You shouldn't have to trust us with your data

Files are processed in memory and deleted within seconds. There's no stored document to breach, leak, or subpoena.

  • Files never stored

    Processed in memory and discarded within seconds.

  • Encrypted in transit

    Every upload and download is served over TLS.

  • True deletion

    Content is removed from the file, not hidden behind a box.

  • Data minimisation

    We don't log document contents or train on your files.

How we protect your documents

Processed in memory, then discarded

Your PDF is loaded into memory, redacted, and returned. It is discarded within seconds. We do not write your document to long-term storage, and there is no URL from which a processed file can be retrieved later.

No content logging

We do not log the contents of your file or the terms you redact, and we do not train models on your documents. For signed-in users we record a page count and plan for billing and fair use — nothing about what the document said.

Encrypted in transit

Every upload and download is served over TLS, and plain HTTP requests are redirected to HTTPS.

One content sub-processor

Pages without a text layer are sent to AWS Textract for OCR — solely to locate text so it can be removed. Pages that already have a text layer never leave our server. Textract is our only content sub-processor and we disclose it on every page.

True content removal

On text pages the matching text objects are deleted from the PDF content stream. On scanned pages the matching pixels are painted out in the image data and the original image object is discarded. Redacted content cannot be selected, searched, or recovered.

The engine is not exposed

The redaction service listens only on the server's loopback interface and requires a shared secret from the application. It is not reachable from the internet.

Compliance — plainly stated

We would rather tell you what we don’t have than imply something we do. As things stand:

  • Data minimisation by design.We don’t retain your documents, so there is very little about you for us to hold, export or erase. See the privacy policy for what we do keep.
  • No SOC 2 report and no HIPAA Business Associate Agreement at this time. If your workflow requires either, please talk to us first rather than assuming.
  • Data Processing Agreement.We don’t offer a standard DPA yet. Get in touch if you need one and we’ll tell you honestly where we are.

Your responsibilities

Review every redacted document before you share it. Automatic detection finds well-formed patterns and the terms you supply; it does not read handwriting, and no OCR is perfect on badly degraded scans. Redaction is permanent and cannot be undone, so keep your original.

Reporting a security issue

Email jmcelvanna@gmail.comwith the details. We respond to good-faith reports promptly and won’t pursue researchers who act responsibly and avoid accessing other people’s data.

See it for yourself

Redact a document, then try to copy the text back out of it. That's the whole claim, and it takes a minute to check.