Privacy Policy
Effective August 3, 2026
The short version: your PDF is processed in memory and never stored — not on disk, not in a database, not in backups. The text extracted from it is never stored either. Before any text is sent to the AI that writes your summary, your names and other chosen terms are masked. Of account numbers, we keep only the last four digits, and only if you register them yourself.
1. What this service is
What's in my docs? ("the service", operated from simple.investments) reads financial PDFs — brokerage statements, bank statements, invoices — and produces an AI summary of what's in them: accounts, balances, movements, tickers, and key facts. This policy explains exactly what happens to your data along the way, because the answer is the product.
2. What we never collect or store
- Your PDF files. Uploads are processed entirely in server memory and discarded the moment processing finishes. They are never written to disk, a database, object storage, or backups.
- The extracted text. The full text pulled from your PDF is held in memory, used to generate your summary, and discarded. It is never persisted anywhere.
- Full account numbers. Only the last four digits of an account number can ever be stored, and only when you add the account to your registry yourself.
- Terms you mask. Masked terms are replaced before text leaves the server for the AI and are never included in summaries.
3. What we do store, and why
- Account details — your email address and name, provided by our sign-in provider (Clerk). Needed to sign you in.
- Document metadata — filename, file size, page count, and upload date for each upload. Powers your document list.
- AI summaries — the generated summary text and its structured data (account names as printed on the statement, balances, changes, movements, tickers, key facts, and the document's as-of date). Powers your dashboard and trend charts.
- Your settings — mask terms you save and your bank account registry (names, nicknames, type, last four digits, currency, notes).
- Billing state — your plan and document-credit balance. Payment card details go directly to Stripe; we never see or store them.
4. How AI processing works
Summaries are generated by DeepSeek's API. What is sent: the extracted text after your saved mask terms and the numbers on screen are masked, never the PDF itself. What comes back is validated, stripped of links, and only then saved. We deliberately minimize what leaves the server — the masking step is not optional and cannot be turned off by us or by you.
5. Subprocessors and providers
- Clerk — authentication. Holds your email, name, and sign-in credentials. Clerk's privacy policy.
- DeepSeek — AI summaries. Receives masked extracted text only, transiently, to generate each summary. DeepSeek's privacy policy.
- Stripe — payments. Receives your card details directly when you pay; we only store a customer reference, your plan, and credit balance. Stripe's privacy policy.
- Mailgun — transactional email. Processes your email address when we send you mail. Mailgun's privacy policy.
- DigitalOcean — hosting and managed Postgres, where the stored data in section 3 lives.
6. Cookies
We use only the cookies Clerk needs to keep you signed in. No analytics cookies, no advertising cookies, no cross-site tracking.
7. Retention and deletion
Stored data lives until you delete it: remove individual documents from your dashboard, or delete your account to erase everything — user record, documents, summaries, mask terms, registry, and billing state. Deletion takes effect immediately in the live database; encrypted backups rotate out within 30 days.
8. Security
Traffic is encrypted in transit (HTTPS) and the database is encrypted at rest. Access to production systems is limited to the operator. Because PDFs and extracted text are never stored, a database breach cannot expose them — by construction, not by policy.
9. Your rights
You can access everything we store about you from within the app (documents, summaries, registry, mask terms), correct it, export it, and delete it. Where GDPR or similar law applies, you additionally have the rights to portability, restriction, and objection — email [email protected] and we will respond within 30 days.
10. Children
The service is not directed at children under 16 and we do not knowingly store their data.
11. Changes
If this policy changes, the effective date above moves and signed-in users are notified by email. Material changes never weaken the guarantees in section 2 — those are the product.
12. Contact
Questions, deletion requests, or concerns: [email protected].