Privacy.ly Filter Privacy Notice

Product privacy

Privacy Notice

This notice explains how Privacy.ly Filter Free Flex processes personal data when you upload, paste, analyze, review, and download reduced copies or clearance packets, and when you join the Priority waitlist.

Last updated: 22 July 2026

Processed

Documents you submit, plus safe workflow metadata such as type, counts, status, timing, and provider mode.

Stored

Metadata-only operational records may be retained. A consented Priority waitlist entry stores your email and workflow interest. Raw document content and generated artifacts are designed not to be stored by the app.

Not Guaranteed

The service assists reduction and review. It does not guarantee anonymization, GDPR compliance, legal compliance, or complete removal of every trace.

Retention

App-managed artifact retention TTL is zero seconds. Infrastructure, security, and operational records can remain when needed to run and protect the service.

Controller

Magic Crystal Limited, 28 Wellington St, Central, Hong Kong.

Privacy contact: support@privacy.ly.

Scope

This notice covers Free Flex and the Priority waitlist at privacy.ly, www.privacy.ly, and the compatibility hostname filter.privacy.ly. It does not cover a separate enterprise deployment or staging environment.

Data We Process

Free Flex processes the document content you choose to submit, including text, HTML email content, and selectable PDF text and layout data. Your browser may display the local filename for your own context, but API responses and clearance packets are designed to omit uploaded source filenames.

Operational metadata can include request timing, queue/provider/post-processing durations, service tier, workflow type, content type, coarse document profile, provider mode, finding counts, PDF verification counts, retry counts, cold-start indicators, success or error categories, and safe request identifiers. Product-use events can include a random identifier limited to the current browser tab and events such as document added, processing started, result received, review completed, output downloaded, or Priority early-access interest. They do not include the document, filename, matched values, or output.

If you join the Priority waitlist, we store your normalized email address, a one-way email hash used to prevent duplicate entries, your selected document-workflow interest, the form source, consent version and timestamp, status, and expiry date. We do not ask for a name, organization, document, or free-text message.

Operational records must not include raw source text, PDF bytes, matched values, uploaded filenames, generated artifacts, provider tokens, database URLs, Stripe secrets, auth secrets, or bearer tokens.

Why We Process It

We process submitted content to provide the redaction-assistance workflow you request: detecting likely private data, allowing human review, generating reduced copies, and verifying selectable PDF redactions.

We process limited operational and product-use metadata to operate, secure, troubleshoot, measure reliability and completion rates, understand which supported workflows are useful, prevent abuse, and maintain evidence that Free Flex is running in the stated posture.

We process Priority waitlist details only to measure demand, plan capacity, and contact you about Priority early access.

Legal Bases

For EU/EEA data protection purposes, processing you initiate through Free Flex is based on providing the requested service or taking steps at your request before a possible service relationship. Security, abuse prevention, reliability, and non-raw operational measurement rely on legitimate interests. Priority waitlist contact is based on the consent you provide with the form. Where a legal obligation requires processing or disclosure, that obligation is the legal basis.

Subprocessors and Recipients

Free Flex and the Priority waitlist are hosted on Cloudflare Workers and Cloudflare Containers, with waitlist records stored in the service database. Live detection currently uses Replicate through server-side provider access. Resend handles Priority waitlist notification emails, and we may share limited information with professional advisers or authorities where required.

We do not sell personal data and do not use submitted documents for advertising.

Retention

Free Flex is configured with app-managed persistent artifact retention TTL of zero seconds. Submitted source content and generated artifacts are held only in transient processing memory while a queued request runs and while the browser retrieves its result; they are not written by the app to job metadata or persistent document/artifact storage.

Metadata-only operational records, infrastructure logs, and security records may be retained for service operation, debugging, abuse prevention, and legal compliance. These records are designed to exclude raw document content, matched values, filenames, and artifacts.

Priority waitlist records expire after 12 months unless you renew your interest. An expired entry is removed when the waitlist store is next initialized or updated. You can request earlier deletion at any time.

International Transfers

Cloud providers, model providers, and email providers may process data outside the EEA. Where required, transfers should rely on an adequacy decision, standard contractual clauses, or another valid transfer mechanism. Contact us if you need information about relevant safeguards.

Your Choices and Rights

Do not submit a document unless you have authority to process it through the service. You may withdraw Priority contact consent at any time and request deletion of your waitlist entry. You may also request access, rectification, erasure, restriction, portability, or objection where applicable, and complain to a competent data protection authority.

Limitations

Privacy.ly Filter provides redaction assistance. It does not guarantee anonymization, GDPR compliance, legal compliance, or complete removal of every personal-data trace. Human review is required before relying on any output. PDF support is review-required; coordinate-backed OCR is attempted for scanned or image-based PDFs when safe, residual traces can remain in unsupported, malformed, image-only, encrypted, or unusual-layout PDFs, and PDFs fail closed when OCR cannot provide mapped redaction coordinates.

Automated Decisions

The service flags likely private data for review. It does not make decisions that produce legal or similarly significant effects about individuals.

Changes

We may update this notice when the product, providers, deployment posture, retention model, or legal requirements change. The latest version is published on this page.