PAILEvidence Runtime
Privacy and retention

Small data surface. Explicit expiry.

01

Public evaluators

Synthetic JSON examples are processed in memory to return a bounded result. The application does not intentionally persist the raw public request body and does not call an LLM for the no-sign-in evidence sample.

02

Public sample and future file workspace

The current public lab provides ten anonymous evaluations over bundled sample records and stores only bounded quota state. Email sign-in and private file upload are not enabled on this deployment. If a protected workspace is activated later, its identity, corpus expiry, deletion, and retention controls will be disclosed before files are accepted.

03

Stored and not stored in Cloudflare D1

D1 stores the email address, tenant ID, hashed session or API-key material, quota counters, corpus identifier and expiry, a SHA-256 query digest, and a bounded result summary. It does not store the raw uploaded file body or raw query text in run history. The private runtime temporarily stores the parsed corpus needed to answer trial queries.

04

Data you must not submit

Do not upload passwords, API keys, payment-card data, government identifiers, patient data, live customer records, confidential employer data, or material you lack permission to process. Redaction is defense in depth, not permission to submit regulated data.

05

Deletion and lifecycle

Corpus deletion is forwarded to the private runtime and the Cloudflare corpus pointer is cleared only after confirmation. Scheduled cleanup retries failed private deletions. The private gateway independently enforces expiry. Users can separately delete individual run summaries or all history.

06

Infrastructure providers

Cloudflare processes requests, authentication metadata, Worker execution, D1 records, and optional Workers AI calls under its service terms. Email delivery uses the configured mail provider. Operational logs may contain normal request metadata even when application storage excludes raw inputs.

07

Questions and requests

For a deletion or privacy request, start the contact form with PRIVACY REQUEST and do not include sensitive data. Contract-specific terms replace this public notice for a dedicated evaluation.