Privacy Policy

Last updated: August 15, 2026

PDFSight is operated by Amidship Inc. ("we", "us", "our"). This policy describes how PDFSight processes information through our website, API, hosted ChatKit experience, ChatGPT, Claude, and compatible MCP Apps hosts.

Product boundary: PDFSight provides one guided document workflow through those channels. The assistant is the interaction channel; PDFSight owns workflow state, deterministic PDF construction and filling, and temporary artifact delivery.

1. Data we process and current retention

The following are the current source-controlled defaults. An expiry window describes when data becomes unavailable to the workflow. Cleanup is performed lazily during the operations identified below; it is not represented as a universal background deletion schedule.

CategoryWhat PDFSight holdsCurrent lifecycle
In-memory form/session stateSession identifiers, uploaded chunks, form schemas, field values, and generated results needed for an active workflow.30 minutes of inactivity; expired state is removed by bounded lazy cleanup during session activity.
Hosted ChatKit thread/message stateThread metadata and messages handled by PDFSight's hosted OpenAI/ChatKit agent.30 minutes of inactivity; bounded lazy cleanup removes the thread and its items together. This store is process-local, non-durable, and not shared across workers.
Local MCP artifactsTemporary fillable and filled PDFs plus owner-bound metadata when local filesystem persistence is used.up to 6 hours; access-time and persistence-time checks lazily delete expired files.
S3 PDF artifactsTemporary source and processed PDFs plus artifact metadata when S3 storage is enabled.up to 1 hour; access checks treat expired objects as unavailable and attempt paired PDF/metadata deletion.
Presigned download URLsTime-limited delivery links to an eligible S3 object.5 minutes; expiry is embedded in each generated URL and does not extend the underlying artifact lifecycle.
One-time PDFSight download ticketsOpaque delivery capabilities minted only after identity and artifact ownership checks. The capability travels in a URL fragment, which is not sent in HTTP request paths or referrers, and only its SHA-256 digest is stored.5 minutes or one successful use, whichever comes first; the first successful same-origin POST redemption consumes the ticket atomically and does not extend the underlying artifact lifecycle.
Pending account verificationNormalized email address, display name, Argon2id password hash, terms-acceptance timestamp, attempt count, and a one-time verification code stored only as a server-keyed HMAC-SHA-256 digest.10 minutes to verify; expired records are eligible for bounded cleanup after 24 additional hours.
Account and authentication dataFor verified accounts: normalized email address, display name, tenant identifier, email-verification source, and terms-acceptance timestamp. A password is optional; when present, only its Argon2id hash is stored. For each linked Google, ChatGPT, or Apple sign-in, PDFSight stores the provider, immutable issuer and subject, email and verification status observed when linked, and optional display name or picture URL. We also process OAuth grants, hashed authorization-code and refresh-token records, revocation state, and security/audit metadata.Retained while needed to provide and secure the account, honor active grants, enforce revocation, resolve abuse, and meet applicable legal obligations.
Usage and estimated-cost metadataAccount identifier, tenant and client channel, operation and outcome, provider/model, provider-reported token counts, estimated provider cost, page/field counts, duration, and timestamp. This ledger excludes PDF contents, filenames, field values, prompts, conversations, credentials, and artifact identifiers.up to 400 days; bounded lazy cleanup removes expired rows. Access is restricted to specifically provisioned PDFSight administrators.
Request and infrastructure logsOperational request metadata such as timestamps, methods, paths, response codes, and diagnostic events. Application access logs omit query strings.No fixed retention period is enforced by this repository; operational infrastructure controls apply.

We do not store plaintext passwords, plaintext verification codes, plaintext refresh tokens, bearer access tokens, or access/refresh tokens received from an external identity provider. We do not collect payment information. Account identifiers authenticate users, bind temporary documents to the correct account and tenant, and secure OAuth access.

The machine-readable source for these values, mechanisms, and enforcement paths is available at /trust-manifest.json.

2. Purposes of Use

We use the data we collect solely for the following purposes:

We do not use your data for advertising, profiling, or any purpose unrelated to providing the PDFSight service.

3. Storage and deletion mechanics

Retention periods for temporary state and artifacts are listed in Section 1. In practice:

4. Processing channels and providers

The provider involved depends on the channel and storage path you use. PDFSight does not represent ChatGPT or Claude as the component that constructs or fills the PDF.

ProviderData and rolePrivacy policy
PDFSight / Amidship Inc.Receives the files, tool inputs, and field values needed to perform the workflow. PDFSight owns temporary workflow state, deterministic PDF construction and filling, and temporary artifact delivery.This policy
Google Gemini APIReceives rendered document-page images for field and document interpretation. Gemini proposes structure; PDFSight's application code constructs and fills the PDF.Google Privacy Policy
Google Identity ServicesIf you choose Google sign-in, Google authenticates you and returns a signed identifier plus the email, email-verification status, name, and picture claims you authorize. PDFSight discards Google's authorization code and tokens after verification.Google Privacy Policy
OpenAIProcesses hosted ChatKit and ChatGPT interaction data when either channel is used. PDFSight's hosted ChatKit path also keeps the process-local state described in Section 1. If you choose ChatGPT sign-in after it is activated, OpenAI authenticates you and returns the signed issuer/subject and requested email/profile claims; PDFSight discards OpenAI's authorization code and tokens after verification.OpenAI Privacy Policy
AppleIf you choose Sign in with Apple, Apple authenticates you and returns a signed identifier, verified email (which may be a Private Relay address), and—on first authorization only—the name you elect to share. PDFSight discards Apple's authorization code and tokens after verification.Apple Privacy Policy
AnthropicProcesses Claude conversation and tool-interaction data when Claude is used as the assistant channel.Anthropic Privacy Policy
Amazon Web Services S3Stores temporary source and processed PDF artifacts when S3 storage is enabled.AWS Privacy Policy
PostmarkDelivers one-time account-verification emails. PDFSight sends the recipient email address, display sender, subject, and verification-message content. PDF documents are never sent to Postmark.Postmark Privacy Policy

Each assistant or provider may process data under its own terms and policies. We do not make unverified claims here about provider training settings or provider-side retention.

Beyond these service providers, we do not sell, trade, rent, or otherwise share your data with any third party, except:

5. Your Rights and Controls

You have the following rights regarding your data:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

6. Security

We implement reasonable technical and organizational measures to protect your data, including:

7. Children's Privacy

PDFSight is not intended for users under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children. If you believe a child has provided data to us, please contact us and we will promptly delete it.

8. International Users

PDFSight is operated from Canada. If you access the service from outside Canada, your data may be transferred to and processed in Canada or other jurisdictions where our service providers operate. By using PDFSight, you consent to this transfer.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. If we make material changes, we will make reasonable efforts to notify users (e.g., via a notice on the website).

10. Contact Us

For privacy-related questions, data requests, or concerns:

PDFSight is a product of Amidship Inc. The data controller responsible for your information is Rida Al Barazi ([email protected]).