Security & Data Protection

Security & Data Protection

This page collects the information most often requested in corporate security reviews. If you need a more detailed document or answers to your own security questionnaire, please contact us.

Last updated: August 11, 2026

This is a reference English translation provided for convenience. The Japanese version is authoritative; where the two differ, the Japanese text prevails.

Data flowData flow

Rasterizing PDF pages happens in your browser by default. Our application runs on Google Cloud in the Tokyo region. Three steps analyse the content of your document with AI (this is processing, not storage).

StepWhat happensSent to
1. BrowserPages are rasterized locally, then uploaded
2. Our platformJob execution and storageGoogle Cloud (Tokyo) / Supabase (Tokyo)
3. Text recognitionCharacters and their positionsMicrosoft Azure Document Intelligence
4. Layout & styleFigure regions and text stylingGoogle Vertex AI (Gemini)
5. Background restoreBackground image with text removedRunPod
6. Edit & exportEdited in the browser; PPTX generated on demand

Support enquiries you send us are also passed to Google Vertex AI (Gemini) to draft a reply.

Our platform runs in Tokyo, but AI processing locations are as listed below. We do not offer Japan-only processing (see “What we do not yet provide”).

SubprocessorsSubprocessors

The authoritative version of this table isSection 3 of our Privacy Policy. This page restates it in a form that is easier to review; additions and changes are announced through revisions of the Privacy Policy.

ProviderPurposeMain locations
Microsoft (Azure Document Intelligence)Text recognition (OCR)Japan / USA
Google (Vertex AI / Gemini)Layout and style estimation; generating replies to inquiriesUSA, etc.
RunPodBackground restoration (image inpainting)Japan / USA
Google Cloud (Cloud Run / Cloud Tasks)Application infrastructure and job executionJapan (Tokyo) / USA, etc.
SupabaseAuthentication, database, storageJapan (Tokyo) / USA, etc.
StripePayment processingUSA, etc.
Vercel / CloudflareHosting, delivery, anti-abuseUSA, etc.
Google (Gmail / Workspace)Sending notification emailsUSA, etc.
PostHog, Inc.Analysis of service usage (analytics)USA

A data processing agreement (DPA) applies to each provider. Signed DPAs are in place with Supabase, RunPod and PostHog; for the others, the standard DPA incorporated into their terms applies and we record the version in force.

The AI services used for text recognition, layout and style estimation, background restoration and support replies are contracted and configured so that input data is not used to train models.

Retention and deletionRetention

DataRetention
Uploaded PDFs and imagesDeleted promptly after conversion completes
Editing dataMaximum of 24 hours (Free), 7 days (Starter) or 30 days (Pro/Business). Defaults are 3 days (Starter) and 7 days (Pro/Business); you can set any value from 1 day up to the maximum
PPTX filesNot stored — regenerated from your editing data on each download. The temporary download file is deleted automatically within 24 hours
Expired dataRemoved by a scheduled deletion job, which is itself monitored for liveness

You can delete your account and data, and download your personal data as JSON, from the settings screen. Retention periods for logs and accounting records are listed in our Privacy Policy.

SafeguardsSafeguards

  • All traffic is encrypted with TLS.
  • Every storage bucket is private; files are retrieved only through expiring signed URLs.
  • Row level security is enabled on every database table, and ownership is checked again in the API.
  • Authentication is Google / Microsoft OAuth only. We do not hold passwords.
  • Payments are handled by Stripe; we do not hold card numbers.
  • Secrets are held in Secret Manager, and service accounts are separated by purpose with least privilege.
  • Human verification and API rate limiting protect against bots and abuse.
  • Multi-factor authentication is enabled on every operational account.
  • Every change must pass automated tests, static analysis and a build.
  • The production branch is protected by repository rules: only commits whose automated checks have all succeeded can be accepted, with no exemption for administrators.
  • Changes are exercised end to end in a separate staging environment configured to match production, and only what passes there is released.
  • After each release we run a fixed set of checks, and we can roll back to the previous version if something is wrong.

Team isolationTeam isolation

Being in the same Business team does not share the documents themselves.

InformationVisible to
Member email, name, join date, roleAll members of the team
Team credit balance, seats, contractAll members of the team
Per-member credit usage this monthOwner and administrators only
Uploaded documents, editing data, resultsThe member only — not even the owner can see them (restricted by row level security)

Incident responseIncident response

  • We maintain a documented procedure for suspected personal data breaches (immediate response, scoping, reporting to the supervisory authority, notifying affected people) together with notification templates.
  • Reports to the Personal Information Protection Commission and notifications to affected people follow Article 26 of Japan's Act on the Protection of Personal Information.
  • We do not currently commit to a fixed notification deadline. If your contract requires one, please talk to us.

What we do not yet provideNot yet

Stated plainly: what is missing, and what stands in its place today.

Third-party certification (ISO 27001 / SOC 2)
Not obtained. Our implemented controls are disclosed under “Safeguards”, and we answer individual security questionnaires on request.
Third-party penetration testing
Not performed. We review authorisation and exposure continuously, and every change passes automated checks.
SAML/SSO and IP allow-listing
Not supported. Authentication is Google / Microsoft OAuth only, and we hold no passwords.
Processing restricted to Japan
Not offered. Our platform runs in Tokyo, but AI processing locations are as listed under “Subprocessors”.

Some availability and recovery items (uptime SLA, recovery granularity) are also not provided. We cover these in the document we send on request — please contact us.

Frequently asked questionsFAQ

Will my documents be used to train AI, or seen by other users?

No. The AI services used for text recognition, layout and style estimation, background restoration and support replies are contracted and configured so that input data is never used for training (zero data retention and equivalent settings).

Can the owner of my team see the documents I upload?

No. Documents, editing data and results are visible only to the member who created them — owners and administrators cannot see them (see “Team isolation”).

Will you complete our security questionnaire?

Yes. Please check what this page already answers, then send us your questionnaire through the contact form.

Request our review pack

If you need a more detailed document, or answers to your own security questionnaire, contact us and we will respond once we understand your requirements.

Contact us