Document Retention & Privacy Policy
Last updated: 27 September 2026
1. Files are processed in memory, not stored
When you upload a file for comparison or extraction, it is read into temporary memory on our server, analysed and deleted when the request finishes. At no point is the raw file written to long-term storage or to public object stores such as AWS S3 or Google Cloud Storage.
Photos of receipts and invoices are read (OCR) inside your browser. The image itself never leaves your device; only the recognised text is sent for analysis. The text-recognition software is downloaded from a public content delivery network (jsDelivr) the first time you use it.
PDF Tools run entirely in your browser. Merging, splitting, compressing, converting, signing, redacting, protecting and every other tool in the PDF Tools hub process your files on your own device; the files are never uploaded to our servers. The only exception is “PDF Invoice to E-Invoice”, which sends the invoice to our server so its data can be extracted; it is processed in memory and not stored, exactly as described above.
1a. When Google Gemini is used
We can switch on Google's Gemini API to help some business document tools read difficult files. When it is switched on and you upload a scanned PDF or a photo that has no selectable text, the file is sent to Gemini so the text can be transcribed, and if our own parser cannot find the line items in a document, the document's text is sent to Gemini to extract them. Nothing else is sent, Gemini is not used by the PDF Tools hub or the calculators, and the response is used only to produce your result.
2. Your files are not used to train AI
We never use your files, or the prices, contracts and totals in them, to train or fine-tune AI models.
3. Using the Tools Without an Account
You can use every tool without signing in. In that case saved workflows and your recent tool history are kept only in your browser’s localStorage on your device. We cannot see them, and clearing your browser data erases them.
4. Cloud Accounts: What We Store
If you create an account (email and password, Google sign-in, or a guest session), we store the following in our database so your work syncs across devices:
- Account details: your name, email address and a securely hashed password. If you sign in with Google, we also store your Google account ID and profile photo address. Guest sessions have no name or email.
- Preferences: your preferred region (UK or US).
- Saved workflows: the calculations and results you choose to save, including the figures and line items shown in that result (for example, extracted invoice lines or a comparison table), plus any notes and favourites.
- Tool usage history: which tools you opened and when, a short summary of the input and output, and the full result for any run you saved. We keep your most recent 150 entries.
- Session data: while you are signed in, a session record containing your IP address and browser user agent, used to keep you signed in and to protect your account.
When you sign in, anything you saved in your browser while signed out is copied into your account. If you were using a guest session, its saved workflows and history are moved to the account you sign in to, and the guest session is deleted.
4a. Messages you send us
When you use the contact form, we store your name, email address, the topic, your message and the page you sent it from, so we can reply. We keep a one-way scrambled version of your IP address, not the address itself, to stop abuse. Messages are deleted automatically 12 months after they arrive.
5. Cookies
The cookie policy lists every cookie and browser storage item we use, and how long each one lasts.
We use only essential cookies: a session cookie, a security (CSRF) token and, once you sign in, a “remember me” cookie that keeps you signed in on that device until you sign out. We do not use advertising cookies. If we enable Google Analytics to measure site usage, Google sets its own analytics cookies; these do not identify you by name.
6. Retention and Deletion
- You can delete any saved workflow, remove individual history entries or clear your entire history at any time from the Saved Workflows panel.
- Guest sessions and all their data are deleted automatically after 30 days of inactivity.
- Signing out ends your session on that device.
- To have your account and all associated data deleted, email support@rightsums.com and we will erase it.
7. Your Rights under UK GDPR and US Privacy Law
We collect only what is needed to provide the service (data minimisation) and never sell or share your personal information. Under UK GDPR you may request access to, correction of, export of, or erasure of your personal data. California residents have equivalent rights under the CCPA/CPRA, including the right to know and the right to delete.
To exercise any of these rights, email support@rightsums.com.