RefractrRefractr logo

Privacy Policy

Last updated 24 August 2026 · Applies to the Refractr alpha.

This policy explains what Refractr collects, why, how long we keep it, and the choices you have. Refractr is operated from the Netherlands and is subject to the EU General Data Protection Regulation (GDPR).

The data controller is Sepp Beld, operating Refractr from the Netherlands. Questions, requests, or anything else: support@refractr.io.

Alpha notice: please read. During the alpha, the full documents you send and the results we return are stored and are used to improve and train the extraction model, in addition to debugging. They are kept for the duration of the alpha round, not deleted on a 30-day cycle. If your documents contain data you cannot allow to be processed or used this way, do not send them during the alpha.

In particular, please do not send identity documents (passports, ID cards, driving licences), medical records, or other special-category personal data during the alpha.

1. What we collect

2. Why we use it

3. How long we keep it

During the alpha, extraction content is kept for the whole round. The documents you send and the results we return are retained for as long as the alpha runs, because they are what we use to improve the model. This is a condition of alpha participation, as set out in the notice at the top of this page.

Training examples derived from that content are kept beyond the alpha, with personal data removed or pseudonymized first. Please note one technical limitation: once an example has been used to train a model, it cannot be removed from that model. Deleting the source document does not reverse the training. If this is a concern for your data, please do not send it during the alpha.

Outside the alpha corpus, routine extraction logs are automatically deleted or anonymized 30 days after the request. Account data and billing records are kept for as long as your account is active and as required for legal and accounting obligations. When you delete your account we delete your account data, and we stop using your extraction content for any purpose beyond what the law requires us to retain and what is already embedded in a trained model.

4. Sharing and subprocessors

We do not sell your data and we do not share it with third parties for their own marketing. We use a small number of subprocessors strictly to run the service:

Where your documents actually go. The application, the database, and the extraction model all run on our own hardware in the Netherlands. Your documents and results are not sent to a third-party cloud, and they are not sent to OpenAI, Anthropic, or any other model provider. The extraction model is ours and it runs on our machines. Stripe is the only external subprocessor that touches your data, and it only handles payments, never document content.

We may disclose data if legally required (e.g. a valid court order).

5. Your rights

Under the GDPR you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can delete your account at any time from your dashboard, under Profile, which removes your account data and revokes your API keys. To exercise any of the other rights, email support@refractr.io and we will respond within 30 days.

You also have the right to lodge a complaint with a data protection supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens. You may also complain to the supervisory authority in your own EU country of residence.

6. Security

Passwords are hashed, API keys are secret tokens you can revoke at any time from your dashboard, and traffic is served over HTTPS. No system is perfectly secure, but we take reasonable measures to protect your data.

7. Changes

We may update this policy as the product moves out of alpha. If we make a material change to how extraction content is used, we will update the date above and, where appropriate, notify you by email.

← Back to Refractr  ·  Terms of Service