Developers

PDFScribe API privacy policy

Last updated: 7 October 2026. PDFScribe API is operated by Veridian Labs LTD. This policy covers the API, developer site, customer console and operator console.

Information and purpose

We process access requests, account and organization details, authentication records, uploaded PDFs and images, extracted JSON, usage and purchase records, support correspondence and security events. We use them to provide extraction, authenticate access, maintain prepaid balances, investigate failures and protect the service. Customer document content is not used for advertising or sold.

Document processing and service providers

Documents and extracted results are stored in Cloudflare R2. The processing worker sends document data to Mistral for OCR and extraction. Temporary worker scratch files are bounded and encrypted. We request deletion of uploaded provider artifacts after processing and retry failed cleanup. Provider artifact deletion is separate from provider retention and model-training settings; this policy does not promise zero provider retention.

Cloud compute, edge security, transactional email, optional Google authentication and payment processing also require service providers. Email delivery uses Resend. Payments use PesaPal. Google authentication, when enabled and linked by you, uses identity information rather than permission to read your mail or files. Contact [email protected] for current sub-processor, transfer and processing details or to discuss a data processing agreement before submitting data with special contractual requirements.

Retention and deletion

Each accepted job snapshots its processing and retention policy. The current default input window is 24 hours after the last associated extraction finishes. The current default canonical JSON result window is seven days from result storage. Shared uploads remain until associated work finishes; cleanup failures can delay physical deletion and are retried. Expired results cannot be treated as a permanent document archive. Download results your integration needs to retain.

Policy defaults for operational metadata, security audit and accounting are 30 days, 365 days and 2,555 days respectively. These policy fields do not promise automatic deletion at an exact instant. Operational records may remain after document expiry, and append-only accounting and security records may be retained for legal obligations, dispute resolution and service integrity. Backup copies and provider records have separate lifecycle controls. Contact us for deletion requests and the applicable retention details; we do not promise immediate deletion from backups or immutable records.

Security and your responsibilities

Connections use HTTPS, passwords and API keys are stored as verifiers, and tenant access is checked from authenticated membership. Keep invitation tokens, passwords, API keys and webhook secrets private. Do not include documents, extracted content, credentials or payment details in support reports. No system can guarantee complete security. Submit only data you are authorized to share and for which this processing arrangement is suitable.

Privacy rights, incidents and changes

Depending on applicable law, you may request access, correction, deletion or restriction of your personal information, object to processing, or complain to the relevant supervisory authority. We verify identity and authority before acting and handle requests according to applicable law. Privacy requests and data incidents can be sent to [email protected]. Security reports can be sent to [email protected]. We provide legally required notifications and follow any separately agreed contract; no additional response-time guarantee is made here.

Material policy changes will be identified in an updated version and communicated as required by law or an applicable contract. This developer site does not load marketing analytics or advertising trackers. Authentication surfaces use cookies needed for sessions and request protection.

GuidesPlan your integrationAPI referenceExplore the contractStatusCheck service updates