Skip to content

SECURITY & DATA HANDLING

Financial documents.
Handled with care.

Your financial documents are sensitive. Here’s how ZentraSnap processes them, how long source files are kept, and which providers are involved.

See how your data is handled

FROM UPLOAD TO EXTRACTION

A clear path for
each kind of document.

Bank statements and invoices don’t follow the same processing route. Here’s what happens in each workflow.

Bank statements

Private temporary
cloud processing.

Statements use ZentraSnap’s own extraction pipeline, separate from Google Gemini.

  1. Private upload
  2. Extraction
  3. Cleanup
  • Private upload

    Statements are uploaded to a private Cloudflare R2 bucket using short-lived authorised upload URLs.

  • Dedicated inference

    Processing runs on Modal infrastructure using ZentraSnap’s document extraction model and OCR when required.

  • Short source-file retention

    The source statement is normally deleted after the extraction job completes or fails. Temporary R2 objects also have a one-day lifecycle expiry rule.

  • No training without separate agreement

    Production customer bank statements are not used to train ZentraSnap’s models unless the customer separately and expressly agrees.

Invoices & receipts

Extraction through
the paid Gemini API.

Google’s paid Gemini API returns structured financial fields from invoices and receipts.

  1. HTTPS transfer
  2. Paid API
  3. Structured fields
  • Encrypted transport

    Documents are transmitted over encrypted HTTPS connections to the processing service.

  • Paid-service data terms

    Google states that content submitted through paid Gemini services is not used to improve its products by default.

  • Provider retention still applies

    Google may retain limited request or response information for abuse prevention, security, logging, or legal purposes under its applicable terms and project settings.

  • No advertising profiles

    ZentraSnap does not sell invoice or receipt content or use customer documents for advertising profiles.

RETAIN LESS. EXPLAIN MORE.

Temporary processing.
Clear retention limits.

ZentraSnap is designed for document processing rather than a permanent archive of customers’ source financial documents.

Bank-statement source files

Normally deleted when the extraction job completes or fails. A one-day lifecycle expiry rule also covers temporary R2 objects.

Invoice & receipt processing

Paid Gemini terms apply. Limited provider retention can occur, so this workflow is not described as zero-retention processing.

THE INFRASTRUCTURE BEHIND THE WORKFLOW

Who helps process
your documents.

Each provider has a defined role in storage, extraction, or application hosting.

Cloudflare R2

Temporary bank-statement storage

Private object storage with encryption at rest and encrypted TLS transport.

Modal

Bank-statement processing & OCR

Modal states that user data is encrypted in transit and at rest and that it has completed a SOC 2 Type 2 audit.

Google

Invoice & receipt extraction

Paid Gemini API content is not used to improve Google products by default under Google’s paid-service terms.

Vercel

Application & API hosting

Vercel publishes SOC 2 Type 2 and ISO/IEC 27001 compliance information for its platform.

Provider certifications apply to those providers. They are not certifications of ZentraSnap itself.

A CLOSER LOOK

Questions about
your data.

The practical details behind document handling and retention.

Are my bank statements permanently stored?
A permanent archive of source bank statements is not part of the service. The source document is normally deleted after its extraction job completes or fails. Temporary R2 objects are also covered by a lifecycle rule configured to expire them after one day.
Are bank statements sent to Gemini?
Bank statements use ZentraSnap’s separate extraction pipeline: private temporary storage in Cloudflare R2, followed by processing on Modal using ZentraSnap’s document extraction model and OCR when required. Invoice and receipt extraction uses the paid Gemini API.
Are invoices and receipts used to train Gemini?
ZentraSnap uses the paid Gemini API. Google states that prompts, files, and responses from paid services are not used to improve its products by default. Limited retention may still occur for abuse prevention, security, logging, or legal purposes under the applicable terms and project settings.
Does ZentraSnap use my documents for training or advertising?
Production customer bank statements are not used to train ZentraSnap’s models unless the customer separately and expressly agrees. ZentraSnap does not sell invoice or receipt content or use customer documents for advertising profiles.
Where can I find the data protection terms?
Our Privacy Policy and Data Processing Agreement describe how personal data is processed and the roles of ZentraSnap and its customers. Customers remain responsible for having an appropriate lawful basis to process their clients’ data.