Security & privacy

Severino goes into your billing portals. This is exactly what it does there.

We get it: giving an extension access to your AWS, Google Cloud or Stripe accounts feels like a big deal. That's why Severino is built to be able to do the bare minimum — and here's all of it, no fine print.

It never sees your passwords

It doesn't ask for them or store them. It uses the session you already have open with each provider, just like you would.

It only goes where you let it

When installed it has access to no website at all. Chrome asks you for permission per provider the first time you fetch its invoices.

It can't pay for or delete anything

Buttons to pay, change plan, cancel, delete or sign out are blocked inside the extension itself.

It strips sensitive data before sending

Emails, cards, IBANs, phone numbers, tax IDs and API keys are removed from the text before anything leaves your browser.

What it can and can't do

It can

  • Open the billing portal of the providers you tick
  • Read the visible text of that page to find the invoice
  • Click navigation and download links
  • Save the PDF to your Downloads folder
  • Email the PDF to your accountant, if you set it up

It can't

  • See, type or store passwords
  • Visit sites you haven't granted permission for
  • Pay, buy, change plan, cancel or delete anything
  • Take screenshots or read your browsing history
  • Act when you haven't clicked “Search invoices”

What happens to your data on every search

  1. 1

    You click “Search invoices”

    Chrome asks for permission on the domains of the ticked providers (first time only). You can revoke it anytime.

    Nothing leaves your browser.

  2. 2

    Severino follows the route it already knows

    For each provider it replays the saved steps — open the invoices page, click download — inside your browser.

    Nothing leaves your browser.

  3. 3

    If the provider changed its site, it asks the AI

    It sends the page's visible text, already stripped of sensitive data, to our server, which asks an AI model for the next click. It isn't stored: we only log the provider, the number of steps and whether it worked.

    Leaves: page text, redacted. Not stored.

  4. 4

    It downloads the invoice

    The PDF goes to your Downloads folder. A copy passes through our server to read the amount, date and number (with the text redacted) and, if you set it up, email it to your accountant.

    Stored: provider, period, amount, number and date. The PDF isn't stored in our database.

Chrome permissions, one by one

These are all the permissions the extension asks for. None of them grants access to websites on its own.

identity
Sign in with your Google account so we know who you are and activate your plan. We only ask for your email, name and profile picture.
downloads
Save each invoice PDF to your Downloads folder.
storage
Remember, in your own browser, which providers you have enabled.
scripting
Read the billing page text and click the download button — only on the domains you authorize.
Per-provider permissions (optional)
Requested one at a time, when you search, and only for the providers you tick. Revoke them from chrome://extensions.

Domains it may request for the providers in the catalog:

*.vercel.comconsole.cloud.google.comconsole.twilio.com*.console.aws.amazon.comgithub.com*.slack.comwww.canva.comsupabase.com*.lovable.dev*.datafast.iowww.make.comhpanel.hostinger.comaccount.godaddy.comconsole.anthropic.complatform.openai.comwww.cursor.com

Where your data lives

These are all the services that process data on our behalf. None of them uses it for advertising, and we don't sell data to anyone.

ServiceWhat forWhat dataWhere
VercelHosts the website and serverExtension requests in transitEU (Frankfurt)
Neon (on AWS)DatabaseAccount, plan, invoice history (no PDFs)EU (Frankfurt)
Vercel AI Gateway + AnthropicAI model for the agent and invoice readingRedacted text, not stored by usUSA
AgentMailEmailing invoices to your accountantPDF and your accountant's emailUSA
StripeSubscription billingPayment data (we never see it)EU / USA
GoogleSign-inEmail and nameEU / USA
PostHogProduct analyticsWebsite and extension usage, no invoice contentEU (Frankfurt)
CrispSupport chatWhatever you write to usEU (France)

Transfers outside the EU rely on the safeguards the GDPR requires (standard contractual clauses or each provider's EU-US Data Privacy Framework certification).

You're in control

  • Revoke access to a provider from chrome://extensions → Severino → Site access.
  • Uninstall the extension and all access ends instantly.
  • Ask for full deletion of your account by writing to hola@severino.io: we delete your account, your history and your sending inbox.
  • Cancel your subscription from your account — no calls, no commitment.

Found a security issue?

Write to us at hola@severino.io and we'll look into it as a priority.

Severino is a product of Twintag Services SL (tax ID B57728818), a Spanish company subject to the GDPR.

Read the full privacy policy