Privacy Policy
Last updated July 4, 2026
Pariom ("we," "us," or "our") operates pariom.ai. This policy explains what data we collect, how we use it, and your rights.
1. What we collect
Account data. When you sign up, we collect your email address and, if you provide it, your name and company name. This is stored in our database (Supabase, on AWS infrastructure).
Reconciliation data. When you set up a check, we store the metric name, the values returned by each side, tolerance settings, and the resulting cases, rulings, and definitions your team records. If you connect a database or warehouse (Postgres or Snowflake) as a check source, we store the connection credentials encrypted at rest (AES-256-GCM), and use them only to run the SELECT query you configure — never to write to your systems. If you push values to us directly, only the values and labels you send are stored.
Financial memo data. If you use the legacy variance-memo tool, we process your trial balance data to produce the memo. We store the output (the structured memo, P&L summary, variance rows, and narrative) — not the raw trial balance rows you uploaded. Your raw CSV or QuickBooks data is processed in memory and discarded immediately after the memo is generated.
QuickBooks / Xero connection. If you connect QuickBooks Online or Xero, we store OAuth tokens (access token and refresh token) to enable re-authentication. We use read-only access scopes and never write to your accounting system. Tokens are stored server-side and never exposed to the browser.
Usage data. We log check runs, case and ruling events, memo generation events, view counts on shared memos, and email delivery records (for the weekly digest and Monday brief). We do not use third-party analytics trackers.
Payment data. Pariom does not currently process payments — billing is not active during the beta period. If paid plans launch, billing will be handled by Stripe and this policy will be updated before any card is charged.
2. How we use your data
We use your data to: run the reconciliation checks and generate memos you configure; power the AI-drafted diagnostic briefs and Q&A features; send the weekly trust digest and Monday morning brief (if you opt in); send transactional emails; respond to support requests; and detect abuse or security issues.
We do not sell your data. We do not use your data to train AI models. We do not share your data with third parties except as described below.
3. Third-party services
We use the following sub-processors:
- Supabase — Postgres database, authentication, and row-level security enforcement (AWS-hosted).
- Vercel — application hosting, cron scheduling, and edge network.
- Anthropic — Claude, used for diagnostic briefs, memo generation, and Ask Pariom queries. Anthropic's API does not use API inputs to train models by default. See Anthropic's privacy policy at anthropic.com/privacy.
- Resend — transactional email delivery (digests, briefs, alerts).
- Upstash — Redis-based rate limiting on unauthenticated API endpoints. No customer financial data is stored.
- Intuit / Xero — QuickBooks Online and Xero OAuth. Read-only access only.
- Stripe — reserved for future payment processing. Not active during the beta period.
4. Data retention
We retain your account data, checks, cases, rulings, definitions, and generated memos for as long as your account is active. If you delete your account, your data is permanently deleted within 30 days. You can request deletion at any time by emailing ask@pariom.ai.
Raw trial balance data (CSV uploads, QuickBooks/Xero transaction data) is never persisted — it exists only in server memory during memo generation and is discarded immediately after.
5. Security
We implement the following security measures:
- All data in transit encrypted via TLS
- Database encrypted at rest (Supabase/AWS)
- Row-level security on every database table — users can only access their own organization's data
- Database and warehouse credentials for reconciliation checks encrypted at rest with AES-256-GCM, decrypted only server-side at check-run time
- OAuth tokens stored server-side only, never in the browser
- Read-only QuickBooks/Xero access — we cannot modify your books
- Outbound connections for reconciliation checks are restricted to public hosts — private and internal network ranges are blocked
6. Your rights
You have the right to access, correct, or delete your personal data at any time. To exercise these rights, email ask@pariom.ai. We will respond within 30 days.
If you are located in the European Economic Area, you have additional rights under GDPR including the right to data portability and the right to lodge a complaint with a supervisory authority.
7. Cookies
We use only essential cookies: an authentication session cookie (set by Supabase Auth) and a short-lived OAuth state cookie (for QuickBooks connection). We do not use advertising or tracking cookies.
8. Children
Pariom is not directed at children under 13. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email. Continued use of Pariom after changes constitutes acceptance of the updated policy.
10. Contact
Questions about this policy? Email ask@pariom.ai.