Loading
Loading
No charter, no badges, no sentence about how seriously we take your privacy. Just where the file goes, who can read it, and the things we have not done yet.
The honest version of this answer is short, so here is the whole of it rather than a summary with a link to a policy.
On the way
On the way
The upload runs over TLS from your browser to our servers. Nobody on the network in between — your café’s wifi, your employer’s proxy, your ISP — sees the contents of the file.
While it is read
While it is read
The text is extracted and analysed in the memory of the process handling your request. It is not written to a disk, a bucket or a table on the way through, and it is not copied anywhere for later.
When the analysis is done
When the analysis is done
The document and its extracted text go out of scope with the request. What you see on screen is the report; the source of it no longer exists on our side unless you asked us to keep it.
If you save it
If you save it
Saving is a choice you make per document. A saved document is encrypted at rest and readable only by the account that saved it — enforced at the data layer, so a bug in a page cannot serve one person’s document to another.
When you delete it
When you delete it
Not flagged as hidden and kept. The record is removed, and it drops out of backups as those age out on their normal cycle. Deleting your account deletes everything in it.
Which is the only kind worth printing. Each of these is a statement of fact about how the product operates, not an aspiration about how we feel.
Not ours, and not anyone else’s. Where analysis runs through a third-party model provider, it runs under terms that prohibit training on the content — and if that ever stops being true of a provider, we change the provider rather than the sentence.
Your documents and what is in them are not a data product. There is no advertising business here to feed, and no arrangement under which a third party receives your content in exchange for anything.
No one here browses documents. Access to production data is restricted, and the rare case where a person needs to look at something to fix a fault requires your explicit permission first — asked for at the time, about that document.
Deleting a document takes one action. Closing an account takes one action and does not require an email to support, a phone call, or a page that asks four times whether you are sure.
The second list is the one worth reading. Every security page has the first.
TLS for everything that crosses a network, including between our own services. Anything stored — a saved document, its analysis — is encrypted on disk.
Which account may read which record is decided below the application, not by a check a page could forget to make. A bug in a route cannot serve one person’s document to another.
Production access is scoped to the people who need it for the job they are doing, granted for as long as they need it, and logged.
Third-party packages are pinned, scanned for known vulnerabilities on every build, and updated on a schedule rather than when something breaks.
We are a young product and have not completed an audit. If your procurement process requires one, tell us — knowing how many people are blocked on it is what decides when we start.
People do upload medical bills, and the analysis works. But we do not sign business associate agreements today, so PaperLens is not an appropriate place for a covered entity to process protected health information.
Testing happens; a report you can read does not exist yet. When there is one worth publishing, it will be linked from this page rather than described on it.
Write to support@paperlens.app with enough detail to reproduce it. We will confirm receipt, keep you updated while we fix it, and credit you if you want to be credited. We will not threaten you with a lawyer for telling us about a bug.