Privacy & data retention

Last updated February 2026

Source evidence is deleted automatically from private storage after your report is produced — typically within 24 hours — together with the extracted text. Cryptographic hashes and verification metadata are retained so your report can continue to be verified independently.

What we process

We process the documents you upload, the text extracted from them, the structured findings produced by the analysis, your account email, and payment metadata from our payment provider. We do not buy, sell or enrich personal data, and we do not use your documents to train models.

Where your documents are stored

Uploads go to a private storage bucket that is not publicly readable. Access is scoped to your own account, enforced at the database level. Report data, findings and citations are readable only by the account that created them.

Retention, item by item

Source files you upload
Deleted from private storage typically within 24 hours of the report completing
The stored bytes are permanently removed from the private evidence bucket. Deletion also runs when a report fails or is deleted by you.
Extracted text and source-indexed chunks
Redacted at the same time as the source file
Retaining the full extracted text would defeat the deletion promise, so chunk text is redacted at the same time as the source file. Structural provenance (page number, section, character offsets, extraction method and confidence) is kept so citations in your report remain meaningful.
Your final report (PDF and report data)
Retained while your account exists
The report is the product you purchased. You can delete it at any time, which also removes the stored PDF.
Cryptographic hashes
Retained
SHA-256 hashes of each source file, the evidence manifest hash, the report document hash and the PDF hash. These are one-way values: they cannot reconstruct your documents, and they are what makes independent verification possible after deletion.
Certification metadata (Certified Execution Record)
Retained
The certificate hash, attestation identifiers, node key identifier, protocol version and verification reference. Required for a third party to verify your report independently.
Payment records
Retained as required for accounting and tax purposes
Amount, currency, tier, status and payment-provider identifiers. Card details are never stored by TraceFolio — payments are handled by Stripe.
Operational and security logs
Short-term
Processing stage events, safe error codes, token counts and cost metrics. Logs never contain evidence text, excerpts or file contents.

Automatic deletion

Deletion is performed by a scheduled job, not by hand. Once a report reaches a final state, its source files are scheduled for deletion 24 hours later; the job runs continuously and removes the stored bytes and redacts the extracted text. Because it runs on an interval, deletion happens shortly after the window elapses rather than at an exact second — which is why we say "typically within 24 hours".

After deletion your report remains readable and remains independently verifiable, because verification relies on hashes rather than on retaining your documents.

Your rights and controls

  • Export. Download a machine-readable export of your account and report metadata from your account settings.
  • Delete a report. Deleting a report removes its data, its stored PDF and any remaining source files.
  • Delete your account. This removes your reports, findings, citations, payment rows, certificate records, profile and sign-in identity. Verification links for those reports stop resolving. This cannot be undone.

Payments

Card details are entered on our payment provider's hosted checkout and are never seen or stored by TraceFolio. We store the amount, currency, tier, status and the provider's identifiers so we can show your receipt and confirm entitlement.

Logging

Operational logs record processing stages, safe error codes, token counts and cost metrics. They do not contain evidence text, excerpts, filenames of a sensitive nature, or report content.

Contact

Privacy questions and requests: privacy@tracefolio.ai.