Privacy Policy
Last updated 26 August 2026
This policy explains what happens to a document you put through ScrubSafe, and what we keep. It is written to be checked against the service's actual behaviour rather than to be reassuring.
1. What happens to a document you upload
A document is processed for the duration of your request and is then deleted. It is written to temporary storage on the server while it is being read and rewritten, and both the uploaded file and the sanitized copy are removed when the request finishes — including when the request fails. The sanitized result is returned to your browser in the response. We do not keep a copy of either file.
2. What we do keep
| Data | Why |
|---|---|
| Your email address | To sign you in and contact you about your account. |
| Your name and the industry you tell us | You supply these when you set up the account; they help us understand who ScrubSafe is for. |
| Per job: a redacted filename | So you can recognise your own history. The filename is put through the same redaction engine as the document, so a name in it becomes a placeholder. The original filename is never stored. |
| Per job: file type, file size, page count, how long it took, how many replacements were made, how many items of each category were found, how many images could not be read | Usage limits, billing, and knowing whether the product works. |
We do not store the sensitive values that were detected. The record says that four items of type PERSON_NAME were replaced; it does not say who they were. A table of detected values would be the single most dangerous thing this service could hold, so it is not created.
3. Diagnostics when something goes wrong
If a job fails, the server records a technical error report so the failure can be investigated, and gives you a reference number. That report can contain fragments of the document being processed. It is short-lived and is not used for any other purpose. We say so here rather than claim that nothing is ever logged.
4. Who else processes your data
| Provider | Role | Where |
|---|---|---|
| Anthropic | Detection. The text of your document is sent to Anthropic's API to identify sensitive information, under API terms that exclude use of that text for training models. | United States |
| Railway | Hosting of the application and the account database. | United States |
| Resend | Delivery of the one-time sign-in codes. Receives your email address, not your documents. | United States |
| Google Fonts | Web fonts on our pages. Your browser requests these directly, which discloses your IP address to Google. No document data is involved. | United States |
Optical character recognition, used to read typed text in scans and images, runs inside our own service. Images are not sent to a third-party OCR provider.
5. Where your data is processed
ScrubSafe runs on cloud infrastructure in the United States. Documents and account data are processed there and are therefore subject to the laws of that country, including lawful access by its authorities. If your firm has a data-residency requirement under PIPEDA or law-society guidance, take this into account before uploading client material. We do not currently offer Canadian-region hosting.
6. Cookies
We set one cookie: a signed session cookie that keeps you logged in. There are no advertising cookies and no third-party analytics on this service.
7. Google Drive
If the optional "Save to Google Drive" feature is enabled, the upload happens from your browser directly to your Drive using an authorisation you grant to Google. Your Google credentials and token never reach our servers, and the permission requested is limited to files ScrubSafe itself creates.
8. Your rights under PIPEDA
Canadian privacy law gives you the right to ask what personal information we hold about you, to have inaccurate information corrected, to withdraw consent, and to have your account and its records deleted. Write to support@scrubsafe.ai and we will respond within 30 days. You may also complain to the Office of the Privacy Commissioner of Canada.
9. How long we keep things
Documents: not kept. Account details: for as long as your account exists. Job records: for as long as your account exists, so your history and usage limits work. Error diagnostics: short-lived. When you ask us to close your account, we delete your account and its job records.
10. Security
Traffic is encrypted in transit. Sign-in is passwordless, so there is no password for us to lose. Access to the production database is limited to the operator of the service. No system is perfectly secure, and we do not claim certification to any security standard.
11. Children
ScrubSafe is a professional tool and is not directed at children.
12. Changes
If we change this policy materially we will give notice by email or in the application before the change takes effect.