Privacy Policy
Last updated 26 July 2026
This policy explains what [LEGAL ENTITY] ("we") does with information when you use WhoPaid. "You" means the business with a WhoPaid account. WhoPaid is a web application — you use it in a browser and your data is processed on our servers.
The short version
Check images you upload travel encrypted to us and the account and routing numbers are masked on arrival. The original, un-masked image is deleted as soon as masking is confirmed, and in every case within hours. We do not keep un-redacted account numbers, and un-redacted images are never sent to any third party.
What happens to an uploaded check
- Upload. The file arrives over an encrypted connection and is held in an encrypted quarantine area, tagged for expiry.
- Masking. Each page goes to our redaction service, which finds the MICR line and masks it. The redacted copy is written to storage and the original is deleted immediately.
- Pages we won't guess on. Where the software cannot confirm it has found the MICR line, it refuses to proceed rather than risk sending an unmasked number onward. Those pages wait for someone at your business to mark the area in the browser; the original is deleted on confirmation.
- Expiry. Any original still sitting in quarantine at expiry is deleted regardless, whether or not it was ever processed.
- Afterwards. Everything downstream — extraction, matching, review, export — works only on redacted images. The account numbers are not present in that part of the system at all.
Account and routing numbers exist only in memory during masking. They are never written to our database.
What we store, and for how long
- Original check images: deleted on redaction, or at expiry at the latest. Not retained.
- Redacted check images and exports: retained according to your account's retention setting.
- Payment and matching records: the extracted fields — payee, date, amount, check number — and the decisions made during review, kept as your working record.
- Audit log: a record of actions taken in the account, so a reconciliation can be traced afterwards.
- Your AR ledger data as you import it.
Who else is involved
- Cloudflare — hosts the application, stores the data, and gates access to your account.
- Anthropic — reads redacted check images and returns the extracted fields. Only redacted images are ever sent. Under Anthropic's commercial API terms, inputs are not used to train their models.
- Stripe — processes payments and stores payment methods.
We do not sell your information, and we do not share it for advertising.
Payment information
Card and bank details are entered on payment pages hosted by Stripe. Card numbers never pass through WhoPaid, and we never see or store them. Stripe's handling of that data is governed by Stripe's privacy policy. From Stripe we receive only what we need to run your account: billing contact, plan or credit status, and payment history.
Account information
We hold your business name, the email addresses of the people you authorise to sign in, your plan or credit balance, and a record of checks processed for billing. Signing in is by email verification or through your own identity provider; we do not store passwords.
Security
Data is encrypted in transit and at rest. Access to your account is gated at the front door and every request is authenticated. Actions within the account are logged. Because long-term storage holds redacted images only, even a worst-case breach of that storage would not expose account or routing numbers.
This website
This marketing site sets no cookies, runs no analytics, and loads nothing from third parties. If you email us, we keep the email so we can reply.
Your choices
You can ask us what information we hold, ask us to correct it, ask us to export it, or ask us to delete it once billing obligations are settled. Write to hello@whopaid.today.
Changes
If this policy changes in a way that affects how check data is handled, we will tell account holders by email rather than only updating this page.
Contact
[LEGAL ENTITY]
[MAILING ADDRESS]
hello@whopaid.today