Privacy-first architecture

Security model for sensitive transaction data.

AutoPay Radar is designed around data minimization, explicit user action, and protective warnings for financial commitments.

Credential boundary

No bank passwords, OTPs, UPI PINs, CVV, or full card credentials are requested.

Redacted evidence

Production persistence stores normalized events and redacted snippets for recurring-payment context.

Retention controls

Users can export normalized data, delete raw imports, or delete all saved data.

OAuth minimization

Gmail alpha uses read-only consent and imports only relevant receipt snippets when configured.

1Inputs

SMS text, receipts, CSV

2Parser

Redact, normalize, classify

3Report

Recurring items, risk, reminders

4Controls

Export, delete, retention off

Input validation

Rate limiting

Audit logs

RLS-ready data model

Fallback demo mode

No destructive autopay actions