← Back to Tooly
🛡️

Security & Data Protection

We take security seriously. Here's exactly how we protect your data — in plain English, not legalese.

🧠

In-Memory Processing

Files are processed in memory and permanently deleted after download

🔒

Encryption at Rest

All data encrypted with AES-256. Passwords hashed with bcrypt.

🔐

TLS Everywhere

Full HTTPS via Let's Encrypt. No unencrypted connections.

🇪🇺

GDPR Compliant

Hosted in Germany. Full GDPR rights: access, deletion, portability.

📁 File Processing Flow

1. You upload a file → 2. Upload goes directly to our API (encrypted in transit) → 3. File is processed in server memory only → 4. Result sent back to you → 5. File immediately deleted from server. No copies, no backups, no permanent storage.

What We Do With Your Data

We don't store your files. Bank statements, invoices, images, PDFs — they're processed in memory and deleted the instant you get your result. We never read them, never analyze them, never share them.

We don't track you. No tracking cookies, no ad networks, no third-party scripts. We use minimal Google Analytics for anonymous page-view stats only.

We don't sell data. It's not our business model. We charge $5/mo for Pro because that's our business model.

Infrastructure

Tooly runs on a single VPS hosted at Contabo data center in Munich, Germany — one of Europe's most secure facilities. All connections are TLS 1.3 encrypted via Let's Encrypt. Server software is updated weekly.

Payment Security

All payments are handled by Stripe, a PCI Level 1 certified payment processor. We never see, touch, or store your credit card details. Stripe tokenizes everything.

Encryption

Passwords are hashed with bcrypt (cost factor 10). We never store plaintext passwords. In fact, we can't see your password at all — not even to reset it. All database files are encrypted at rest.

Data Retention

Account data (email, hashed password, subscription status) is kept as long as your account exists. Delete your account, and all data is permanently removed within 48 hours. Uploaded files are never retained — they're deleted immediately after processing.

Compliance & Certifications

GDPRStripe PCI Level 1Let's Encrypt TLS 1.3EU HostedISO 27001 (Contabo)

Security Contact

Found a vulnerability? Email hello@tooly.work. We take all reports seriously and will respond within 24 hours.

🔒 Your data is safe with us. Always has been, always will be.

Questions? Read our Privacy Policy or contact us.