Privacy
Browser-local prechecks, explicit private processing and optional consented AI.
Browser-local files
Your selected PDF stays in this browser session during the limited precheck. No silent upload, file-name analytics or document-content telemetry. Clear the session or close the page to release its local references. Review exports contain the notes you explicitly entered.
Private workspace uploads
Authenticated cloud save is an explicit action. Source PDFs, candidates, previews, crops, extracted text and review notes expire 30 days after project creation; uploads into the same project do not extend its expiry. A 500 MB ceiling includes all variants. Deletion revokes access immediately; a retryable cleanup task targets removal within 24 hours. The worker runs periodic cleanup. Database backups use a separate private store and encryption key, with a six-day retention limit. These database archives do not include source PDF bytes. Backup expiry and deletion replay have been tested with synthetic records; interruption or provider outages can delay physical cleanup.
Optional analytics
Production analytics requires your permission. Google Analytics measures public pages and fixed usage events, excluding document contents, filenames and private workspace URLs. When you return from a paid checkout with analytics enabled, a verified purchase may be reported with its amount, currency, pseudonymous transaction reference and Google browser identifiers. We do not send your email, Clerk identity or Stripe customer identifiers. Decline or withdraw permission using Analytics preferences. Testing payments are excluded. Minimal purchase reporting records may remain to prevent duplicate revenue reporting. The current Google property retains event-level data for two months and user-level data for fourteen months, with user retention reset by new activity; aggregated reports can remain longer. Enhanced Measurement is limited to scrolls, with manual sanitized page views. Automatic history, form, search, outbound-link, video and download capture are disabled, as are granular location/device collection, Google Signals and advertising personalization. Private pages do not initialize the tracking SDK. Consented public-page purchase attribution is retained in browser session storage for at most 24 hours; missing attribution stays unknown.
Cloud descriptions
An explicit selected-figure action and consent send a bounded crop and relevant context through OpenRouter to Microsoft Azure for the pinned GPT-4.1 Mini model. The configured route requires zero-data-retention eligibility and denies provider data collection, with no fallback processor. Account and endpoint privacy must be verified before use; these settings do not provide a regulated-data guarantee.
Deletion and records
Compact content review records expire with their project. Minimal financial/usage records may remain without document content. An immutable deletion journal stores pseudonymous owner hashes, project references and deletion timestamps separately from document content to preserve deletion after a database restore. An isolated hosted recovery test verified that replaying this journal denies access to deleted projects and accounts and purges restored synthetic records. This does not promise instant deletion from backups or provider monitoring. Deleting this product workspace does not delete your global Clerk identity.
Contact support@pondir.com. Do not attach private documents unless a separate secure support process is agreed.