Security & Data Protection

Security & Data Protection

This page collects the information most often requested in corporate security reviews. If you need a more detailed document or answers to your own security questionnaire, please contact us.

Last updated: September 21, 2026

This is a reference English translation provided for convenience. The Japanese version is authoritative; where the two differ, the Japanese text prevails.

Data flowData flow

Rasterizing PDF pages happens in your browser by default. Our application runs on Google Cloud in the Tokyo region. Three steps analyse the content of your document with AI (this is processing, not storage).

StepWhat happensSent to
1. BrowserPages are rasterized locally, then uploaded—
2. Our platformJob execution and storageGoogle Cloud (Tokyo) / Supabase (Tokyo)
3. Text recognitionCharacters and their positionsMicrosoft Azure Document Intelligence
4. Layout & styleFigure regions and text stylingGoogle Vertex AI (Gemini)
5. Background restoreBackground image with text removedRunPod
6. Edit & exportEdited in the browser; PPTX, PDF, PNG and JPEG generated on demand—

Support enquiries you send us are also passed to Google Vertex AI (Gemini) to draft a reply.

Our platform runs in Tokyo, but AI processing locations are as listed below. We do not offer Japan-only processing (see “What we do not yet provide”).

SubprocessorsSubprocessors

The authoritative version of this table isSection 3 of our Privacy Policy. This page restates it in a form that is easier to review; additions and changes are announced through revisions of the Privacy Policy.

ProviderPurposeMain locations
Microsoft (Azure Document Intelligence)Text recognition (OCR)Japan / USA
Google (Vertex AI / Gemini)Layout and style estimation; generating replies to inquiriesUSA, etc.
RunPodBackground restoration (image inpainting)Japan / USA
Google Cloud (Cloud Run / Cloud Tasks)Application infrastructure and job executionJapan (Tokyo) / USA, etc.
SupabaseAuthentication, database, storageJapan (Tokyo) / USA, etc.
StripePayment processingUSA, etc.
Vercel / CloudflareHosting, delivery, anti-abuse, web analytics (Vercel Web Analytics)USA, etc.
Google (Gmail / Workspace)Sending notification emailsUSA, etc.
PostHog, Inc.Analysis of service usage (analytics)USA

A data processing agreement (DPA) applies to each provider. Signed DPAs are in place with Supabase, RunPod and PostHog; for the others, the standard DPA incorporated into their terms applies and we record the version in force.

The AI services used for text recognition, layout and style estimation, background restoration and support replies are contracted and configured so that input data is not used to train models.

Retention and deletionRetention

DataRetention
Uploaded PDFs and imagesDeleted promptly after conversion completes
Editing dataMaximum of 7 days (Free/Light) or 30 days (Standard/Team). Defaults are 1 day (Free), 3 days (Light) and 7 days (Standard/Team); you can set any value from 1 day up to the maximum
Export files (PPTX, PDF, PNG, JPEG)Not stored — regenerated from your editing data on each download. The temporary download file is deleted automatically within 24 hours
Expired dataRemoved by a scheduled deletion job, which is itself monitored for liveness

You can delete your account and data, and download your personal data as JSON, from the settings screen. Retention periods for logs and accounting records are listed in our Privacy Policy.

SafeguardsSafeguards

  • All traffic is encrypted with TLS.
  • Every storage bucket is private; files are retrieved only through expiring signed URLs.
  • Row level security is enabled on every database table, and ownership is checked again in the API.
  • Authentication is Google / Microsoft OAuth only. We do not hold passwords.
  • Being signed in does not last indefinitely: a session ends after 30 days without activity, or after 90 days at the latest, and you sign in again.
  • If a device is lost, use “Sign out of all devices” on the settings page to revoke them yourself (every device is cut off within 15 minutes).
  • Payments are handled by Stripe; we do not hold card numbers.
  • Secrets are held in Secret Manager, and service accounts are separated by purpose with least privilege.
  • Human verification and API rate limiting protect against bots and abuse.
  • Multi-factor authentication is enabled on every operational account.
  • Every change must pass automated tests, static analysis and a build.
  • The production branch is protected by repository rules: only commits whose automated checks have all succeeded can be accepted, with no exemption for administrators.
  • Changes are exercised end to end in a separate staging environment configured to match production, and only what passes there is released. The staging environment does not use production data.
  • After each release we run a fixed set of checks, and we can roll back to the previous version if something is wrong.

Team isolationTeam isolation

Being on the same Team plan does not share the documents themselves.

InformationVisible to
Member email, name, join date, roleAll members of the team
Team page balance, seats, contractAll members of the team
Per-member page usage this monthOwner and administrators only
Uploaded documents, editing data, resultsThe member only — not even the owner can see them (restricted by row level security)

Incident responseIncident response

  • We maintain a documented procedure for suspected personal data breaches (immediate response, scoping, reporting to the supervisory authority, notifying affected people) together with notification templates.
  • Reports to the Personal Information Protection Commission and notifications to affected people follow Article 26 of Japan's Act on the Protection of Personal Information.
  • We do not currently commit to a fixed notification deadline. If your contract requires one, please talk to us.

What we do not yet provideNot yet

Stated plainly: what is missing, and what stands in its place today.

Third-party certification (ISO 27001 / SOC 2)
Not obtained. Our implemented controls are disclosed under “Safeguards”, and we answer individual security questionnaires on request.
Third-party penetration testing
Not performed. We review authorisation and exposure continuously, and every change passes automated checks.
SAML/SSO (self-serve plans)
Not offered on Free, Light, Standard or Team. Authentication is Google / Microsoft OAuth only and we hold no passwords — if your organisation uses Google Workspace or Microsoft Entra ID, your own sign-in policies such as multi-factor authentication and conditional access apply as they are. Under an enterprise contract we can provision SAML 2.0 single sign-on (Microsoft Entra ID, Google Workspace or Okta) individually — please contact us.
SCIM (automatic user provisioning and de-provisioning)
Not supported. Even with SAML single sign-on, users are created on first sign-in. When someone leaves, disabling their account at your identity provider stops any new sign-in, and removing them from the team in the team screen stops them using the team's shared pages. If you need them signed out of every device straight away, contact us: we revoke the sessions and every device is cut off within 15 minutes.
IP allow-listing
Not supported. If members sign in through your Google Workspace or Microsoft Entra ID, your own sign-in conditions apply at authentication time.
Processing restricted to Japan
Not offered. Our platform runs in Tokyo, but AI processing locations are as listed under “Subprocessors”.

Some availability and recovery items (uptime SLA, recovery granularity) are also not provided. We cover these in the document we send on request — please contact us.

Frequently asked questionsFAQ

Will my documents be used to train AI, or seen by other users?

No. The AI services used for text recognition, layout and style estimation, background restoration and support replies are contracted and configured so that input data is never used for training (zero data retention and equivalent settings).

Can the owner of my team see the documents I upload?

No. Documents, editing data and results are visible only to the member who created them — owners and administrators cannot see them (see “Team isolation”).

Will you complete our security questionnaire?

Yes. Please check what this page already answers, then send us your questionnaire through the contact form.

Request our review pack

If you need a more detailed document, or answers to your own security questionnaire, contact us and we will respond once we understand your requirements.

Contact us