Privacy Policy
Sensitive Data De-identification Service
Data Processing Principles
This service is designed with privacy as a core architectural principle. All data processing follows these guarantees:
- Zero server-side data retention — No uploaded text, documents, images, or PDFs are stored on the server. All processing occurs entirely in memory and data is discarded immediately after the response is returned. Your input may remain visible in the browser until you close the tab or navigate away — this is standard browser behaviour and no data is sent back to the server.
- Internal processing only — All entity detection and redaction happens locally within the deployment environment. No document content is transmitted to external services.
- No external API calls — The service makes no outbound calls with your data. ML model weights are baked into the container image at build time; the runtime environment is configured in offline mode (
HF_HUB_OFFLINE=1) to prevent any outbound model downloads.
What Data Is Processed
| Data Category | Purpose | Retention |
|---|---|---|
| Uploaded content (text, documents, images) | Entity detection and de-identification | Server: none — discarded after response. Browser: until tab is closed. |
| Authentication claims (username, user ID) | Session management and access control | Session duration only (JWT cookie) |
| Request metadata (method, path, status, duration) | Operational monitoring and diagnostics | Log rotation policy (no PII logged) |
| Usage counters (username, input type, mode) | Prometheus metrics for capacity planning | In-memory only — reset on restart |
Reversible Mode & Encryption Keys
When using reversible de-identification, a unique encryption key is generated per request using cryptographically secure random generation (Fernet / AES-128-CBC + HMAC-SHA256). The key is delivered to you in the downloaded key file and is never stored on the server. Only you possess the key needed to restore the original content. If the key file is lost, the original data cannot be recovered.
Technical Safeguards
- No database — The service has no database, no disk cache, and no temporary file storage.
- In-memory processing — All file handling uses in-memory byte streams (BytesIO) that are garbage-collected after each request.
- Stateless sessions — Authentication uses signed JWT cookies with no server-side session store.
- Security headers — OWASP-recommended headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) are enforced on every response.
- Sanitized error responses — Error messages returned to clients never contain internal details or user data fragments.
Your Rights (GDPR)
Assessment in progress: this service has not yet been formally assessed by the Compliance team for GDPR conformity. The assessment is ongoing, and the information below reflects the service's intended design rather than a validated compliance position.
Under the General Data Protection Regulation, you have the right to:
- Access — Request information about what personal data is processed.
- Erasure — Since no data is retained, this right is satisfied by design.
- Portability — All output is returned directly to you in the response.
- Object — You may stop using the service at any time.
Last updated: September 2026
