Trust

Security & Data

How Tockly protects invoice, contact and account information.

Last updated 4 October 2026

Security approach

Tockly uses layered technical and organisational safeguards appropriate to an online invoice-follow-up service. These include encrypted connections, access controls, protected integration credentials, restricted administrative access and incident-response procedures.

Account protection

  • New passwords are uniquely salted and hashed using bcrypt. Older PBKDF2 records are automatically upgraded after a successful login, and passwords are never stored in readable form.
  • Sessions are stored in Tockly’s database and users are signed out after 60 minutes of inactivity, with a separate absolute expiry.
  • Connection credentials for services such as Xero, MYOB and QuickBooks are encrypted before storage.
  • Account activity and service errors may be logged for security and troubleshooting.

Data storage

Tockly runs on the OpenAI Sites platform and uses Cloudflare Workers, D1 and R2 for application computing, structured records and uploaded invoice files. Cloudflare’s global infrastructure may process information in multiple countries. Reminder email is delivered through Resend by default. A customer may instead authorise send-only access to its Microsoft 365 or Google mailbox. Tockly does not request inbox-reading permission for that connection.

Payments and integrations

Where Stripe-hosted checkout is offered, complete card details are entered with Stripe and are not stored by Tockly. Authorised accounting connections can import customers, invoices and payment status, and upload confirmed sent invoices and supported documents for reconciliation. Disconnecting an accounting service stops future access but does not erase previously imported records.

Responsible use

Customers should use unique passwords, protect their devices, grant access only to authorised people, check imported invoice information and avoid uploading sensitive information that is not needed for invoice follow-up.

Report a security issue

Please report suspected vulnerabilities or unauthorised access privately to contact@tockly.ai. Include enough detail for us to investigate, but do not send another person’s sensitive information unnecessarily.

AI-assisted work and review

Selected Capture images, dictation recordings and relevant matching context can be sent to OpenAI for the features you choose. AI proposals require review. Provider-side response storage is disabled for Responses API requests, but this is not a promise of zero provider retention. See the Privacy Policy for the data sent and retained.

Recovery and deletion

Tockly-managed database snapshots and archived file versions use a 30-day rolling retention window, with current files protected while in active use. Cleanup records its result and failures for operational review. Provider-managed recovery systems are separate; their account-specific expiry periods remain under verification. Permanent account deletion removes active workspace records and schedules any failed file cleanup for retry. Recovery must respect the deletion ledger; no backup system guarantees that data can never be lost.