← Medical PDF Solutions

Privacy Policy

Last updated: June 25, 2026
Short version: we collect your email to run your account, process your uploaded files only to convert them, and delete those files automatically. We never sell your data. Please don’t upload protected health information (PHI) — the Service isn’t built to hold it.

This Policy explains what we collect, why, and your choices when you use Medical PDF Solutions (the “Service”).

1. Information we collect

2. How we use it

To provide the conversion, run your account and credits, process payments, prevent abuse, and improve detection quality. Layout-only data (the geometry of a form, never its filled-in contents) may be retained to recognize the same blank form in future and improve accuracy.

3. Service providers (subprocessors)

ProviderPurpose
StripePayment processing
SupabaseAuthentication & account database
RailwayApplication hosting
CloudflareNetwork / content delivery
Anthropic / Microsoft AzureAI form-field detection (AI tier only)

When you use the AI tier, the rendered page image is sent to the AI provider solely to detect form fields. Do not use the AI tier on files containing PHI.

4. Retention

Uploaded files and generated PDFs are automatically deleted after a short window (free jobs ~3 days; paid jobs are kept ~30 days so you can re-download what you paid for). Your account, email, and billing ledger are retained while your account is active and as needed for legal/accounting purposes.

5. We don’t sell your data

We do not sell or rent personal information, and we don’t use your uploaded file contents for advertising.

6. Security

We use reputable providers and reasonable safeguards. No system is perfectly secure, and because the Service is not HIPAA-accredited, you should not upload PHI.

7. Your choices and rights

You can request access to or deletion of your account data by contacting us. Signing out and letting your jobs expire removes uploaded files automatically. Depending on where you live, you may have additional rights (e.g., GDPR/CCPA); contact us to exercise them.

8. Cookies and local storage

We use minimal browser storage to keep you signed in and to restore your in-progress conversion after the sign-in redirect. We don’t use third-party advertising cookies.

9. Children

The Service is not directed to children under 18.

10. Changes & contact

We may update this Policy; the “Last updated” date reflects the latest version. Questions or requests? Reach us via the contact link on our home page.