Security and Data Handling

PDF2TEXT uses authenticated workspaces, bounded processing, and HTTPS transport to protect customer document workflows.

HTTPS Transport

The production site and API are served over HTTPS. Secure cookies and strict transport security are enabled for production sessions.

Private Workspace Retention

Uploaded files and extracted results remain available in your private workspace for review and export. We do not currently promise automatic deletion after 24 hours. Contact support to request deletion.

Purpose-Limited Processing

Customer documents are processed to provide extraction, validation, and export features. We configure supported OpenAI API requests with storage disabled and do not sell uploaded documents or extracted financial data.

Bounded Processing

File size, page count, image dimensions, render memory, request rates, and worker time are bounded to protect service availability.

Strict Access Control

Documents and exports are owner-scoped. Browser sessions and API keys cannot read another account's files or runs.

Data Requests

You can contact support to request access to or deletion of account data and stored documents. Business customers can also request subprocessor details or a data processing addendum path from security@pdf2text.ai.

Questions About Security?

We're happy to answer any questions about our security practices and how we protect your financial data.

Contact Security Team