Confyro

Legal · the legal pack

Privacy Policy

DRAFT — UNDER LEGAL REVIEW. NOT YET IN FORCE.

This is working draft v0.1, prepared 18 July 2026 and published for transparency. It is not yet in force; the version that takes effect will carry an effective date. Open points are marked [OWNER DECISION] or [TO BE COMPLETED WITH COUNSEL].

THE SHORT VERSION

  • We process — your email, license key, machine ID, and usage counters
  • We never see — document content or filenames, on any plan
  • Your documents — stay on your server; AI-included plans talk directly to Anthropic
  • This website — no trackers, no analytics, no cookies

Who we are

Confyro is a self-hosted document-verification product, built and run by its founder. Contact for anything in this policy: hello@confyro.com. Final legal entity and postal address: [OWNER DECISION].

What we process, and why

This is the complete list of what our systems handle about you:

  • Your email address — to deliver your license and welcome kit, and to send receipts and other transactional mail.
  • Your license key — to activate your installation and keep its license refreshed.
  • A machine ID — an anonymous random token your installation generates at install time. It is not derived from your hardware; it exists only to bind a license to a machine.
  • Numeric usage counters (AI-included plans only) — pages, checks, token totals, reported model cost. These meter the usage included in your subscription. Counters, never content.

Online activation sends exactly the activation key and the machine ID. Bring-your-own-key (Enterprise) installations send only that license ping — no counters. Air-gapped installations can activate from a signed license file and send nothing at all.

Payments are processed by Stripe; card details go to Stripe, not to us. We see the transaction records a merchant normally sees — never full card numbers.

What we never process

Never your document content. Never your filenames. Never your reference libraries or the contents of your reports. They live on your server, and the product has no feature that sends them to us — there is nothing to opt out of, because the path does not exist.

Where document content actually goes

On AI-included plans, document text travels from your server directly to Anthropic, the AI model provider, under a dedicated per-customer key in an isolated workspace. It never passes through our servers. On Enterprise (bring-your-own-key), content flows under your own provider agreement — or stays entirely on your hardware with local models.

Retention on your own server

An optional retention rule in the product can purge uploaded documents automatically after checking; reports are kept. That setting is entirely yours — we have no access to your server either way, so we could not apply or read it if we wanted to.

This website, and the demo playground

confyro.com sets no cookies, runs no analytics, and loads no third-party trackers. If you email us, use email accordingly — the product exists precisely so you do not have to send anyone your documents.

The hosted demo playground (try.confyro.com), where available, is the one labeled exception to “nothing leaves your server”, because it runs on ours: it is for test documents only, and what you upload there is purged within about one hour.

Sub-processors

These providers help run the parts of Confyro that we operate:

  • Stripe — payments
  • Amazon Web Services (Lightsail) — activation server hosting
  • Cloudflare — DNS and email routing
  • GitHub — website hosting and the private image registry
  • Resend — transactional email
  • Anthropic — AI model provider on AI-included plans

None of them receive your document content from us, because we never have it. The DPA-lite refers to this list.

How long we keep our records

We keep the licensing, metering, and billing records above for as long as they are needed to run your subscription and meet legal obligations. After termination, we delete license and usage records on request — except billing records we are legally required to keep.

Your rights, and how to reach us

Applicable data-protection law may give you rights to access, correct, or delete personal data, and to complain to a supervisory authority [TO BE COMPLETED WITH COUNSEL: the precise legal bases and jurisdictions]. Given how little we hold, the practical route is simple: email hello@confyro.com and we will show you, fix, or delete what we have, subject to the billing-records exception above.