Security and data handling
The safest place for your ledger is your own computer, so that is where PaidTwice scans it. The file is never uploaded, and nothing from it leaves your browser unless you choose to save the flagged lines to your account.
Check it yourself in two minutes
You do not have to take our word for it. Your browser can show you every request this site makes.
- 1Open the scan page and your browser's developer tools (F12, or Cmd+Option+I on a Mac), then select the Network tab.
- 2Drop your export into PaidTwice and run the scan.
- 3Watch the Network tab: no request carries your file. You can even switch off your Wi-Fi once the scan page has loaded; the scan still works.
What is stored, and where
| Data | Stored? | Details |
|---|---|---|
| Your export file | Never stored | Read and scanned in your browser's memory, then discarded when you close the tab. |
| Lines that are not flagged | Never stored | They never leave your computer, on any plan. |
| Flagged lines | Only if you save an audit | Paid plans can save the findings shown on screen, with your status notes and recovered amounts. |
| Your account | Stored | Email address, a hashed password and any name, company and country you add. |
| Payments | Paddle | Paddle, our reseller, takes the payment. We receive its order and subscription references, never a full card number. |
| Enquiries | Stored | What you send through the contact form, so we can reply. |
| Visit statistics | Vercel | Vercel's cookieless statistics record the page address (with record IDs and any query details other than campaign tags removed), browser, device and country. |
How it is protected
The scan runs on your computer
The file is read and checked by code running in a background thread of your browser (a Web Worker). There is no upload step in the product, and the scanner has no way to send the file anywhere.
Your browser enforces it
Every page carries a Content Security Policy that only lets the browser connect to this site, our Supabase backend and Paddle's checkout. Any other destination is blocked by the browser itself.
Saved audits are private to your account
Saved audits live in a Supabase Postgres database in London (UK), encrypted at rest. Row-level security rules let each account read only its own audits; billing records are writable only by our server functions.
Encrypted in transit
All traffic uses HTTPS with HSTS. Other sites cannot frame our pages, and links to other sites pass on only our domain name, never the page address.
Passwords and sign-in
Passwords are handled by Supabase Auth and stored only as salted hashes. Sign-ups and contact messages are rate limited to slow down abuse.
You stay in control
Delete a saved audit, or your whole account and every audit in it, yourself from the app at any time.
Providers we use
Each provider only receives what it needs to run its part of the service. None of them ever receives your export file, because we never have it.
- Supabase
- Database, sign-in and server functions. Data stored in the London (UK) region.
- Vercel
- Hosting for the website, its content delivery network, and cookieless visit and speed statistics.
- Paddle
- Checkout, invoicing and tax, as our reseller and Merchant of Record.
- Resend
- Transactional email, where we use it.
What we do not claim
PaidTwice is run by a small team and does not hold SOC 2 or ISO 27001 certification. Because your ledger never reaches our servers, most of what those audits cover does not apply to the scan itself. If your organisation needs a security questionnaire answered, we are happy to help.
Reporting a vulnerability
If you find a security problem, please tell us before making it public, through the contact form. We will acknowledge it quickly and keep you updated.