Privacy Policy
Effective Date: January 25, 2026
Provider: Redactory ("Provider," "we," "us," "our", the "Service")
Contact: support@redactory.app
1. Scope
This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Service. It applies to our website and the Service.
2. Key Privacy Principles
No document retention by default: We are designed to delete uploaded files automatically after processing, subject to limited operational needs described below.
Data minimization: We collect and retain only what is necessary to operate, secure, and improve the Service.
Security-first: We apply reasonable administrative, technical, and organizational safeguards.
3. Information We Collect
3.1 Information You Provide
- Account information: email, authentication credentials (stored via our authentication provider), and account status.
- Support communications: content of messages you send us (may include attachments if you choose).
3.2 Information Processed to Provide the Service
- Customer Content (documents): files you upload for verification/redaction.
- Default retention: temporary processing only; deleted automatically after processing and/or within short time windows.
- We do not intentionally store extracted text from your documents in logs or analytics.
3.3 Automatically Collected Information
- Usage data: timestamps, feature usage, job status events, basic device/browser info.
- Security and fraud signals: IP address (or partial/hash), authentication events, rate-limit triggers, suspected abuse indicators.
- Transaction data: purchase events, credit pack purchases, and payment status (payment card details are handled by our payment processor and not stored by us).
3.4 Cookies and Similar Technologies
We use cookies/local storage for session management, security, and preferences. We may use limited analytics to understand product usage. You can control cookies through your browser settings (some features may not work without cookies).
4. How We Use Information
We use information to:
- Provide, maintain, and secure the Service (including processing your files).
- Manage accounts, authentication, and customer support.
- Process payments and maintain a credits ledger.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Monitor performance, debug, and improve reliability.
- Comply with legal obligations and enforce our Terms.
5. How We Share Information
We may share information with:
- Service providers ("processors") who help us run the Service (e.g., hosting, database, storage, payment processing). They may access information only to perform services for us under contractual obligations.
- Payment processors (Stripe) to process transactions.
- Legal and safety: if required by law or to protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, or asset sale (with appropriate safeguards).
We do not sell your personal information in the conventional sense. If we engage in cross-context behavioral advertising, we will provide appropriate notices and opt-outs as required by applicable law.
6. Data Retention
6.1 Documents and Files
- Default: uploaded documents and generated outputs are stored only temporarily to perform processing and deliver downloads, then deleted automatically.
- Deletion windows: outputs may be available for download for a limited time (up to 1 hour) unless you download sooner.
- Operational exceptions: limited temporary caching or retries may occur to complete processing reliably.
6.2 Metadata and Logs
- We retain minimal job metadata (e.g., job timestamps, file size/page count, PASS/FAIL/UNCERTAIN result, structural findings codes) to support your job history, system reliability, security, fraud prevention, and billing integrity.
- We retain security logs as necessary to protect the Service and comply with legal obligations.
7. Security
We implement reasonable safeguards, such as encryption in transit, access controls, least privilege, and monitoring. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
8. Your Choices and Rights
8.1 Account Controls
You can:
- Deactivate your account (disables access).
- Request permanent deletion of your account (subject to limited retention for legal/security purposes).
8.2 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have rights to:
- Know what personal information we collect, use, and disclose.
- Request deletion of personal information (subject to exceptions).
- Correct inaccurate personal information.
- Opt out of certain "sharing" for cross-context behavioral advertising (if applicable).
- Not be discriminated against for exercising privacy rights.
To exercise rights, contact: support@redactory.app with subject "Privacy Request." We will verify your request consistent with applicable law.
8.3 Other Jurisdictions
Depending on your location, you may have similar rights under local law (e.g., access, deletion, objection). Contact us to submit a request.
9. International Data Transfers
We may process and store information in the United States and other countries where our providers operate. Where required, we use appropriate transfer mechanisms and safeguards.
10. Children's Privacy
The Service is not intended for children under 13 (or the minimum age required by law). We do not knowingly collect personal information from children.
11. Third-Party Links
The Service may contain links to third-party websites. Their privacy practices are governed by their policies.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version and update the Effective Date. Material changes will be communicated via the Service or email.