AES-256 encryption. EU-only servers. Auto-deletion after 1 hour. No AI training on your data. No selling to anyone. Ever.
Your browser encrypts the file with TLS 1.3 before it leaves your device. The connection is secured with HTTPS using a Let's Encrypt certificate, refreshed every 60 days.
On our servers, the file is written to an isolated worker namespace with strict POSIX permissions. Only the worker that processes your specific request can read it.
The requested operation (merge, OCR, compress, etc.) runs in a sandboxed Python or Node.js process. No network access, no other tenants' files visible, no shared state.
The result is served via a signed time-limited URL. Only you (with the matching session token) can access it.
A scheduled cleanup job runs every 5 minutes and deletes any file older than 1 hour. No manual intervention possible — even our engineers can't recover deleted files.
We don't sell, license, or share customer files or metadata with anyone. Ever.
Your documents never enter any training pipeline — ours or a third party's.
Files are processed by automated pipelines. No human reviewer ever opens your documents.
Analytics measure page views and anonymous product events only. No ad networks, no data brokers, no profiling from your files.
Cancel your subscription anytime. Export your data. We don't hold your files hostage.
File storage and processing stay on our EU VPS. Only the optional AI features call US model APIs, under zero-retention terms.
We take security seriously. If you discover a vulnerability, please report it responsibly:
We don't currently run a paid bug bounty, but we credit responsible reporters in our security acknowledgements.
EU servers, AES-256, GDPR. Files deleted after 1 hour. No tracking.