Privacy Policy
Effective August 9, 2026
AP Control is an invoice-control service operated by AP Control Labs, a Colorado business in formation. This policy explains how we handle information when you use the AP Control console, API, MCP tools, marketplace endpoints, or support channel.
Information we process
We process account and organization details, API-key metadata, invoice and purchase-order documents or normalized data you submit, extraction evidence, duplicate and matching results, review decisions, webhook configuration, usage records, pseudonymous page-view and conversion events, private-preview request details, and support communications. Preview-request contact details are encrypted at rest and used only to review access and contact you about that preview. API keys are stored as hashes and are shown only once when created.
How we use it
We use this information to authenticate users, operate and secure the service, extract invoice fields, perform duplicate and match checks, deliver webhook events, enforce trial and usage limits, understand whether public documentation and purchase paths work, investigate errors, and provide support. AP Control does not sell personal information or invoice data, use it for advertising, or use Customer Content to train a general-purpose model. It does not write to accounting systems, initiate payments, or alter accounting records.
Retention and deletion
Source invoice documents are encrypted in private object storage and are retained for 30 days by default. Your organization may choose 0, 7, 30, 90, or 365 days. Structured invoice records and audit metadata are retained for one year by default so results remain explainable. Expired source documents are scheduled for deletion. You may request deletion or ask a retention question through the contact address below; we may retain limited information where needed for security, fraud prevention, billing records, or legal obligations.
Service providers
We use Supabase for authentication and database services; Railway for application hosting; Cloudflare R2 for private document storage; AWS Textract for invoice-aware OCR; Stripe for billing when billing is enabled; and, when configured, Sentry for privacy-preserving error monitoring. These providers process information only to provide their services to us, subject to their terms and data practices.
If you choose to access AP Control through a third-party marketplace or agent directory, that provider may process your account identifier, credential, request metadata, usage, and billing information under its own terms and privacy policy. Use a dedicated revocable API key for each third-party connection.
Security
We use tenant-scoped access controls, hashed API keys, encrypted stored documents and secrets, short-lived private upload and download URLs, signed webhooks, request limits, audit logging, structured logs, and privacy-preserving error monitoring when configured. No system is perfectly secure, so customers should protect API keys, use least-privilege access, and avoid submitting information they are not authorized to provide.
Your choices
You can manage organization access, revoke API keys, configure document retention, and control webhook delivery through the console. You may contact us to request access, correction, or deletion of account information, subject to verification and applicable law.
Changes and contact
We may update this policy as the service evolves. We will post the revised policy here with a new effective date and, when material, provide notice through the console or account email.
Privacy and deletion requests: apcontrollabs.support@gmail.com · Data Processing Addendum