Privacy & data retention
Last updated February 2026
Source evidence is deleted automatically from private storage after your report is produced — typically within 24 hours — together with the extracted text. Cryptographic hashes and verification metadata are retained so your report can continue to be verified independently.
What we process
We process the documents you upload, the text extracted from them, the structured findings produced by the analysis, your account email, and payment metadata from our payment provider. We do not buy, sell or enrich personal data, and we do not use your documents to train models.
Where your documents are stored
Uploads go to a private storage bucket that is not publicly readable. Access is scoped to your own account, enforced at the database level. Report data, findings and citations are readable only by the account that created them.
Retention, item by item
- Source files you upload
- Deleted from private storage typically within 24 hours of the report completing
- The stored bytes are permanently removed from the private evidence bucket. Deletion also runs when a report fails or is deleted by you.
- Extracted text and source-indexed chunks
- Redacted at the same time as the source file
- Retaining the full extracted text would defeat the deletion promise, so chunk text is redacted at the same time as the source file. Structural provenance (page number, section, character offsets, extraction method and confidence) is kept so citations in your report remain meaningful.
- Your final report (PDF and report data)
- Retained while your account exists
- The report is the product you purchased. You can delete it at any time, which also removes the stored PDF.
- Cryptographic hashes
- Retained
- SHA-256 hashes of each source file, the evidence manifest hash, the report document hash and the PDF hash. These are one-way values: they cannot reconstruct your documents, and they are what makes independent verification possible after deletion.
- Certification metadata (Certified Execution Record)
- Retained
- The certificate hash, attestation identifiers, node key identifier, protocol version and verification reference. Required for a third party to verify your report independently.
- Payment records
- Retained as required for accounting and tax purposes
- Amount, currency, tier, status and payment-provider identifiers. Card details are never stored by TraceFolio — payments are handled by Stripe.
- Operational and security logs
- Short-term
- Processing stage events, safe error codes, token counts and cost metrics. Logs never contain evidence text, excerpts or file contents.
Automatic deletion
Deletion is performed by a scheduled job, not by hand. Once a report reaches a final state, its source files are scheduled for deletion 24 hours later; the job runs continuously and removes the stored bytes and redacts the extracted text. Because it runs on an interval, deletion happens shortly after the window elapses rather than at an exact second — which is why we say "typically within 24 hours".
After deletion your report remains readable and remains independently verifiable, because verification relies on hashes rather than on retaining your documents.
Your rights and controls
- Export. Download a machine-readable export of your account and report metadata from your account settings.
- Delete a report. Deleting a report removes its data, its stored PDF and any remaining source files.
- Delete your account. This removes your reports, findings, citations, payment rows, certificate records, profile and sign-in identity. Verification links for those reports stop resolving. This cannot be undone.
Payments
Card details are entered on our payment provider's hosted checkout and are never seen or stored by TraceFolio. We store the amount, currency, tier, status and the provider's identifiers so we can show your receipt and confirm entitlement.
Logging
Operational logs record processing stages, safe error codes, token counts and cost metrics. They do not contain evidence text, excerpts, filenames of a sensitive nature, or report content.
Contact
Privacy questions and requests: privacy@tracefolio.ai.