Who can see your records, and how you keep it that way.
Your records are kept apart from every other business’s, and each person you invite signs in with their own login. Plain answers first; the technical detail follows.
Last updated 29 Sept 2026.
Plain answers
- Who can see my records?
- You decide who joins your workspace. Each person you invite has their own login and a role that decides what they can change. Every record carries the business it belongs to, and the database checks that on every read and write, so one business cannot reach another’s records.
- Where are my documents kept?
- Your records and the files you attach, such as receipts and your logo, are stored by Supabase in its EU region in Stockholm. Receipts, invoices and statements you choose to have read, including invoices sent to your workspace’s inbox address, are sent to Anthropic to be read. Every provider is listed further down.
- How does my customer open an invoice?
- Through a private link with a long random key. NumWise keeps only a fingerprint of the key; the link expires, and you can withdraw it.
- How do I protect my sign-in?
- Turn on two-step sign-in in Settings, Security. After your password, NumWise asks for the code shown in an authenticator app such as Google Authenticator or Authy.
- What if I forget my password or lose my phone?
- Choose “Forgot password?” on the sign-in page and follow the link in the email. Resetting the password does not switch two-step sign-in off, and NumWise does not give backup codes. If you lose your authenticator app, email hello@numwise.eu from the address on your account. Once we have checked it is you, we switch two-step sign-in off so you can set it up again.
- Can I take my records with me?
- Yes. In Reports, Accountant pack brings a selected period into one ZIP with reports, registers and available attached documents. Its index identifies files that could not be included. The owner or an admin can also download an all-time Excel workbook of records from Settings, Organisation. After a trial or plan ends the workspace becomes read-only, and viewing and export stay open. If NumWise ever closes, we will tell you at least 60 days before, and export stays open the whole time.
The technical detail
- Each business sees only its own records
Every table carries the business it belongs to, and the database itself checks that on every read and write (row-level security). Automated tests try to reach one business’s records from another and must fail.
- Sign-in
Passwords need at least 8 characters with upper and lower case letters and a number, and passwords known from public data breaches are refused. Two-factor sign-in with an authenticator app can be turned on in Settings, Security.
- Support staff
NumWise support staff can open support requests only while signed in with two-factor verification.
- Invoice links
The link your customer opens carries a long random key. NumWise stores only a fingerprint of it; the link expires, can be withdrawn, and repeated guessing is slowed down.
- In transit and at rest
The site is served over HTTPS only. The database and stored files are held by Supabase, which encrypts data at rest.
- Bank data
Transactions arrive only in statement files you upload. NumWise never asks for your online banking login and has no connection to your bank.
- Card details
Card payments are entered on Stripe’s own pages. NumWise does not see or store card numbers.
Who processes your data, and where
These are the services NumWise uses to run. The legal terms, including how transfers outside the EU are protected, are in the privacy policy.
| Service | What it does for NumWise | Where |
|---|---|---|
| Supabase | Database, stored files (receipts, logos) and sign-in | EU: Stockholm region (eu-north-1) |
| Vercel | Delivers the website and the app to your browser | Global network; may be outside the EU |
| Anthropic | Reads the receipts, invoices and statements you choose to have read, and invoices sent to your inbox address | May be outside the EU, including the United States |
| ImprovMX | Sends NumWise’s own emails, such as sign-in emails, the welcome email and support replies, forwards email you send to numwise.eu addresses, and receives the invoices sent to your workspace’s inbox address | May be outside the EU |
| Stripe | Plan payments and, if you connect it, card payments on your invoices | May be outside the EU |
| Sentry | Error reports when something breaks in the app | May be outside the EU |
| Sign-in with Google if you choose it; sends your invoices if you connect Gmail; website analytics only if you agree | May be outside the EU |
Deleting an account
Ask us to delete your account from Settings, Profile, or as described on the account deletion page.
Found a problem?
If you think you have found a security problem, email hello@numwise.eu with what you saw and how to repeat it. Please do not test against other people’s accounts.
Try NumWise with your own records.
7-day free trial, no card needed. If you leave, you can export your records.