Privacy policy
What PDFAA collects when it audits your documents, how long we keep it, and where it goes. We do not sell your data or our logs, to anyone, ever.
Effective August 18, 2026
1. Who we are
PDFAA is operated by FivePaths, LLC. This policy covers the pdfaa.report website, the PDFAA API, the audit portal at audit.pdfaa.report, and document submission by email. Reach us at info@pdfaa.report.
2. What we collect
Documents you submit
The service exists to analyze the PDFs you send it, so we store the documents themselves and what the audit derives from them: images of each page, the document's extracted text and tag structure, audit results, repaired versions, and accessible alternate versions. Document properties travel with the file: the original filename, size, page count, and the PDF's own metadata (title, author, and the software that produced it).
Contact and account details
We record who submitted each job: the email address on your portal login or API submission, and for documents sent by email, the sender address and subject line. API submissions also carry the website the document belongs to and the credentials you supply for model access. We identify portal and admin users through Cloudflare Access sign-in (a one-time code sent to your email); we never see or store passwords.
Service logs
The system keeps operational logs: job progress events and application messages, which can include submitter email addresses and filenames. Our application code does not collect IP addresses or browser user agents. Cloudflare, which hosts the service, processes request data at its network edge as any host does.
What we don't collect
The public site sets no cookies and runs no analytics, trackers, or third-party scripts. We process no payment card or bank details; billing happens by ordinary invoice.
3. AI evaluation of your documents
PDFAA uses artificial intelligence to evaluate PDFs. To produce an audit, we send the document, images of its pages, and its extracted text and structure to Google's Gemini models, routed through Cloudflare's AI Gateway. Google's copies are temporary: files uploaded for model processing expire on Google's side within 48 hours, and we additionally delete them when the job finishes. The model's verdicts become the audit report; the terms of use describe the limits of AI evaluation, and no output leaves the AI pipeline as a guarantee of accessibility.
4. How long we keep things
- Model-side copies at Google: deleted when the job finishes, and expire within 48 hours regardless.
- Page images rendered for analysis: deleted from storage after 7 days.
- Download links for repaired documents and alternate versions: expire after 7 days.
- API credentials you supply for model access: removed from the job record once your results are delivered, and kept only while a failed delivery might still be retried.
- Operational logs and job events: purged automatically after 90 days.
- Documents, audit results, and reports: retained while your engagement is active, so that re-audits can be compared against earlier runs. They are deleted when you ask us to delete them (see section 5). Reports we email to you live in your own mailbox under your control.
5. Deleting your data
Email info@pdfaa.report and we will delete your documents, results, and job records from our storage. Log entries age out on the 90-day schedule above.
6. Where your data goes, and where it doesn't
We do not sell your documents, your personal information, or our logs. We do not share them with advertisers or data brokers. Data leaves our systems only to:
- Cloudflare, Inc., which hosts the entire service: compute, document storage, the database, sign-in, email delivery, and the AI Gateway.
- Google LLC, whose Gemini models perform the AI evaluation described in section 3.
- You: results are delivered to the callback endpoint or email address your submission names.
- Authorities, if the law requires it. We have never been required to.
FivePaths operators can view jobs and reports in an internal console to run and support the service; operator actions there are themselves logged.
7. Security
Traffic is encrypted in transit. The portal and the internal console sit behind Cloudflare Access sign-in, and report and download links for API-submitted jobs are signed and expire. Documents are stored in Cloudflare R2 and referenced by content hash.
8. Changes
Material changes to this policy will be posted here with a new effective date.
9. Contact
Questions, deletion requests, or anything else about your data: info@pdfaa.report.