Security
How your data is protected
Encryption, retention, access controls and AI processing.
- TLS on every connection; HSTS enabled.
- Uploaded files encrypted at rest with AES-256-GCM.
- Original files deleted 24 hours after processing; extracted data deleted per plan retention.
- Extraction via the OpenAI API with response storage disabled; API data isn't used to train models by default.
- Payments processed by Polar; we never see full card numbers.
See the Security page and Subprocessors.