Security and privacy
Your documents stay yours
Unpublished manuscripts, patient reports and internal studies need care. This page explains where your files live, who can see them, and when they’re deleted.
- Files stored in the EU
- Zero data retention for AI
- Deletion on your schedule
- Two-step verification
01
Where your files live
- Uploaded PDFs are stored in EU-jurisdiction object storage.
- Every connection to PDFSifter uses HTTPS.
- Results live in a managed database with automatic backups.
02
Retention and deletion
- Source PDFs are deleted after your workspace’s retention period: 30 days on Free, 60 on Starter and 90 on Lab and Research. The extracted values, quotes and text stay, so results and search keep working.
- Deleted jobs and templates wait in the Trash for 30 days, then they’re removed for good. You can delete them forever sooner.
- Export files are kept for 7 days.
- When you delete your account, workspaces you own on your own are removed with their files after 30 days.
03
How AI sees your documents
- Page text is sent to AI models only to extract, draft and train for your own workspace.
- Requests go only to providers that commit to zero data retention, so they don’t store your text.
- Templates, training pairs and prompts belong to your workspace. Nothing is shared with other customers.
04
Accounts and sign-in
- Two-step verification with an authenticator app, plus one-time recovery codes.
- Sign in with Google, Microsoft or ORCID, or with email and password.
- Resetting your password signs you out on every device.
- We email you when your password, email, two-step settings or API keys change, and we sign out a device if its sign-in token looks copied.
05
Control inside your workspace
- Roles decide who can upload, review, train, export and change settings.
- An audit log records who changed what, and when.
- API keys act with their owner’s role, and read-only keys can’t change anything.
- Webhooks are signed with HMAC-SHA256 so you can check they came from us.
Services we use
| Provider | What for |
|---|---|
| Cloudflare | Serving the app, file storage (EU jurisdiction), outgoing email |
| DigitalOcean | Application servers and the managed database |
| OpenRouter | Routing AI requests to zero-data-retention model providers |
| Stripe | Payments and invoices |
Found a security issue?
Please tell us privately at security@pdfsifter.com. We’ll confirm we got it and keep you updated while we fix it.