
Pyro
Pyro reads invoices for accounting firms and turns them into draft entries in Xero. To do that we handle two very different kinds of information, and we treat them differently:
app. We decide how this is used, so this policy governs it.
to. Your firm decides what happens to them, not us. Those are covered by our Data Processing Agreement instead.
We do not sell your data. We do not use it for advertising. We do not run any analytics or tracking on our website. We do not let AI providers train on your invoices.
Pyro is operated by Trevor St. John, an individual trading as "Pyro".
Based in: Malta — postal address available on request Email: support@pyroplatform.com
For anything in this policy, that email reaches a real person.
This matters, so it's worth one clear paragraph.
Where we are the "controller" — we decide why and how information is used. This covers your user account, the details you give us when you ask to set up a firm, our billing records, and our security logs. This policy covers that.
Where we are the "processor" — we handle information purely on your firm's instructions and for its purposes. This covers everything inside the invoices and accounting documents you upload, and everything we read from your Xero organisation. Our DPA covers that, not this policy. If you are a supplier or customer whose details appear on an invoice someone uploaded to Pyro, the accounting firm — not Pyro — is who you should contact.
Pyro has no password system. You sign in with your Xero account, and Xero tells us your email address. That's it — we never see or store a password.
| What | Why | Legal basis |
|---|---|---|
| Email address | To identify your account and let you in | Performance of a contract |
| Your role and firm membership | To show you the right things and enforce permissions | Performance of a contract |
The form on our website collects:
| What | Why | Legal basis |
|---|---|---|
| Firm name, your name, email, phone (optional) | To contact you and set up the account | Steps taken at your request before a contract |
| Rough number of clients and monthly invoices | To suggest a suitable plan | Steps taken at your request before a contract |
If you complete a survey we've sent you, we collect your name, firm, email, phone and your answers. Legal basis: our legitimate interest in understanding what accounting firms need. You can ask us to delete this at any time and we will.
| What | Why | Legal basis |
|---|---|---|
| A record of actions taken on each invoice (who did what, when) | So your firm has an audit trail, and so we can investigate problems | Performance of a contract; our legitimate interest in a reliable service |
| Security events — sign-ins, Xero connections, admin changes | To detect and investigate misuse | Legal obligation (GDPR security duty); legitimate interest in security |
| Usage and cost records for billing | To bill you accurately and show you what you've spent | Performance of a contract |
Payments go through Stripe. Stripe collects your card details directly on its own hosted checkout — we never see or store your card number. We keep your Stripe customer reference and the amounts charged.
When your firm uploads an invoice, here is exactly what happens:
and has no shareable link.
is never sent anywhere.
Anthropic, OpenAI or Google, depending on which tier your firm has chosen.
posted to Xero automatically without someone seeing it as a draft.
We handle these documents as a processor on your firm's instructions. See the DPA for the full detail.
We send only the document content needed to read the invoice. We do not send them our database, your other clients, or anything else about you.
Under the terms currently in force with each provider:
API, and deletes API inputs and outputs within 30 days (longer only where content is flagged for safety reasons or the law requires it).
API inputs and outputs for up to 30 days for abuse monitoring before deleting them, unless legally required to keep them.
paid service to improve its products. Unlike Anthropic and OpenAI, Google does not commit to a fixed number of days for how long it keeps this content — its own terms say only that it is logged "for a limited period of time" for abuse detection. Google also does not commit to processing this content only in the United States the way the other two do.
We want to be precise here: we do not have a "zero retention" arrangement with any of these three providers. So it would be wrong for us to tell you your invoices are never stored by them. What we can tell you honestly is that none of them use your documents to train their models, and Anthropic and OpenAI both delete them within 30 days.
Xero is your own accounting system, not ours. When your firm connects a Xero organisation, you authorise us to:
so we can code invoices correctly
Everything we post to Xero is a draft. Pyro never approves or authorises anything in your accounts.
We store the token that keeps the connection alive. It is encrypted before it is written to our database, so it is not readable from the database alone.
These are the only third parties involved:
| Who | What they do | Where |
|---|---|---|
| Supabase | Our database and file storage | Paris, France (EU) |
| Vercel | Runs our application | EU-proximate edge; US company |
| Anthropic | AI reading of invoices (Nova / Atlas) | United States |
| OpenAI | AI reading of invoices (Apex) | United States |
| AI reading of invoices (Pulse) | Not limited to one country — see above | |
| Stripe | Payments | United States / Ireland |
That's the complete list. There is nobody else.
We do not use any analytics or tracking. No Google Analytics, no Facebook pixel, no advertising cookies, no session recording, no third-party trackers of any kind. We're not being modest — there genuinely aren't any.
We do not use cookies to track you. To keep you signed in, we store your session token in your browser's local storage. That is strictly necessary to operate the service and is not used to follow you anywhere.
No third-party requests, either. Our fonts are served from our own domain rather than from Google Fonts, so simply loading a Pyro page does not reveal your IP address to Google or anyone else. Everything the page needs comes from us.
Your account data and your uploaded documents are stored in the European Union (Paris, France).
Your information leaves the EU in two situations:
United States. Google (the Pulse tier) does not commit to processing it in any single country.
These transfers are covered by Standard Contractual Clauses, the transfer mechanism approved by the European Commission, for all three AI providers. We can provide evidence on request.
Your firm decides. In Billing & wallet, a firm owner can set a retention period — after that many days we automatically delete the original files you uploaded. A job runs daily to do it. The extracted figures and coding stay, because that's your accounting data, and the same file is already attached to the draft in your Xero.
We don't set a period for you. Until your firm chooses one, we keep documents until you delete them. That's deliberate — you know your own record-keeping obligations and we don't, and quietly deleting a firm's invoices on an assumption would be far worse than keeping them. The shortest period we accept is 30 days.
| What | How long |
|---|---|
| Your account and firm records | Until the account is closed, then deleted within 30 days |
| Original uploaded files | Your firm's retention period, if set — otherwise until you delete them |
| Extracted figures and coding | Until you delete the client, or the account closes |
| Security event log | Kept indefinitely — it's an integrity record we don't edit or delete |
| Billing records | Kept as long as Maltese tax law requires |
| Survey responses | Until you ask us to delete them |
You can also delete a client — and all of its documents, files, coding history and audit trail — from inside the app at any time. That deletion is real, not a flag.
(AES-256-GCM) before they're stored, so they aren't readable from the database alone.
credential, which lives only in our hosting platform's environment settings — never in our source code.
enforced on every single request.
or delete.
What we don't claim. We are a small operation and we'd rather say so than imply otherwise. Pyro does not hold ISO 27001 certification, has not completed a SOC 2 audit, and has not had an independent penetration test. No system is perfectly secure, and we won't pretend ours is.
Under the GDPR you can ask us to:
Email support@pyroplatform.com. We'll respond within one month. There's no charge unless a request is clearly excessive or repetitive, and we'd tell you before charging anything.
If your details appeared on someone's invoice: we hold that information for an accounting firm, not for ourselves. Please contact that firm. If you're not sure who they are, write to us and we'll pass your request to them.
If we've got something wrong, tell us first — we'd like the chance to fix it.
You also have the right to complain to the Maltese data protection authority:
Office of the Information and Data Protection Commissioner (IDPC) Floor 2, Airways House, High Street, Sliema SLM 1549, Malta https://idpc.org.mt
If you live in another EU country, you can complain to your local authority instead.
Pyro is a business tool for accounting professionals. It is not intended for anyone under 18, and we don't knowingly collect children's data. If you think a child has given us information, tell us and we'll delete it.
Pyro uses AI to suggest how an invoice should be coded. It does not make decisions about people. Every suggestion is reviewed by a person on your team before anything is posted. There is no automated decision-making that produces legal effects for any individual.
If we change this policy we'll update the version number and the date at the top. For significant changes affecting your rights, we'll email firm owners. Previous versions are kept and available on request.
Trevor St. John, trading as Pyro Malta · postal address available on request support@pyroplatform.com
Privacy Policy v1.2 — last updated 1 September 2026.