Privacy & data

How your document is handled

This page describes what the product actually does today. It is an operational disclosure, not a finished legal privacy policy.

What you submit

A PDF or Word document you upload, or wording you paste in. You may also tell us what kind of document it is and what matters most to you. Nothing else is asked for.

Only upload or paste documents you are authorized to share. Documents often contain other people's information as well as your own.

Why it is processed

To produce one plain-language report: what the document says, what it means, why it matters, and where each finding was found. It is not used for advertising, profiling, model training by us, or any other purpose.

The path your document takes

  1. You choose a file or paste wording in your browser.
  2. The file's bytes, or the pasted wording, are sent by an HTTPS POST request to the Before You Sign server. Document content is never placed in a web address.
  3. The server checks the file's size, type and signature, then extracts the text — page by page for a PDF, paragraph by paragraph for a Word document.
  4. Only what the analysis needs is sent to OpenAI: the extracted text, or the uploaded file inline within the single request, plus the document kind and your chosen priorities. Your filename is not sent; a generic name is used instead.
  5. OpenAI returns a structured analysis.
  6. The server checks every quoted passage against your own document and discards findings it cannot trace, then returns the report.
  7. The report is held in this browser tab only.

The one cookie we set

To keep the service usable and to stop automated misuse, the server sets one small cookie. It holds a random string and nothing else: no name, no email address, no location, no filename and nothing from your document. It cannot be read by JavaScript in your browser, it is only sent back to this site, and it expires after 24 hours.

The server uses it to count how many analyses have been run recently and to make sure only one analysis runs at a time for you. A one-way scrambled version of it is sent to OpenAI as an abuse-prevention identifier — it cannot be turned back into the cookie, and it is not linked to you as a person. Clearing your cookies simply gives you a new random string.

What is not saved

This version has no account and no database. Original files, extracted text, pasted wording, quotations, analyses and reports are not written to a database, to server files, to a queue or cache, or to deployment logs. They are not written to localStorage, sessionStorage, IndexedDB, your browser history, or the cookie described above.

The server holds your content in memory only for the length of the request, and releases its references when the request finishes. We do not claim that JavaScript memory is securely erased or overwritten — reclaiming memory is the runtime's business, not ours.

What stays in this tab

The document you added and the finished report stay in this tab's memory so you can read them. They disappear when you clear them, refresh the page, close the tab, or start another document.

OpenAI

Analysis is performed by OpenAI. Each request explicitly sets store: false, so the request is not retained by OpenAI as stored response state. We do not use the Files API, Conversations, Threads, Assistants or Vector Stores, and no data-sharing or training opt-in is enabled in our code.

OpenAI states that data submitted through its API is not used to train its models unless the API account opts in. OpenAI's default abuse-monitoring retention may keep content for up to 30 days. Before You Sign has not claimed or confirmed Zero Data Retention with OpenAI, so we cannot promise same-day removal of your content from those logs.

What we may record

Operational records may contain a request identifier, the model identifier, whether the source was a file or pasted text, the file type, byte count, page count, how long the work took, token counts, an outcome category and a sanitized error category.

They never contain document contents, extracted text, quotations, report text, pasted wording, file bytes, filenames, API keys, authorization headers or complete provider responses. Application code does not log IP addresses or user-agent strings.

Limits we keep

Uploads are limited to one PDF or Word file, up to 10 MB and 40 pages, and are checked against their declared type and their own file signature. Pasted wording must be between 400 and 45,000 characters.

Status of this page

This page describes current product behaviour during development. It should receive professional privacy and legal review before public launch. Before You Sign explains documents in plain language; it does not provide legal, financial, medical or insurance advice. We explain. You decide.