Legal

Privacy policy.

What we collect, where it is processed, how long it is kept, and who else touches it — stated as specific windows and named subprocessors rather than generalities. Last updated 12 August 2026.

Roles

Controller and processor

For your account data — name, email, organisation, billing records — Routeser is the controller.

For the documents you upload and the values extracted from them, Routeser is a processor acting on your instructions. If those documents contain other people's personal data, you remain the controller and are responsible for having a lawful basis to send them. A data processing agreement is available at dpa@routeser.com.

Routeser is not designed for special categories of data. Do not upload government identity documents, biometric data, health or medical records, or full payment-card numbers without a separate written agreement — see the acceptable-use terms.

Collection

What we collect

  1. Account data: name, email address, organisation name, and authentication identifiers from Google or GitHub sign-in where you use it.
  2. Documents you upload for extraction, and the structured values returned from them.
  3. Operational telemetry: request timing, page counts, model-call counts, and error codes, used for billing and reliability.
  4. Billing records held by Paddle as merchant of record. Routeser never receives or stores your card details.

Location

Where documents are processed

Documents are currently processed in the United States. Routeser is built to run in several regions and the set may change; the current processing regions are published on the trust centre, which is the authoritative list.

If you need processing pinned to a particular region, contact us before sending production data.

Retention

How long anything is kept

Deletion is enforced by storage lifecycle rules, not by someone remembering to run a job.

  1. Uploaded source documents: deleted after 90 days.
  2. Extraction results: deleted after 90 days.
  3. Intermediate page artifacts produced during processing: deleted after 1 day.
  4. Account and billing records: kept while your account is open, and afterwards only as long as tax and accounting law requires.
  5. You may delete an extraction job and its stored document at any time through the API or console.

Subprocessors

Who else is involved

  1. Amazon Web Services — document storage, queueing and extraction compute.
  2. Cloudflare — API edge, account database, and authentication email delivery.
  3. OpenRouter — routes page images to the vision models that perform extraction.
  4. Paddle — merchant of record for payments, subscriptions and invoicing.

The trust centre carries the current list with the data category each one sees. We do not sell personal data, and we do not use your documents or extracted values to train models.

Your rights

Access, correction, deletion and export

You may request access to the personal data we hold about you, correction of anything inaccurate, deletion of your account and its data, or an export. Write to dpa@routeser.com and we will respond within 30 days.

Depending on where you live you may also have the right to complain to a data protection authority.

Security

How it is protected

Documents are encrypted in transit and at rest. Access is scoped per tenant, and API keys are stored only as hashes — a key cannot be recovered from our systems, only replaced.

Routeser holds no third-party security certification today. The trust centre states plainly what exists and what does not, rather than implying an audit that has not happened.

FAQ

Frequently asked questions

Are my documents used to train models?

No. Documents and extracted values are used to answer your request and nothing else, and are deleted on the retention schedule above.

Where are my documents processed?

Currently in the United States. Routeser supports multiple regions and the current list is published on the trust centre; contact us if you need processing pinned to a specific region.

How long do you keep an uploaded file?

Source documents and extraction results are deleted after 90 days, and intermediate page artifacts after 1 day. You can delete a job and its document yourself at any time.

Can I get a DPA?

Yes. Request one at dpa@routeser.com and we will send the current agreement.

Next step

Make a privacy request

Access, correction, deletion, export, or a data processing agreement.

Email us