InPlace

PRIVACY, WITHOUT HAND-WAVING

Your document is not
our business model.

InPlace separates temporary document processing from the account records needed to run a paid product.

What temporary document processing means

PDF files, checkpoints, previews, and outputs exist only in the processing environment while a job is active. They are deleted after the one-time output download, explicit deletion, or the configured expiry window. They are not retained as part of the customer account.

TEMPORARY DOCUMENTS

Files have an expiry

The source PDF, translation checkpoint, field map, and finished output are temporary. Users can delete a job immediately. A background cleanup process removes expired files.

MANAGED CREDENTIALS

No provider setup required

Translation-service credentials are managed securely on the backend. They are never exposed to the browser or stored in customer account and job records.

TRANSLATION TRANSFER

Only mapped text is submitted

Mapped text fields—not the complete PDF file—are submitted to the managed translation provider. Images and vector artwork remain in the document-processing environment.

ACCOUNT RECORDS

Metadata we do retain

Email, salted password hash, subscription status, page/token totals, job state, and timestamps are stored for authentication, billing, support, abuse prevention, and usage reporting. Translated text is not stored in account records.

PROOF, NOT A BADGE

How customers can verify it

  • Run the service locally or on-premise.
  • Inspect the published source and database schema.
  • Audit outbound traffic at the firewall.
  • Review provider and retention disclosures.
  • Request independent security and deletion audits before enterprise rollout.

PDF ENGINE LICENSE

Commercial launch gate

InPlace uses PyMuPDF. Commercial distribution is disabled until the deployment either complies fully with the AGPL or has an Artifex commercial license. Billing stays locked while the app is in development license mode.