Data handling
Policy documents you upload
- Uploaded PDFs are stored securely in object storage scoped to your workspace.
- Rule extraction sends document text to Anthropic using the key configured for your workspace. There is no platform-key fallback. The key determines which provider account receives the text; a key configured by PathReader staff does not establish that you own that account. Review its recorded provenance in Settings → AI provider keys.
- Extraction requires a configured key. Missing or invalid configuration is reported on the document.
- Documents and rules are workspace-scoped. Authorized PathReader staff can access a workspace through support controls; support actions are audited.
Action checks
- Structured requests are evaluated by deterministic policy checks. API Check has no LLM fallback, and plain-text interpretation is unavailable. Configuring a document-extraction key does not enable text interpretation for action checks.
- API check records contain the decision, rule references, request metadata, and a request hash. Full request payloads are excluded from these records; retained free-text metadata is screened for detected sensitive values.
Retention & deletion
Workspace owners configure retention for API check records, audit records, documents, and connected-machine activity in Settings → Data retention. A class without a configured retention window is kept indefinitely. The page shows the configured windows and the latest cleanup status.
You can request erasure of your workspace data or of an individual user's personal data at any time by contacting your PathReader representative. On an erasure request we remove the workspace's documents, policies, evaluation history, API keys, and stored files, and we scrub personal data from a removed user's records. Erasure requests are fulfilled by PathReader staff (there is no self-serve hard delete) and recorded for our own audit trail.
Service providers
Service providers support hosting, storage, and transactional email. AI processing uses the provider account associated with your workspace key. Refer to your agreement for the applicable provider and data-processing terms. We do not sell personal data or use your content to train AI models.
Your rights & contact
Depending on your jurisdiction you may have rights to access, correct, delete, or port your personal data. For data we process on a customer's behalf, we assist that customer in responding to such requests.
Privacy questions: [email protected] · Security reports: [email protected]
Questions about data handling? Help or contact your PathReader representative.