Trust & Security
Privacy-first by design. No accounts, automatic deletion, EU hosting, and full GDPR compliance.
Your project is accessed only via a private, 48-character secret link. We never ask for your email.
All data transferred over HTTPS/TLS 1.3. No unencrypted connections ever.
Documents are encrypted at rest in a private Cloudflare R2 bucket.
Projects and files are automatically deleted 30 days after creation. No data hoarding.
We process data under GDPR Art. 6(1)(b) and follow EU data protection law in full.
Database data uses a Neon EU region and document storage uses Cloudflare R2 EU jurisdiction.
Your documents are processed via Google Gemini API under terms that prohibit using API data for model training.
Files are never publicly accessible. All downloads use time-limited signed URLs (1-hour TTL).
| Component | Provider | Region |
|---|---|---|
| Database | Neon PostgreSQL | Configured EU region |
| File Storage | Cloudflare R2 | EU jurisdiction |
| Application Hosting | Vercel | Global edge |
| AI Processing | Google Gemini API | Google Cloud |
Read our Privacy Policy and Data Retention Policy for full details.