← Back home

Security & safety

Protection for both the file and the financial meaning.

Security is more than keeping a document private. RecehKu also protects exact amounts, account boundaries, and decisions made from your records.

Last updated Jul 22, 2026

  1. No bank credentialsRecehKu reads documents you provide and never asks for your banking password or PIN.
  2. Files are screenedUploads are checked before they enter the financial-document processing path.
  3. Records do not move moneyRecehKu organizes information. It cannot transfer funds or place a trade.

Protection in layers

  • Account access. Passwords are stored as one-way hashes. Browser sessions use an HttpOnly, host-only cookie, while only a hash of the opaque session credential is stored.
  • Upload screening. RecehKu checks file size and content, scans uploads for malware, and uses hardened PDF tools for document handling.
  • Space boundaries. Authenticated requests are scoped to the current space and role. Guest files live in a separate, short-lived area.
  • Protected secrets. A reusable document password is stored only when you deliberately add one, using authenticated encryption tied to its space.
  • IP addresses. Session IP addresses are stored securely with restricted access. Each view is recorded in the activity history.
  • Abuse controls. Rate limits, guest quotas, email confirmation, and restricted administrative access reduce automated and unauthorized use.

Improvement-data boundary

Uploaded PDFs and images never enter RecehKu’s contribution dataset. When contribution is on, only a separate structured copy reaches the staging boundary after names, free text, document links, account details, participant identities, and application identifiers are removed; dates and amounts are transformed.

Staged records use keyed pseudonyms only so an opt-out can find and revoke them. Eligible payloads expire automatically, and turning contribution off clears linked payloads without changing the financial records in your space. The complete collection and retention rules are on the Data processing page.

Financial safety by design

AI can propose an extraction or merchant identity, but it does not become database truth on confidence alone. Backend rules preserve the printed description, verify amounts and transaction meaning, and mark uncertain results for review.

Missing information stays missing instead of becoming zero. Native currencies stay separate unless stored exchange-rate evidence supports a conversion. Changes to saved records require an authenticated request, and RecehKu never sends a bank payment or places an investment trade.

What you can do

  • Use a unique password and keep the email account used for RecehKu secure.
  • Review extracted totals and unusual transactions against the source document.
  • Invite only people who need access, and use a Circle—the place for trusted people to split or track shared costs—when a full space is unnecessary.
  • Delete old source files and saved document passwords when you no longer need them.
  • Reset your password if you suspect unauthorized access. A successful reset revokes existing sessions.

Clear limits

No internet service can promise perfect security or uninterrupted availability. Keep your original statements, review important outputs, and do not treat RecehKu as the only record of an account, payment, tax position, or investment.

If a file, result, or sign-in looks suspicious, stop using that item, change your password when relevant, and contact the support channel provided by your RecehKu operator.