This policy explains what Refractr collects, why, how long we keep it, and the choices you have. Refractr is operated from the Netherlands and is subject to the EU General Data Protection Regulation (GDPR). Questions or requests: [email protected].
1. What we collect
- Account data: your email address and a securely hashed password. We never store your password in plain text.
- Usage metadata: API request timestamps, job IDs, credit and billing records, template/document sizes, success/failure status, and IP addresses used for rate limiting and abuse prevention.
- Extraction content (alpha): the full request document (
document_text), the template you submit, and the extracted result. This is retained for debugging and for improving and training the extraction model. - Payment data: credit purchases are processed by Stripe. We do not receive or store your full card details; Stripe handles them under its own privacy policy.
2. Why we use it
- To operate the service: authenticate requests, run extractions, meter credits, and prevent abuse.
- To debug failures and improve extraction quality.
- During the alpha, to generate training data from extraction feedback so the model gets better over time.
- To contact you about your account (e.g. password resets, service notices).
3. How long we keep it
Logged extraction content (documents and results) is automatically deleted or anonymized 30 days after the request. Account data and billing records are kept for as long as your account is active and as required for legal and accounting obligations. When you delete your account, we delete your account data and stop using your extraction content for any purpose beyond what the law requires us to retain.
4. Sharing and subprocessors
We do not sell your data and we do not share it with third parties for their own marketing. We use a small number of subprocessors strictly to run the service:
- Hosting / infrastructure provider — stores and serves the application and its data.
- Stripe — payment processing for credit purchases.
We may disclose data if legally required (e.g. a valid court order).
5. Your rights
Under the GDPR you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can delete your account at any time, which removes your account data. To exercise any of these rights, email [email protected] and we will respond within 30 days.
6. Security
Passwords are hashed, API keys are secret tokens you can revoke at any time from your dashboard, and traffic is served over HTTPS. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Changes
We may update this policy as the product moves out of alpha. If we make a material change to how extraction content is used, we will update the date above and, where appropriate, notify you by email.