What Rakhlo stores and how it is protected.
Account data
Rakhlo uses Supabase Auth for account authentication. Session cookies are handled server-side through the Supabase SSR integration.
Your purchase data
Purchases, reminders, warranty information, payment records and document metadata are stored in Supabase Postgres. The application’s tables use Row Level Security with ownership rules based on the authenticated user.
Uploaded files
Purchase documents are stored in a private Supabase Storage bucket. Upload and download access uses signed URLs. Rakhlo accepts only purchase-proof document categories (such as receipts, invoices, warranty cards and payment proofs), limited to PDF, JPEG, PNG and WebP files up to 10 MB with basic file-signature validation. Rakhlo is not intended to be a general-purpose image or file host and prohibits sexually explicit content.
Notifications and offline data
When browser notifications are enabled, a web-push subscription is stored so scheduled reminders can be delivered. Rakhlo also keeps queued purchase drafts in your browser’s local storage so they can be submitted when connectivity returns. The public Purchase Print Tool is different: its working data stays in the current page and is never sent to or stored by Rakhlo.
Deletion and requests
For privacy questions or a request to review or delete information, contact us through the Support form. The exact retention of provider-level authentication records may be subject to the underlying service provider’s infrastructure and policies.