Privacy policy
Last updated: August 2026
This policy describes how RTLDocs handles the documents you send to our extraction API and the account information you give us. It applies to the API, the playground, and the dashboard.
What we collect
Account information. When you sign up, we collect your name and email, and — if you choose to provide them — phone, country, and address. Email is required to send you a one-time login code; the rest is optional and only used to personalize your account.
Documents. Files or URLs you submit to /v1/extract, either directly or through the playground.
Usage data. Request counts, page and token consumption, timestamps, and API response times — used for billing, rate limiting, and the shared daily free/playground token pool.
How documents are processed
Zero-retention is the default on every plan. Uploaded documents are processed in-memory and deleted immediately after extraction — we don't keep a copy, and we don't use your documents to train models unless you explicitly opt in. Extraction is performed by a third-party model provider; document content passes through that provider only for the duration of the request.
Who we share data with
We use a small number of sub-processors to run the service: our model provider (to perform extraction), our cloud hosting provider (to run the API and store account/billing data), and our payment processor, Lemon Squeezy (to handle card payments and act as merchant of record — we never see or store raw card numbers). We don't sell your data, and we don't share documents or account information with anyone else.
Data retention
Account information is retained for as long as your account is active, plus a limited period afterward for legal, tax, and billing record-keeping. Documents themselves are not retained at all under the default zero-retention policy. Usage and billing records are kept for the periods required by applicable tax and accounting law.
Your rights
You can access, correct, or delete your account information at any time from your dashboard, or by reaching out through Contact us. Depending on where you're located, you may have additional rights under laws like the GDPR or CCPA — contact us and we'll handle the request directly.
Security
API traffic is encrypted in transit. Account credentials are never stored as plaintext passwords — login is passwordless, via a one-time code sent to your email. Payment details are handled entirely by Lemon Squeezy and never touch our servers.
Changes to this policy
We'll update this page if our data practices change materially, and update the "Last updated" date above accordingly.
Contact
Questions about this policy or a specific request? Reach us through Contact us.