For full details, see our Data Deletion page.
Data export
From Settings, you can export a JSON file containing everything Guardian has recorded for your organization — counterparties, transactions, findings, business memory, and activity history. The uploaded document files themselves are not included in this export, only their metadata.
Your privacy rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Guardian supports these directly in-product: account and organization details are viewable and editable in Settings, data export is available on demand, and organization deletion is available on demand. For anything not available directly in-product, contact us at kaykiti21@gmail.com.
International data processing
TODO: CONFIRM WHETHER INTERNATIONAL DATA TRANSFERS APPLY, based on where Guardian's infrastructure runs and where its users are located. This section should be completed with accurate detail (or removed if not applicable) before submission.
Children's privacy
Guardian is a business tool and is not directed at, or intended for use by, individuals under 18. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as Guardian changes. We'll update the "Last updated" date above when we do. Material changes will be communicated through the product where practical.
Contact
Questions about this policy or your data can be sent to kaykiti21@gmail.com.