Security & data handling

Process the job. Deliver the output. Delete the financial files.

The product architecture is built around a narrow promise: uploaded ledgers are temporary work material. They are not a dataset we want to keep.

What we never ask for

Deletion timeline

DataPlanned treatment
Uploaded financial filesDeleted at job completion; maximum 24-hour object-storage lifecycle backstop.
IntermediatesDeleted immediately after processing.
Generated PDFs and ZIPsDeleted after download or 24 hours, whichever comes first.
Job metadataCounts and status retained; no ledger rows or identity-linked amounts.
Owner mappings and brandingRetained until you delete them.
Owner closing balancesOptional, encrypted, and deletable in Settings. Turn storage off to re-enter opening balances each month.

Limited use of models

The initial commentary workflow is deterministic. If an optional language-model feature is added later, it is designed to receive only aggregated variance rows such as category, amount, and delta — never owner names, tenant names, or account numbers. Your uploaded financial data is not intended as model-training data.

Operational scope

This page describes UnitClose’s current production data-handling design. It is not a certification or audit report. Security controls and vendor configuration are reviewed as part of ongoing operations, and any material limitations are documented rather than implied away.

Ready for the next close?

Choose the plan that fits your portfolio.

Create or sign in to your secure UnitClose account. Your selected plan opens directly in Paddle checkout.