PaidTwice

Security and data handling

The safest place for your ledger is your own computer, so that is where PaidTwice scans it. The file is never uploaded, and nothing from it leaves your browser unless you choose to save the flagged lines to your account.

Check it yourself in two minutes

You do not have to take our word for it. Your browser can show you every request this site makes.

  1. 1Open the scan page and your browser's developer tools (F12, or Cmd+Option+I on a Mac), then select the Network tab.
  2. 2Drop your export into PaidTwice and run the scan.
  3. 3Watch the Network tab: no request carries your file. You can even switch off your Wi-Fi once the scan page has loaded; the scan still works.

What is stored, and where

What PaidTwice stores for each kind of data
DataStored?Details
Your export fileNever storedRead and scanned in your browser's memory, then discarded when you close the tab.
Lines that are not flaggedNever storedThey never leave your computer, on any plan.
Flagged linesOnly if you save an auditPaid plans can save the findings shown on screen, with your status notes and recovered amounts.
Your accountStoredEmail address, a hashed password and any name, company and country you add.
PaymentsPaddlePaddle, our reseller, takes the payment. We receive its order and subscription references, never a full card number.
EnquiriesStoredWhat you send through the contact form, so we can reply.
Visit statisticsVercelVercel's cookieless statistics record the page address (with record IDs and any query details other than campaign tags removed), browser, device and country.

How it is protected

The scan runs on your computer

The file is read and checked by code running in a background thread of your browser (a Web Worker). There is no upload step in the product, and the scanner has no way to send the file anywhere.

Your browser enforces it

Every page carries a Content Security Policy that only lets the browser connect to this site, our Supabase backend and Paddle's checkout. Any other destination is blocked by the browser itself.

Saved audits are private to your account

Saved audits live in a Supabase Postgres database in London (UK), encrypted at rest. Row-level security rules let each account read only its own audits; billing records are writable only by our server functions.

Encrypted in transit

All traffic uses HTTPS with HSTS. Other sites cannot frame our pages, and links to other sites pass on only our domain name, never the page address.

Passwords and sign-in

Passwords are handled by Supabase Auth and stored only as salted hashes. Sign-ups and contact messages are rate limited to slow down abuse.

You stay in control

Delete a saved audit, or your whole account and every audit in it, yourself from the app at any time.

Providers we use

Each provider only receives what it needs to run its part of the service. None of them ever receives your export file, because we never have it.

Supabase
Database, sign-in and server functions. Data stored in the London (UK) region.
Vercel
Hosting for the website, its content delivery network, and cookieless visit and speed statistics.
Paddle
Checkout, invoicing and tax, as our reseller and Merchant of Record.
Resend
Transactional email, where we use it.

What we do not claim

PaidTwice is run by a small team and does not hold SOC 2 or ISO 27001 certification. Because your ledger never reaches our servers, most of what those audits cover does not apply to the scan itself. If your organisation needs a security questionnaire answered, we are happy to help.

Reporting a vulnerability

If you find a security problem, please tell us before making it public, through the contact form. We will acknowledge it quickly and keep you updated.

Read the privacy policy