Your form stays private.
The free workflow reads PDFs and spreadsheets on your device. A draft is stored in browser IndexedDB; browser cleanup or storage eviction can remove it. Mapping backups omit customer rows. Downloaded files remain on your device.
For supported native forms, AI requires separate consent to send selected page images, headers, up to three selected sample rows and instructions to Pondir, OpenRouter and Azure. Requests require zero-data-retention routing, no training and no provider fallback. OpenRouter prompt storage and observability broadcasting were verified off. This is not a guarantee of regional residency or regulatory compliance. No automatic AI sending on upload.
Pro cloud retention removes temporary run inputs after 7 days. Saved templates and completed outputs remain available for 90 days after the verified paid period ends, unless you delete them sooner. Deletion immediately withdraws product downloads; reference-aware cleanup removes stored objects. Private cloud processing uses this product’s Railway database and object storage. Billing uses Stripe and authentication uses Clerk. Billing identifiers, entitlement history and webhook audit records are retained separately for accounting, disputes and security; deleting a PDF run does not delete these records. Contact support to request account-data review or deletion, subject to applicable recordkeeping obligations.
With your consent, Google Analytics measures public page visits and bounded tool events using browser identifiers. Uploaded contents, filenames, spreadsheet values and private account URLs are excluded. Verified purchases may use an opaque transaction fingerprint. Decline or withdraw analytics through Analytics preferences in the footer. Contact support@pondir.com for FillBatch privacy questions.