Last updated: August 15, 2026
PDFSight is operated by Amidship Inc. ("we", "us", "our"). This policy describes how PDFSight processes information through our website, API, hosted ChatKit experience, ChatGPT, Claude, and compatible MCP Apps hosts.
Product boundary: PDFSight provides one guided document workflow through those channels. The assistant is the interaction channel; PDFSight owns workflow state, deterministic PDF construction and filling, and temporary artifact delivery.
The following are the current source-controlled defaults. An expiry window describes when data becomes unavailable to the workflow. Cleanup is performed lazily during the operations identified below; it is not represented as a universal background deletion schedule.
| Category | What PDFSight holds | Current lifecycle |
|---|---|---|
| In-memory form/session state | Session identifiers, uploaded chunks, form schemas, field values, and generated results needed for an active workflow. | 30 minutes of inactivity; expired state is removed by bounded lazy cleanup during session activity. |
| Hosted ChatKit thread/message state | Thread metadata and messages handled by PDFSight's hosted OpenAI/ChatKit agent. | 30 minutes of inactivity; bounded lazy cleanup removes the thread and its items together. This store is process-local, non-durable, and not shared across workers. |
| Local MCP artifacts | Temporary fillable and filled PDFs plus owner-bound metadata when local filesystem persistence is used. | up to 6 hours; access-time and persistence-time checks lazily delete expired files. |
| S3 PDF artifacts | Temporary source and processed PDFs plus artifact metadata when S3 storage is enabled. | up to 1 hour; access checks treat expired objects as unavailable and attempt paired PDF/metadata deletion. |
| Presigned download URLs | Time-limited delivery links to an eligible S3 object. | 5 minutes; expiry is embedded in each generated URL and does not extend the underlying artifact lifecycle. |
| One-time PDFSight download tickets | Opaque delivery capabilities minted only after identity and artifact ownership checks. The capability travels in a URL fragment, which is not sent in HTTP request paths or referrers, and only its SHA-256 digest is stored. | 5 minutes or one successful use, whichever comes first; the first successful same-origin POST redemption consumes the ticket atomically and does not extend the underlying artifact lifecycle. |
| Pending account verification | Normalized email address, display name, Argon2id password hash, terms-acceptance timestamp, attempt count, and a one-time verification code stored only as a server-keyed HMAC-SHA-256 digest. | 10 minutes to verify; expired records are eligible for bounded cleanup after 24 additional hours. |
| Account and authentication data | For verified accounts: normalized email address, display name, tenant identifier, and an Argon2id password hash. If a supported external identity is used, PDFSight also stores the immutable identity issuer and subject plus the email observed when linked. We also process OAuth grants, hashed authorization-code and refresh-token records, revocation state, and security/audit metadata. | Retained while needed to provide and secure the account, honor active grants, enforce revocation, resolve abuse, and meet applicable legal obligations. |
| Usage and estimated-cost metadata | Account identifier, tenant and client channel, operation and outcome, provider/model, provider-reported token counts, estimated provider cost, page/field counts, duration, and timestamp. This ledger excludes PDF contents, filenames, field values, prompts, conversations, credentials, and artifact identifiers. | up to 400 days; bounded lazy cleanup removes expired rows. Access is restricted to specifically provisioned PDFSight administrators. |
| Request and infrastructure logs | Operational request metadata such as timestamps, methods, paths, response codes, and diagnostic events. Application access logs omit query strings. | No fixed retention period is enforced by this repository; operational infrastructure controls apply. |
We do not store plaintext passwords, plaintext verification codes, plaintext refresh tokens, or bearer access tokens. We do not collect payment information. Account identifiers authenticate users, bind temporary documents to the correct account and tenant, and secure OAuth access.
The machine-readable source for these values, mechanisms, and enforcement paths is available at /trust-manifest.json.
We use the data we collect solely for the following purposes:
We do not use your data for advertising, profiling, or any purpose unrelated to providing the PDFSight service.
Retention periods for temporary state and artifacts are listed in Section 1. In practice:
The provider involved depends on the channel and storage path you use. PDFSight does not represent ChatGPT or Claude as the component that constructs or fills the PDF.
| Provider | Data and role | Privacy policy |
|---|---|---|
| PDFSight / Amidship Inc. | Receives the files, tool inputs, and field values needed to perform the workflow. PDFSight owns temporary workflow state, deterministic PDF construction and filling, and temporary artifact delivery. | This policy |
| Google Gemini API | Receives rendered document-page images for field and document interpretation. Gemini proposes structure; PDFSight's application code constructs and fills the PDF. | Google Privacy Policy |
| OpenAI | Processes hosted ChatKit and ChatGPT interaction data when either channel is used. PDFSight's hosted ChatKit path also keeps the process-local state described in Section 1. If PDFSight later activates its preregistered OpenAI identity option, OpenAI also authenticates that identity and returns the issuer/subject and requested profile claims; the option remains hidden when no client is provisioned. | OpenAI Privacy Policy |
| Anthropic | Processes Claude conversation and tool-interaction data when Claude is used as the assistant channel. | Anthropic Privacy Policy |
| Amazon Web Services S3 | Stores temporary source and processed PDF artifacts when S3 storage is enabled. | AWS Privacy Policy |
| Postmark | Delivers one-time account-verification emails. PDFSight sends the recipient email address, display sender, subject, and verification-message content. PDF documents are never sent to Postmark. | Postmark Privacy Policy |
Each assistant or provider may process data under its own terms and policies. We do not make unverified claims here about provider training settings or provider-side retention.
Beyond these service providers, we do not sell, trade, rent, or otherwise share your data with any third party, except:
You have the following rights regarding your data:
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
We implement reasonable technical and organizational measures to protect your data, including:
PDFSight is not intended for users under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children. If you believe a child has provided data to us, please contact us and we will promptly delete it.
PDFSight is operated from Canada. If you access the service from outside Canada, your data may be transferred to and processed in Canada or other jurisdictions where our service providers operate. By using PDFSight, you consent to this transfer.
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. If we make material changes, we will make reasonable efforts to notify users (e.g., via a notice on the website).
For privacy-related questions, data requests, or concerns:
PDFSight is a product of Amidship Inc. The data controller responsible for your information is Rida Al Barazi ([email protected]).