Skip to content

Privacy Policy

How InlinePDF collects, uses, protects, exports, and deletes account and document data.

Data we process

We process account details, authentication events, billing identifiers, uploaded documents, rendered page images, extracted OCR text, edits, exports, usage and cost records, support messages, product events, and security logs needed to operate InlinePDF.

Provider keys that users bring to InlinePDF are encrypted at rest and are never returned in API responses. Admin views display suffix-only key metadata.

AI data flow

When hosted OCR is used, document page images and extraction prompts are sent to the configured OCR provider to produce structured OCR output. When a user brings their own provider key, requests are made with that key and are metered separately from hosted usage.

We do not sell document data or use customer documents for advertising. Provider processing is limited to producing the requested OCR, verification, and export results.

Security controls

Documents are tenant-isolated, malware-scanned on upload, stored on private disks, and served through signed URLs. Staff access requires admin permission and two-factor authentication; document-content access by support is restricted to guarded impersonation and audit logging.

Operational logs and error reports are scrubbed to avoid provider keys, prompts, document content, raw OCR text, passwords, tokens, cookies, and payment data.

Retention and requests

Document retention depends on the active plan and any admin-approved overrides. Account erasure removes documents and personal data while retaining billing and invoice records required for legal, tax, fraud-prevention, and accounting obligations.

You may request data export or erasure through the product or support channel. Export and erasure requests are tracked with SLA due dates and completion records.

Last updated: 2026-07-04