Privacy policy

2026-09-06

In short

We keep your email address and the documents you upload. Each document is sent once to OpenAI to locate the fields to fill. We sell nothing, track no one, and install no advertising cookies.

What we collect

Your email address and your password, the latter as a scrypt hash — we cannot read it, nor remind you of it.

The documents you upload, their content, and the fields you place on them along with what you write into them.

A session cookie, strictly necessary to recognise you from one page to the next. There are no analytics or advertising cookies, and therefore no banner to click.

Why, and on what basis

To provide the service you asked for: keeping your documents, finding the fields, letting you fill them in and take them back. The legal basis is performance of our contract with you (GDPR article 6.1.b).

Who else sees your documents

OpenAI, Ireland Ltd. When you upload a document, it is sent once to their vision model to recognise the fields and name them. OpenAI undertakes not to use data submitted through their API to train their models.

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Allemagne, which hosts the server — without accessing the content.

No one else. Your documents are not sold, not analysed for any other purpose, and not read by us outside a technical intervention you have asked for.

For how long

Your documents stay in your account for as long as you leave them there. You can delete any of them at any time: it is then erased from the database and from storage, for good.

A document you stop opening is erased automatically after ninety days. The clock restarts each time you open it.

Deleting your account erases all your documents with it.

Your rights

You may request access to your data, its correction, its erasure, its portability, or object to its processing. Write to [email protected].

If our answer does not satisfy you, you may lodge a complaint with the Belgian Data Protection Authority, rue de la Presse 35, 1000 Brussels (autoriteprotectiondonnees.be).

Security

Traffic goes over HTTPS. Passwords are hashed with scrypt, never stored in the clear. The session cookie is out of reach of page scripts. Documents live in private storage, with no public address.

None of this makes a breach impossible. Should one occur and put you at risk, we would tell you, and the Data Protection Authority.

Legal notice·Privacy