Privacy

Last updated 10 September 2026.

Short version: your documents are read on our own hardware, they are not sent to any other company, and they are yours to delete at any time.

What we hold

WhatWhy
Your GitHub user id, username, display name and avatar To sign you in and to show whose account it is. We ask GitHub for read:user only — not your email address, and not your repositories.
The documents you upload or photograph To read them. They are the product.
What the reader got out of them — text, tables, field values and the position of each value on the page To show you the result, to let you check a value against the page, and to export it.
Where a photograph was taken, if the photograph said so and you chose to send it So you can group and search your scans by place. Off unless you leave it on, and absent entirely for most files, because most files carry no position.
Names you give a place So a set of coordinates reads as “Glendora store”.
How many pages you read, when, and at which output To bill you and to show you what is left of your plan.
An email address, only if you give us one To write to you before deleting the documents of a cancelled account, and for nothing else — no newsletters, no product mail. Signing in with GitHub does not give us one, so we ask. Confirmed by opening a link we send to it, because an address we cannot reach is not a way to warn you. Remove it in the app whenever you like.

Where it goes

The reading happens on our own machines. Documents are sent to GPU servers we run and to models we host. They are not sent to OpenAI, Google, Anthropic, AWS Textract or any other reading service, and nothing you upload is used to train a model.

The files themselves are stored in our own Amazon S3 bucket in Oregon (us‑west‑2), encrypted at rest, with public access blocked at the bucket. The database that holds the extracted values is backed up nightly.

Amazon Web Services is therefore a processor for us; they hold the bytes and do not read them. If and when we take card payments, Stripe will process those and we will hold only the customer and subscription identifiers they give us — never a card number.

Third-party code on this site

The marketing pages — this one, the home page and the pricing page — load a support chat widget from kavilo.cloud. It is deliberately not present on any page that shows a document, an API key or your account, because a script on a page can read that page.

There is no analytics, no advertising and no tracking script anywhere on this site.

How long we keep things

While your plan is active, we keep your documents. There is no expiry that removes a scan while you are still paying for the account it lives in.

After you cancel, we keep them for at least 90 days so that you can come back, or export what you need. After that we may delete them.

We will tell you before deletion starts, and that is a rule in the code rather than a promise on a page: the job that deletes documents skips any account with no record of a warning sent at least 14 days beforehand. So if the warning does not go out, nothing is deleted.

The date is shown in the app as soon as a plan is cancelled. If you have given us a confirmed email address we write to it as well — and if you have not, the notice in the app is the only one you will get, which is why we ask for one.

You do not have to wait for us. Deleting a batch in the workspace removes its files straight away. Your usage history stays, because your invoices have to be able to refer to it.

What you can ask for

Ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete your account and all of it. Write to privacy@scanandfile.com. We will not ask why.

Every scan is already exportable without asking: each batch offers CSV and JSON from its own screen.

Changes

If this policy changes in a way that affects what we do with documents you have already given us, we will say so on this page and date it, and we will not apply the change retroactively to reduce what we promised when you uploaded them.