Privacy Policy

Last updated: August 15, 2026

PDFSight is operated by Amidship Inc. ("we", "us", "our"). This policy describes how PDFSight processes information through our website, API, hosted ChatKit experience, ChatGPT, Claude, and compatible MCP Apps hosts.

Product boundary: PDFSight provides one guided document workflow through those channels. The assistant is the interaction channel; PDFSight owns workflow state, deterministic PDF construction and filling, and temporary artifact delivery.

1. Data we process and current retention

The following are the current source-controlled defaults. An expiry window describes when data becomes unavailable to the workflow. Cleanup is performed lazily during the operations identified below; it is not represented as a universal background deletion schedule.

CategoryWhat PDFSight holdsCurrent lifecycle
In-memory form/session stateSession identifiers, uploaded chunks, form schemas, field values, and generated results needed for an active workflow.30 minutes of inactivity; expired state is removed by bounded lazy cleanup during session activity.
Hosted ChatKit thread/message stateThread metadata and messages handled by PDFSight's hosted OpenAI/ChatKit agent.30 minutes of inactivity; bounded lazy cleanup removes the thread and its items together. This store is process-local, non-durable, and not shared across workers.
Local MCP artifactsTemporary fillable and filled PDFs plus owner-bound metadata when local filesystem persistence is used.up to 6 hours; access-time and persistence-time checks lazily delete expired files.
S3 PDF artifactsTemporary source and processed PDFs plus artifact metadata when S3 storage is enabled.up to 1 hour; access checks treat expired objects as unavailable and attempt paired PDF/metadata deletion.
Presigned download URLsTime-limited delivery links to an eligible S3 object.5 minutes; expiry is embedded in each generated URL and does not extend the underlying artifact lifecycle.
One-time PDFSight download ticketsOpaque delivery capabilities minted only after identity and artifact ownership checks. The capability travels in a URL fragment, which is not sent in HTTP request paths or referrers, and only its SHA-256 digest is stored.5 minutes or one successful use, whichever comes first; the first successful same-origin POST redemption consumes the ticket atomically and does not extend the underlying artifact lifecycle.
Pending account verificationNormalized email address, display name, Argon2id password hash, terms-acceptance timestamp, attempt count, and a one-time verification code stored only as a server-keyed HMAC-SHA-256 digest.10 minutes to verify; expired records are eligible for bounded cleanup after 24 additional hours.
Account and authentication dataFor verified accounts: normalized email address, display name, tenant identifier, and an Argon2id password hash. If a supported external identity is used, PDFSight also stores the immutable identity issuer and subject plus the email observed when linked. We also process OAuth grants, hashed authorization-code and refresh-token records, revocation state, and security/audit metadata.Retained while needed to provide and secure the account, honor active grants, enforce revocation, resolve abuse, and meet applicable legal obligations.
Usage and estimated-cost metadataAccount identifier, tenant and client channel, operation and outcome, provider/model, provider-reported token counts, estimated provider cost, page/field counts, duration, and timestamp. This ledger excludes PDF contents, filenames, field values, prompts, conversations, credentials, and artifact identifiers.up to 400 days; bounded lazy cleanup removes expired rows. Access is restricted to specifically provisioned PDFSight administrators.
Request and infrastructure logsOperational request metadata such as timestamps, methods, paths, response codes, and diagnostic events. Application access logs omit query strings.No fixed retention period is enforced by this repository; operational infrastructure controls apply.

We do not store plaintext passwords, plaintext verification codes, plaintext refresh tokens, or bearer access tokens. We do not collect payment information. Account identifiers authenticate users, bind temporary documents to the correct account and tenant, and secure OAuth access.

The machine-readable source for these values, mechanisms, and enforcement paths is available at /trust-manifest.json.

2. Purposes of Use

We use the data we collect solely for the following purposes:

We do not use your data for advertising, profiling, or any purpose unrelated to providing the PDFSight service.

3. Storage and deletion mechanics

Retention periods for temporary state and artifacts are listed in Section 1. In practice:

4. Processing channels and providers

The provider involved depends on the channel and storage path you use. PDFSight does not represent ChatGPT or Claude as the component that constructs or fills the PDF.

ProviderData and rolePrivacy policy
PDFSight / Amidship Inc.Receives the files, tool inputs, and field values needed to perform the workflow. PDFSight owns temporary workflow state, deterministic PDF construction and filling, and temporary artifact delivery.This policy
Google Gemini APIReceives rendered document-page images for field and document interpretation. Gemini proposes structure; PDFSight's application code constructs and fills the PDF.Google Privacy Policy
OpenAIProcesses hosted ChatKit and ChatGPT interaction data when either channel is used. PDFSight's hosted ChatKit path also keeps the process-local state described in Section 1. If PDFSight later activates its preregistered OpenAI identity option, OpenAI also authenticates that identity and returns the issuer/subject and requested profile claims; the option remains hidden when no client is provisioned.OpenAI Privacy Policy
AnthropicProcesses Claude conversation and tool-interaction data when Claude is used as the assistant channel.Anthropic Privacy Policy
Amazon Web Services S3Stores temporary source and processed PDF artifacts when S3 storage is enabled.AWS Privacy Policy
PostmarkDelivers one-time account-verification emails. PDFSight sends the recipient email address, display sender, subject, and verification-message content. PDF documents are never sent to Postmark.Postmark Privacy Policy

Each assistant or provider may process data under its own terms and policies. We do not make unverified claims here about provider training settings or provider-side retention.

Beyond these service providers, we do not sell, trade, rent, or otherwise share your data with any third party, except:

5. Your Rights and Controls

You have the following rights regarding your data:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

6. Security

We implement reasonable technical and organizational measures to protect your data, including:

7. Children's Privacy

PDFSight is not intended for users under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children. If you believe a child has provided data to us, please contact us and we will promptly delete it.

8. International Users

PDFSight is operated from Canada. If you access the service from outside Canada, your data may be transferred to and processed in Canada or other jurisdictions where our service providers operate. By using PDFSight, you consent to this transfer.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. If we make material changes, we will make reasonable efforts to notify users (e.g., via a notice on the website).

10. Contact Us

For privacy-related questions, data requests, or concerns:

PDFSight is a product of Amidship Inc. The data controller responsible for your information is Rida Al Barazi ([email protected]).