Your files, your privacy.
Browser processing
Eligible JPEG, PNG and WebP images and PDFs are processed and validated with Rust/WebAssembly on your device. Error screenshots use browser WASM OCR first. File contents are never sent to the server. Local results live in browser memory until you close the page or delete them.
Context assistance
PDF context extraction and screenshot OCR run on your device first. If you request AI suggestions, the description or reviewed excerpt you submit is sent to our self-hosted model. It is not saved as profile memory. On-device-only mode disables this transfer.
Accounts and email
Accounts store an email address and a password hash, or a verified Google account identifier. Verification and password-reset messages go through the configured transactional email provider. Message contents are removed from our outgoing queue after delivery. Password reset revokes previous sessions.
Subscriptions and advertising
When enabled, Stripe handles subscription checkout and billing details. We store the subscription identifier and status. Free accounts and anonymous visitors may see labeled banner ads on marketing, pricing and utility pages. When AdSense is enabled, Google advertising and consent scripts run on these pages and may process device, network and page information. We do not supply filenames, document contents, OCR excerpts or processing results as ad targeting data. AdSense requires a configured consent platform. Pro accounts do not receive ads or load advertising scripts after their paid entitlement is confirmed.
Stateless edge fallback
If browser processing cannot finish, supported files can use the local Rust edge service. It returns output directly to this browser and retains no file copies. The control plane keeps only job settings and validation metadata.
Local server fallback
Only files that cannot be handled by the browser or edge are uploaded directly to private object storage in your Kubernetes cluster. Originals are scheduled for deletion after one hour; outputs after four hours. A cleanup worker runs every minute. Failed or cancelled jobs can be deleted immediately. Previously issued download links expire after sixty seconds.
Accounts and workflows
Accounts store an email, a password hash, processing metadata and saved settings. Workflows contain constraints and rule references, never document content. This local edition has no external payment, advertising, analytics or email service configured. Optional advisory inference runs through local Ollama.
Local development boundary
This deployment is for your machine. It uses localhost HTTP and local persistent volumes. Internet deployment requires TLS, verified email and recovery, malware scanning, tenant isolation review, and production backup and security review.