PRIVACY, WITHOUT HAND-WAVING
Your document is not
our business model.
InPlace separates temporary document processing from the account records needed to run a paid product.
What temporary document processing means
PDF files, checkpoints, previews, and outputs exist only in the processing environment while a job is active. They are deleted after the one-time output download, explicit deletion, or the configured expiry window. They are not retained as part of the customer account.
TEMPORARY DOCUMENTS
Files have an expiry
The source PDF, translation checkpoint, field map, and finished output are temporary. Users can delete a job immediately. A background cleanup process removes expired files.
MANAGED CREDENTIALS
No provider setup required
Translation-service credentials are managed securely on the backend. They are never exposed to the browser or stored in customer account and job records.
TRANSLATION TRANSFER
Only mapped text is submitted
Mapped text fields—not the complete PDF file—are submitted to the managed translation provider. Images and vector artwork remain in the document-processing environment.
ACCOUNT RECORDS
Metadata we do retain
Email, salted password hash, subscription status, page/token totals, job state, and timestamps are stored for authentication, billing, support, abuse prevention, and usage reporting. Translated text is not stored in account records.
PROOF, NOT A BADGE
How customers can verify it
- Run the service locally or on-premise.
- Inspect the published source and database schema.
- Audit outbound traffic at the firewall.
- Review provider and retention disclosures.
- Request independent security and deletion audits before enterprise rollout.
PDF ENGINE LICENSE
Commercial launch gate
InPlace uses PyMuPDF. Commercial distribution is disabled until the deployment either complies fully with the AGPL or has an Artifex commercial license. Billing stays locked while the app is in development license mode.