Privacy policy
Your documents are processed to produce your result and then deleted on a schedule we enforce in code, not on request. Uploads go after 2 hours; results after 24 hours.
Last updated . Applies to frisket.robomiri.com, operated by Robomiri.
Who we are
Robomiri operates frisket.robomiri.com and is the data controller for the account and billing data described below. For the content of the documents you upload we act as a processor on your instructions — see the data processing agreement.
What we collect
Documents you upload
The file itself, and whatever the job needs to produce from it: extracted text, numbers, structure and the result file. We do not read your documents for any purpose other than running the job you asked for. We do not use them to train models, and we do not sell or share them.
Account data
Your email address, and the sign-in tokens and session records that keep you logged in. We use email sign-in links rather than passwords, so we never hold a password of yours.
Billing data
Plan, subscription state, invoices and the last four digits of your card. Card numbers are handled by our payment processor and never reach our servers.
Technical logs
One line per request: timestamp, method, path, status, duration and a request ID. We do not store your IP address. Rate limiting and session counting hash it with a salt that is random per process and — for analytics — rotates daily, so the address itself is never written down and the hash cannot be reversed or linked from one day to the next. Logs do not contain document content.
Why we are allowed to process it
- Performing our contract with you — running the job, delivering the result, taking payment, supporting you when something fails.
- Legitimate interests — keeping the service up, preventing abuse, and keeping the security and billing records a business has to keep. We have balanced these against your interests; the mitigation is that none of it needs document content.
- Legal obligation — retaining invoices and tax records for the period the law requires.
How long we keep it
Deletion is a scheduled job, not a promise to act on request. These windows are the ones the platform enforces; the same numbers configure the deletion sweep.
| What | Deleted after | Why that long |
|---|---|---|
| Files you upload | 2 hours | A job has to be able to read the file while it runs, and you have to be able to retry a failed conversion without re-uploading. Neither needs longer. |
| Converted files and generated documents | 24 hours | Long enough that a download link still works the next morning, short enough that we are not a copy of your records. |
| Verification reports and their reference numbers | 30 days | A report is evidence: whoever you sent it to must be able to check it against the reference number for a reasonable period. Reports contain the check result and the document hash, not the document. |
Account records are kept while your account exists and for 30 days after you delete it, so an accidental deletion can be undone. Invoices are kept for the statutory period, which is longer than anything else on this page and is not something we can shorten for you. Backups are encrypted, rotated on a fixed schedule, and expire within 30 days; a document deleted from live storage can survive in a backup until that backup expires.
Who else processes it
We use a small number of subprocessors. Each is bound by a written contract with terms at least as protective as this policy, and the ones that can reach document content are marked as such.
| Subprocessor | What they do for us | Where | Can they see document content? |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database, and object storage | Germany (EU) | Yes |
| Stripe Payments Europe, Ltd. | Payment processing and billing records | Ireland (EU), with transfers to the United States under Stripe’s SCCs | No |
| Anthropic PBC | Model inference for extraction steps that need it | United States, under standard contractual clauses | Yes |
Where a subprocessor is outside the UK or EEA, the transfer relies on standard contractual clauses. We publish changes to this list on this page before a new subprocessor starts handling your data.
Cookies and analytics
One cookie, and it is the session cookie that keeps you signed in. We do not use advertising cookies and we do not embed third-party trackers. Usage analytics are aggregate and cookie-free: page, referrer class, and whether a step in the funnel completed. No cross-site profile is built and nothing is sold.
Your rights
You can ask us for a copy of your data, correct it, delete it, restrict or object to processing, or take it elsewhere in a portable format. Email privacy@robomiri.com; we reply within 30 days. If you are unhappy with the answer you can complain to your data protection authority — in the UK, the Information Commissioner’s Office.
Security
Traffic is encrypted in transit. Uploads and results are stored in object storage in the EU, encrypted at rest, and are reachable only through short-lived signed links tied to your account. Access to production is limited to the people who operate it, and every request carries a request ID so an incident can be traced.
If a breach affects your data and is likely to result in a risk to you, we will tell you and the relevant authority within the time the law allows.
Changes
Substantive changes are announced here with a new date at the top of the page, and by email if they affect how your documents are handled.