Trust
Security, privacy and your documents
Your uploads go to private storage that only your own account can read, they are deleted automatically about 24 hours after your report is finished, and the fingerprints needed to keep the report verifiable are kept instead. Nothing you upload is published, and certification never receives your documents.
Who can read your evidence
- Uploads are stored in a private bucket that is not publicly readable and has no shareable link.
- Access is scoped to the account that created the report and enforced at the database level, not just in the interface.
- Reports, findings and citations are readable only by the account that created them.
- Nothing you upload becomes public, and your documents are never used to train models.
When your documents are deleted
Once a report reaches a final state, its source files are scheduled for deletion 24 hours later. A scheduled job removes the stored bytes and redacts the extracted text. Because the job runs on an interval, deletion happens shortly after that window rather than at an exact second, which is why the wording is "typically within 24 hours".
After deletion your report is still readable and still verifiable, because verification uses fingerprints rather than copies of your files. The privacy and data retention page lists each class of data and how long it is kept.
What you control
- Delete a report at any time, which removes its data, its PDF and any remaining source files.
- Export your account and report metadata from account settings.
- Delete your account, which removes reports, findings, citations, payment rows, certificate records and your sign-in identity. Verification links for those reports then stop resolving.
Who processes your data
TraceFolio uses a small number of third-party services: hosting, private storage and authentication, the analysis model, text recognition for scanned pages, certification, payments and transactional email. Each one, and exactly what it receives, is listed on the subprocessors page.
Certification is the one worth repeating: it receives one-way fingerprints and processing details only. That is enough to prove the link between your inputs and your report, and not enough to reconstruct anything about their contents.
Payments
Card details are entered on the payment provider's hosted checkout and are never seen or stored by TraceFolio. Only the amount, currency, tier, status and the provider's identifiers are stored, so a receipt can be shown and access to the report confirmed.
Logging
Operational logs record processing stages, safe error codes and cost metrics. They do not contain evidence text, quoted excerpts or report content.
Related reading
Create your evidence report
Create a report knowing your uploads stay private to your account and are deleted automatically once the report is finished.