Pyro
Back to Pyro

Privacy Policy

Version 1.2 · Last updated 1 September 2026 · Operated by Trevor St. John, trading as Pyro, Malta

The short version

Pyro reads invoices for accounting firms and turns them into draft entries in Xero. To do that we handle two very different kinds of information, and we treat them differently:

  1. Information about you — your email address, your firm, what you do in the

app. We decide how this is used, so this policy governs it.

  1. The invoices you upload — we only handle these because your firm told us

to. Your firm decides what happens to them, not us. Those are covered by our Data Processing Agreement instead.

We do not sell your data. We do not use it for advertising. We do not run any analytics or tracking on our website. We do not let AI providers train on your invoices.


1. Who we are

Pyro is operated by Trevor St. John, an individual trading as "Pyro".

Based in: Malta — postal address available on request Email: support@pyroplatform.com

For anything in this policy, that email reaches a real person.


2. The two roles we play

This matters, so it's worth one clear paragraph.

Where we are the "controller" — we decide why and how information is used. This covers your user account, the details you give us when you ask to set up a firm, our billing records, and our security logs. This policy covers that.

Where we are the "processor" — we handle information purely on your firm's instructions and for its purposes. This covers everything inside the invoices and accounting documents you upload, and everything we read from your Xero organisation. Our DPA covers that, not this policy. If you are a supplier or customer whose details appear on an invoice someone uploaded to Pyro, the accounting firm — not Pyro — is who you should contact.


3. What we collect, and why

3.1 When you sign in

Pyro has no password system. You sign in with your Xero account, and Xero tells us your email address. That's it — we never see or store a password.

WhatWhyLegal basis
Email addressTo identify your account and let you inPerformance of a contract
Your role and firm membershipTo show you the right things and enforce permissionsPerformance of a contract

3.2 When you ask us to set up a firm

The form on our website collects:

WhatWhyLegal basis
Firm name, your name, email, phone (optional)To contact you and set up the accountSteps taken at your request before a contract
Rough number of clients and monthly invoicesTo suggest a suitable planSteps taken at your request before a contract

3.3 If you fill in one of our research surveys

If you complete a survey we've sent you, we collect your name, firm, email, phone and your answers. Legal basis: our legitimate interest in understanding what accounting firms need. You can ask us to delete this at any time and we will.

3.4 While you use Pyro

WhatWhyLegal basis
A record of actions taken on each invoice (who did what, when)So your firm has an audit trail, and so we can investigate problemsPerformance of a contract; our legitimate interest in a reliable service
Security events — sign-ins, Xero connections, admin changesTo detect and investigate misuseLegal obligation (GDPR security duty); legitimate interest in security
Usage and cost records for billingTo bill you accurately and show you what you've spentPerformance of a contract

3.5 Payments

Payments go through Stripe. Stripe collects your card details directly on its own hosted checkout — we never see or store your card number. We keep your Stripe customer reference and the amounts charged.


4. The documents you upload

When your firm uploads an invoice, here is exactly what happens:

  1. The file is stored in our private, encrypted file storage. It is not public

and has no shareable link.

  1. If we've already learned that supplier's layout, we read it locally. It

is never sent anywhere.

  1. Otherwise, the document is sent to an AI provider to be read

Anthropic, OpenAI or Google, depending on which tier your firm has chosen.

  1. The extracted result is shown to a person on your team to review. Nothing is

posted to Xero automatically without someone seeing it as a draft.

We handle these documents as a processor on your firm's instructions. See the DPA for the full detail.

What we send to AI providers, and what they do with it

We send only the document content needed to read the invoice. We do not send them our database, your other clients, or anything else about you.

Under the terms currently in force with each provider:

API, and deletes API inputs and outputs within 30 days (longer only where content is flagged for safety reasons or the law requires it).

API inputs and outputs for up to 30 days for abuse monitoring before deleting them, unless legally required to keep them.

paid service to improve its products. Unlike Anthropic and OpenAI, Google does not commit to a fixed number of days for how long it keeps this content — its own terms say only that it is logged "for a limited period of time" for abuse detection. Google also does not commit to processing this content only in the United States the way the other two do.

We want to be precise here: we do not have a "zero retention" arrangement with any of these three providers. So it would be wrong for us to tell you your invoices are never stored by them. What we can tell you honestly is that none of them use your documents to train their models, and Anthropic and OpenAI both delete them within 30 days.


5. Xero

Xero is your own accounting system, not ours. When your firm connects a Xero organisation, you authorise us to:

so we can code invoices correctly

Everything we post to Xero is a draft. Pyro never approves or authorises anything in your accounts.

We store the token that keeps the connection alive. It is encrypted before it is written to our database, so it is not readable from the database alone.


6. Who else handles your information

These are the only third parties involved:

WhoWhat they doWhere
SupabaseOur database and file storageParis, France (EU)
VercelRuns our applicationEU-proximate edge; US company
AnthropicAI reading of invoices (Nova / Atlas)United States
OpenAIAI reading of invoices (Apex)United States
GoogleAI reading of invoices (Pulse)Not limited to one country — see above
StripePaymentsUnited States / Ireland

That's the complete list. There is nobody else.


7. Cookies, analytics and tracking

We do not use any analytics or tracking. No Google Analytics, no Facebook pixel, no advertising cookies, no session recording, no third-party trackers of any kind. We're not being modest — there genuinely aren't any.

We do not use cookies to track you. To keep you signed in, we store your session token in your browser's local storage. That is strictly necessary to operate the service and is not used to follow you anywhere.

No third-party requests, either. Our fonts are served from our own domain rather than from Google Fonts, so simply loading a Pyro page does not reveal your IP address to Google or anyone else. Everything the page needs comes from us.


8. Where your information goes

Your account data and your uploaded documents are stored in the European Union (Paris, France).

Your information leaves the EU in two situations:

  1. When a document is read by AI — Anthropic and OpenAI process it in the

United States. Google (the Pulse tier) does not commit to processing it in any single country.

  1. Hosting and payments — Vercel and Stripe are US companies.

These transfers are covered by Standard Contractual Clauses, the transfer mechanism approved by the European Commission, for all three AI providers. We can provide evidence on request.


9. How long we keep things

Your firm decides. In Billing & wallet, a firm owner can set a retention period — after that many days we automatically delete the original files you uploaded. A job runs daily to do it. The extracted figures and coding stay, because that's your accounting data, and the same file is already attached to the draft in your Xero.

We don't set a period for you. Until your firm chooses one, we keep documents until you delete them. That's deliberate — you know your own record-keeping obligations and we don't, and quietly deleting a firm's invoices on an assumption would be far worse than keeping them. The shortest period we accept is 30 days.

WhatHow long
Your account and firm recordsUntil the account is closed, then deleted within 30 days
Original uploaded filesYour firm's retention period, if set — otherwise until you delete them
Extracted figures and codingUntil you delete the client, or the account closes
Security event logKept indefinitely — it's an integrity record we don't edit or delete
Billing recordsKept as long as Maltese tax law requires
Survey responsesUntil you ask us to delete them

You can also delete a client — and all of its documents, files, coding history and audit trail — from inside the app at any time. That deletion is real, not a flag.


10. How we protect your information

(AES-256-GCM) before they're stored, so they aren't readable from the database alone.

credential, which lives only in our hosting platform's environment settings — never in our source code.

enforced on every single request.

or delete.

What we don't claim. We are a small operation and we'd rather say so than imply otherwise. Pyro does not hold ISO 27001 certification, has not completed a SOC 2 audit, and has not had an independent penetration test. No system is perfectly secure, and we won't pretend ours is.


11. Your rights

Under the GDPR you can ask us to:

Email support@pyroplatform.com. We'll respond within one month. There's no charge unless a request is clearly excessive or repetitive, and we'd tell you before charging anything.

If your details appeared on someone's invoice: we hold that information for an accounting firm, not for ourselves. Please contact that firm. If you're not sure who they are, write to us and we'll pass your request to them.


12. Complaints

If we've got something wrong, tell us first — we'd like the chance to fix it.

You also have the right to complain to the Maltese data protection authority:

Office of the Information and Data Protection Commissioner (IDPC) Floor 2, Airways House, High Street, Sliema SLM 1549, Malta https://idpc.org.mt

If you live in another EU country, you can complain to your local authority instead.


13. Children

Pyro is a business tool for accounting professionals. It is not intended for anyone under 18, and we don't knowingly collect children's data. If you think a child has given us information, tell us and we'll delete it.


14. Automated decision-making

Pyro uses AI to suggest how an invoice should be coded. It does not make decisions about people. Every suggestion is reviewed by a person on your team before anything is posted. There is no automated decision-making that produces legal effects for any individual.


15. Changes to this policy

If we change this policy we'll update the version number and the date at the top. For significant changes affecting your rights, we'll email firm owners. Previous versions are kept and available on request.


16. Contact

Trevor St. John, trading as Pyro Malta · postal address available on request support@pyroplatform.com


Privacy Policy v1.2 — last updated 1 September 2026.