Sanitize.
Your documents stay yours

Privacy notice

Your documents are processed on your device. Purchase checks use a separate online service.

Updated 2026-10-05

Who operates Sanitize

Avalanche Financial Inc · Registered in Delaware, United States

For privacy questions or requests, use the contact on our support page.

Your document session

PDFs, JPG/PNG images, PDF passwords, names and other details you enter, extracted text, page images, redaction selections, and OCR results are processed in your browser. Sanitize does not upload these to its servers, Stripe, an AI service, or a cloud OCR service.

Document work is held in the current browser session. Sanitize does not intentionally save your document or review to local storage, IndexedDB, or its offline cache. Clearing the session or closing the tab discards that app session. This is not a secure-erasure guarantee for browser or operating-system memory. Your original and downloaded files remain wherever you saved them.

What your browser stores

  • Application code, local scanner models, fonts, license notices, these pages, and the published fictional sample are cached for offline use.
  • Your light/dark appearance preference is saved on your device.
  • Purchase access uses an essential secure session cookie, normally valid for 30 days. Signing out of purchases ends that session. Clearing a document session does not sign you out of purchases.
  • You choose where to save exported files and your purchase recovery code. The recovery code is not emailed by Sanitize.

You can remove cached app files, the preference, and cookies through your browser’s site-data controls. This removes offline readiness and may require restoring your purchase.

Purchase information

Checkout opens separately through Stripe Managed Payments and Link. Stripe/Link collects the information entered there, such as payment details, email and billing address, and handles receipts, transaction support, tax calculations and fraud checks. Their privacy notice explains that processing. Sanitize’s app does not receive your complete card number.

Our billing service stores a random purchase-account identifier, a hash of the recovery code, your verified purchase email, named browser activations, hashed email-verification codes, verification attempt counters, session records, checkout and payment references, purchased plans, credit usage, and refund or dispute status. Purchase checks also send an account-specific identifier for the exact source file so all its sections and repeat exports share one unlock. This identifier does not include the PDF, its filename, entered details, or a raw document hash.

Hosting, security and support

Google Firebase Hosting, Cloud Run and Firestore provide the website and billing infrastructure. Normal web and billing requests expose connection information such as IP address, user agent, requested path, timing and response status to the hosting provider. Billing requests do not include document contents. Our billing code avoids logging payment-provider objects, request bodies, cookies, recovery codes and email-verification codes. Resend delivers purchase verification emails and receives the recipient email address, verification code and requested account action. It does not receive your documents or redaction details.

Cloudflare Turnstile checks for automated requests when you create a purchase account or request a verification or recovery email. The check runs on a separate origin and receives browser and connection signals. It cannot access your document or editor. Our server receives a short-lived verification token and validates it with Cloudflare.

The document editor includes no analytics, advertising trackers or third-party scripts. Browser extensions and software on your device operate separately from Sanitize.

If you contact support, we receive the information you choose to send. Use a fictional example or a screenshot with personal information removed. Do not send sensitive documents, full card numbers, passwords or your recovery code.

Retention and your choices

Purchase and source-unlock records are retained to recognize paid access, prevent duplicate credit use, handle refunds or disputes, and meet recordkeeping duties. They are not automatically deleted when you close a tab. Session access expires after 30 days; expired server session records are scheduled for cleanup.

Billing-database backups are retained for 30 days, with a separate point-in-time recovery window of up to seven days. Deleted records can remain in these recovery copies until they expire. If a backup is restored, completed deletion requests must be applied again. Ordinary Cloud Run logs currently use 30-day retention; Google’s required administrative and security audit logs use 400-day retention. These logs and backups do not contain uploaded documents, because Sanitize does not upload them.

You can request access, correction or deletion of information associated with your purchase through support. We may need to verify ownership and may retain records needed for security, legal obligations or unresolved transactions. Deleting records used for paid access may affect purchase recovery; we will explain that before acting. Stripe/Link also handles requests concerning the information it holds.

Hosting and payment providers may process information outside your country. We do not sell document contents or use them to train models. If our data practices change, we will update this notice.