Security & Data Handling

You're trusting us with your documents, so here is exactly what happens to them — what leaves our servers, what doesn't, and what we can and can't promise.

Where your data goes

  1. You upload a document over an encrypted (HTTPS/TLS) connection.
  2. We extract its text. Scanned pages are read by OCR models we run on our own infrastructure.
  3. When you ask a question, the relevant passages are sent to the AI model that answers it. On paid tiers that model is run by a third-party provider (see the sub-processor list below); on the free self-hosted tier the model runs on our own infrastructure and your document never reaches a third party.
  4. The answer comes back cited to the source page, and your uploaded file is deleted automatically shortly after.

Automatic deletion

Uploaded files are deleted automatically from our servers shortly after processing by a cleanup job that runs every hour — it is real code that runs on a schedule, not just a sentence on a page. Your conversation and the extracted text are kept so you can keep chatting and revisit your history; you can delete your account and associated data at any time, and paid history can be cleared on request.

We do not train on your data

We never use your documents, your questions, or the answers we generate to train AI models. The third-party model providers we call do so through their commercial APIs, which contractually do not train on the data sent to them. We never sell or rent your documents.

Sub-processors

The limited set of third parties we rely on to run the service, and what each one receives:

Provider Purpose What it receives
Anthropic, OpenAI, Google, OpenRouterAI models that answer your questions (paid tiers)The passages of your document relevant to your question
Self-hosted models (our own infrastructure)Free-tier chat and scanned-document OCRStays on our infrastructure — no third party
Stripe, PayPalPayment processingYour payment details (handled directly by them); we receive only confirmation

We share data with these providers only as needed to run the service, never for their own marketing.

Private mode (coming)

We are building a private mode that keeps your document entirely on our own infrastructure and never sends it to a third-party model provider — turning the privacy promise into something architectural rather than contractual. Want it for your team? Get in touch.

Reporting & contact

Found a security issue, or need a Data Processing Agreement? Email hello@pdf.chat and we'll respond.

تقييم هذه الصفحة
5.0/5 (0)

ما الذي يمكننا تحسينه؟ تساعدنا تعليقاتكم على حل المشاكل.