Not yet in force — pre-launch draft.
- Awaiting review by Swiss counsel.
Privacy Policy
Last updated: 29 July 2026
1. Who we are
Crepuscule is operated by Superstellar Sàrl, with registered seat at Baarerstrasse 52, 6300 Zug, Switzerland (commercial register CHE-433.879.620).
For all data protection matters, including the exercise of your rights, write to yann.borie@superstellar.io. We have not appointed a data protection officer; Swiss law does not require one for an organization of our size, and enquiries reach a person directly at that address.
2. The two roles we act in
This distinction determines who decides what happens to which data, and it runs through the whole of this policy.
- We are the controller for data about our own relationship with you: your account and organization details, waitlist registrations, billing records, technical logs, and our audit trail. We decide why and how that data is processed, and this policy governs it.
- We are a processor for the content you put into the service: your invoice documents, the data we extract from them, and your bank movement data. Your organization is the controller of that content. We process it only on your documented instructions, for the purposes of providing the service, and we do not decide its purposes. Your own privacy notice — not this one — governs how you may use it, and you are responsible for having a lawful basis to process the personal data of the third parties it contains.
Where we act as processor, the terms of this policy describing subprocessors, security, international transfers, retention, and breach notification form the substance of our processor commitments to you under Art. 9 revFADP (and Art. 28 GDPR where it applies).
3. Legal framework
We process personal data under the Swiss Federal Act on Data Protection of 25 September 2020 (revFADP, SR 235.1, in force since 1 September 2023) and its implementing Ordinance.
A note on how the revFADP works, because it differs from the GDPR in a way that shapes this document: Swiss law does not require a private controller to identify a "legal basis" before each processing operation. Processing is lawful provided it respects the principles of lawfulness, good faith, proportionality, purpose limitation, accuracy, and security, and does not unlawfully breach the personality of the data subject (Art. 6 and Art. 30 revFADP). We therefore set out our purposes below rather than a list of legal bases, and we add the corresponding GDPR bases only where the GDPR applies.
Crepuscule is offered to businesses established in Switzerland, and we do not target or market the service to data subjects in the EU/EEA. We therefore do not currently fall within Art. 3(2) GDPR and have not appointed an Art. 27 representative. Where the GDPR nonetheless applies to a particular processing operation, we honour the corresponding rights, and we will appoint a representative before admitting customers established in the EU/EEA.
4. Data we process as controller
- Waitlist data — if you register interest before the service opens, we collect your email address, and any name or company you choose to provide, in order to contact you about access. Registering does not create an account. Ask us at the address above and we will remove you from the list.
- Account data — name, email address, and organization membership, held by our identity provider Clerk. We never see or store your password. If you sign in through a third-party identity provider, we receive only the identifiers that provider releases.
- Technical data — IP address, request metadata, and server logs, generated when you use the service and used to operate it securely.
- Audit data— a record of security-relevant and financial actions in your organization: which actor performed which action on which entity, and when. This exists so that a disputed ledger posting can be reconstructed. It is written append-only: no part of the application updates or deletes an audit entry. It records the fact of an action rather than the contents of a document, though some entries carry descriptive detail such as an uploaded file's name or the text of a processing error.
5. Data we process as your processor
- Invoice documents and extracted data — the PDFs you upload and the fields we derive from them: supplier names and addresses, amounts, dates, IBANs, and QR payment references. These routinely contain personal data of third parties, for example sole proprietors and individual contractors.
- Bank movement data — the account movements you import or synchronize for matching: dates, amounts, counterparties, and payment references.
- bexio connection data — the OAuth tokens authorizing us to act on your bexio account, held encrypted, and revocable by you in bexio at any time.
We do not process special categories of personal data (Art. 5(c) revFADP) as a designed function of the service, and ask that you do not upload documents containing them.
6. Why we process it
- To provide the service — extracting invoice data, proposing matches against your bank movements, and posting entries to your bexio ledger when you confirm them. Under the GDPR, where applicable: performance of a contract (Art. 6(1)(b)).
- To keep the service secure and accountable — authentication, rate limiting, audit logging, and abuse prevention. Under the GDPR: our legitimate interest in operating a secure multi-tenant service and being able to evidence what happened (Art. 6(1)(f)).
- To communicate with you — service notices, and, if you joined the waitlist, notification that access is available. Under the GDPR: contract performance, or your consent for the waitlist (Art. 6(1)(a)), withdrawable at any time.
- To comply with legal obligations — retaining records where Swiss law requires it. Under the GDPR: Art. 6(1)(c).
We do not use your data for advertising, profiling for marketing purposes, or any secondary purpose incompatible with those above.
7. Subprocessors
We use the following providers to run Crepuscule. Each processes personal data on our behalf under a data processing agreement that binds them to confidentiality, security, and onward-transfer restrictions no weaker than those we owe you.
| Provider | Purpose | Location | Transfer safeguard | Notes |
|---|---|---|---|---|
| Clerk Inc. | Identity, authentication, and organization management | United States | Swiss–U.S. Data Privacy Framework or standard contractual clauses | Holds account data: name, email address, and organization membership. Passwords are never seen or stored by us. |
| Vercel Inc. | Application hosting, request logging, and encrypted document storage (Vercel Blob) | United States; document storage and compute in the EU (Frankfurt) | Swiss–U.S. Data Privacy Framework or standard contractual clauses | Documents are encrypted by us before they reach the blob store, and the store is private — never publicly addressable. |
| Neon Inc. | Managed Postgres database | EU (Frankfurt, on AWS infrastructure) | Processing within the EU; EU adequacy recognized by Switzerland | Sensitive fields — IBANs, QR references, addresses, and extraction output — are encrypted at field level before they are written. |
| Anthropic PBC | AI extraction of invoice data from uploaded documents | United States | Swiss–U.S. Data Privacy Framework or standard contractual clauses | Receives document content for extraction only. Anthropic does not train models on API inputs. |
| Upstash Inc. | Distributed rate limiting | EU (Frankfurt) | Processing within the EU; EU adequacy recognized by Switzerland | Processes request identifiers and counters only — never document content. |
| Functional Software, Inc. (Sentry) | Error and exception tracking | United States | Swiss–U.S. Data Privacy Framework or standard contractual clauses | Error reports are filtered before transmission: request bodies, headers, cookies and query strings are removed, and credentials, encryption keys and payment identifiers are stripped by pattern. Document files are never sent. |
| bexio AG | Accounting integration — your own ledger | Switzerland | Not applicable — processing remains in Switzerland | We post entries to your bexio account only on your instruction, using an OAuth authorization you grant and can revoke in bexio at any time. |
We will give reasonable advance notice before adding or replacing a subprocessor that processes customer content, so that you can object.
8. International transfers
Our database, document storage, and rate limiting run in the EU (Frankfurt). Switzerland recognizes the EU as providing adequate protection, so those transfers require no additional safeguard.
Some providers listed above are established in the United States, which Swiss law does not treat as generally adequate. For those transfers we rely on the Swiss–U.S. Data Privacy Framework where the provider is certified under it, and otherwise on standard contractual clauses recognized by the FDPIC, adapted for Swiss law and supplemented by the technical measures described in section 9 — in particular, that document content reaching foreign storage is already encrypted under a key we hold. You may request a copy of the safeguards in place for any specific transfer.
9. How we protect your data
Each organization has its own data-encryption key, and that key is itself wrapped by a master key held separately from the database. Stored documents, and the invoice fields we treat as sensitive — the supplier IBAN, QR payment reference, supplier address, and the raw extraction output — are encrypted with AES-256-GCM under that key. Document files live in a private blob store that is never publicly addressable. Every query is scoped to a single tenant, and access requires an authenticated session in that organization. Our security page describes the architecture in full.
Two things about that design are worth stating plainly rather than leaving to be inferred.
- An upload is briefly held unencrypted. Your browser sends the file directly to a private staging area of our blob store, from which our server reads it, encrypts it, and writes it to its permanent location. Between those two steps the file sits in that private staging area unencrypted. A staged file whose processing never completes is deleted automatically within roughly an hour.
- Some fields are deliberately not encrypted,because the service has to query them: supplier names, invoice numbers, amounts, dates and currencies, and the whole of your imported bank movement data — including counterparty names, counterparty IBANs, payment references and descriptions. Encrypting these would make matching an invoice to a payment impossible. They are protected by tenant scoping and by our providers' own at-rest encryption, not by our per-organization key.
10. Retention and erasure
- Documents and extracted data are retained for as long as your organization exists. The service does not currently offer per-document deletion; to have specific documents erased before then, write to us at the address above and we will do it for you.
- On deletion of an organization, its data enters a 7-day grace period during which deletion can still be reversed. After that window the organization's encryption key is destroyed. Because that key is the only means of reading the organization's ciphertext, its documents and encrypted fields become unreadable at that moment, in live storage and in any subsequent backup alike.
- What that erasure does not reach.Backups taken before the key was destroyed still contain the key in its wrapped form, so they remain restorable until they age out of our providers' retention windows. The fields listed in section 9 as deliberately unencrypted — supplier names, amounts, dates, and bank movement data — are not affected by key destruction at all, and are removed only when the underlying records are deleted. If you need erasure that covers these too, tell us and we will delete the records directly.
- Audit records survive that erasure. After the key is destroyed, the audit trail retains the fact that actions occurred — actor identifier, action, entity, and timestamp — including the record of the erasure itself. This is deliberate: it is what allows us to evidence that a deletion was carried out. It holds no document content and nothing decryptable, and we retain it for as long as it may be needed to establish, exercise, or defend legal claims.
- Waitlist entries are kept until the service opens to you or you ask to be removed, and are deleted once they are no longer needed to manage access.
- Account data held by Clerk is deleted through Clerk when your account or organization is deleted.
Note that your own retention obligations are separate from ours: Swiss bookkeeping law requires businesses to preserve their books and accounting records for ten years (Art. 958f of the Swiss Code of Obligations). Crepuscule is not an archive, and you should not rely on it as your only copy. Export what you need before deleting anything.
11. Automated processing
Crepuscule scores candidate matches between invoices and bank movements automatically, and proposes the results to you. These are suggestions: no entry is posted to your ledger unless a person in your organization confirms it.
We do not make automated individual decisions producing legal effects or similarly significant effects on any person within the meaning of Art. 21 revFADP or Art. 22 GDPR, and we do not profile individuals.
12. Your rights
You may request access to your personal data, its correction or deletion, a portable copy in a common electronic format, and information about its origin and recipients. You may object to processing based on our legitimate interests, ask us to restrict processing, and withdraw any consent you have given with effect for the future.
Write to yann.borie@superstellar.io. We answer access requests within 30 days as a rule, as provided by Swiss law, and within one month where the GDPR applies. Exercising these rights is free of charge. We may need to verify your identity before disclosing personal data.
If the data concerns content held in a customer's organization, we act as processor and cannot answer directly — we will refer you to the customer who controls it, and assist them in responding.
You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (https://www.edoeb.admin.ch), or, where the GDPR applies, with the supervisory authority of your habitual residence.
13. Data breaches
If a breach of data security occurs that is likely to result in a high risk to the personality or fundamental rights of affected persons, we notify the FDPIC as soon as possible, as required by Art. 24 revFADP, and inform affected persons where necessary for their protection or where the authority requires it. Where we act as processor, we notify the affected customer without undue delay so that they can meet their own obligations, and where the GDPR applies we support notification within its 72-hour deadline.
14. No sale of data, no model training
We do not sell, rent, or trade personal data. We do not share your documents with anyone other than the subprocessors listed above, as needed to run the service, or where compelled by law. Your documents are never used to train AI models — neither by us, nor by our extraction provider on the API configuration we use.
15. Cookies
Crepuscule sets only the strictly necessary cookies used to keep you signed in and to protect against cross-site request forgery. We use no advertising cookies, no cross-site tracking, and no third-party analytics. Swiss law requires disclosure of cookie use rather than prior consent for cookies of this kind, which is why you are not asked to dismiss a consent banner. If we ever introduce non-essential cookies, we will ask first.
16. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the application or by email before they take effect. The date at the top reflects the latest revision.