Legal
Privacy Policy
What Xorah handles, where it is processed, who else can see it, and how long it is kept.
Effective
7 August 2026
Draft. These terms have not yet been reviewed by counsel and are published for comment. They do not replace the agreement in your pilot contract, which governs where the two differ.
The short version: your documents stay in an environment used for your organization alone, the model that reads them runs inside that same boundary, nothing is used to train anything, and nothing is sold. The rest of this page is the detail behind those four sentences.
1. Scope
This policy covers the Xorah quality-document review service and this website, both provided by Xorah. It explains what we handle, why, where it is processed, who else is involved, how long it is kept, and what you can ask us to do about it. Terms defined in the Terms of Service have the same meaning here.
2. Our role: controller and processor
The distinction matters, because different rules follow from it.
- For customer documents and reports we act as a processor — we handle them on your organization's instructions, for the purposes it sets, under your agreement with us. Your organization is the controller. If you are an individual whose details appear in a document (an inspector named on a certificate, a signature block), your organization decides what happens to that document, and we will refer your request to it.
- For account and website data we act as a controller — the details of who has an account, how the service is used, and who contacted us.
3. This website sets no cookies and runs no trackers
These marketing pages carry no analytics, no advertising, no tracking pixels, no third-party scripts and no cookies. Every page is a single self-contained file that makes zero external requests — the fonts and styles are embedded in it, which you can verify by opening your browser's network tab.
One thing we will not overstate: like any web server, the host serving these pages writes an access log, which records your IP address, the page requested, and your browser's user-agent string. We use those logs only to keep the site available and secure, and they are deleted within 30 days. We do not build a profile from them and we do not connect them to anything else.
4. What we handle
- Documents you upload. Quality documents, mill certificates, dimensional reports, hardness surveys, NDE results, drawings, specifications and purchase orders, and the requirement files you supply with them.
- Reports produced from them. The graded output, including each characteristic's requirement, measured value, status, confidence score and reasoning.
- Account data. Name, work email address, organization, and role of each user.
- Audit records. Who uploaded what, who reviewed it, what they decided, and when. An audit trail is the point of the product, so this is retained deliberately and cannot be silently edited.
- Operational logs. Timestamps, which document was processed, performance data, and errors — kept to run, secure and debug the service.
- Correspondence. What you send us by email or through support.
Your documents may themselves contain personal data. We handle it as part of the document, under the same controls, and we do not extract it for any separate purpose.
5. Why we handle it
To provide the service you asked for — reading documents, grading characteristics, producing reports and their audit trail; to authenticate users and secure the service; to support you when you contact us; to bill you; and to meet our legal obligations. Where the law requires a lawful basis, ours is the performance of our contract with your organization, our legitimate interest in securing and improving the service, and compliance with law.
6. Where it is processed
In one place: Amazon Web Services, Amazon Web Services, US East (N. Virginia), in an environment used for your organization and no one else's. Your documents are not stored in a pool shared with other customers, and no other customer's credentials can reach them.
Documents are encrypted in transit (TLS 1.2 or better) and at rest (AES-256). Access requires authentication, is granted on a least-privilege basis, and is logged.
7. Models, and what they are not allowed to do
Reading a scanned certificate is a model call — a page image has to be turned into values before anything can be graded. Three things about that:
- It runs inside your own boundary. Inference happens through Amazon Bedrock in the same AWS account, region and network boundary your documents already sit in. No part of a document is sent to a third-party model endpoint, and no document leaves that boundary in normal operation.
- Nothing is retained by the model. Inference is configured for zero retention: the page is read and the values come back, and neither the prompt nor the response is stored by the model service. We do not enable model invocation logging, which is the setting that would write page contents into a log.
- The model only ever reads. Grading is deterministic code that never sees the model's confidence or opinion — it compares a value to a limit. That is a design decision, but it is also a privacy one: the judgment that matters is not made by a system that could have learned it from someone else's documents.
We do not train, fine-tune or evaluate any model on your documents, reports or account data, and we do not permit any vendor to do so through us. We do not do it on anonymized or aggregated copies either. This applies to every account by default and we will not change it without your written agreement.
8. Sub-processors
We use one, and name it:
| Sub-processor | What it does | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, authentication, and in-account model inference (Bedrock) | United States |
We will give you notice before adding a sub-processor with access to customer documents, and you may object. We remain responsible to you for what our sub-processors do.
9. What we never do
- We do not sell your personal data or your documents, and we do not share them for advertising or cross-context behavioral advertising.
- We do not put your documents on a shared platform beside another company's work.
- We do not use one customer's documents, specifications or requirement encodings to serve another.
- We do not disclose customer data except where you instruct us to, or where the law compels it — and where we are lawfully able, we will tell you first.
10. Retention and deletion
Customer documents, reports and audit records are kept while your account is active, because a quality record that vanishes before the audit that asks for it is worth little. You can delete individual documents at any time.
On termination you have 30 days to export. After that we delete customer data from live systems within 30 days, and from backups as those expire on their normal cycle. Operational logs are kept for up to 12 months for security and debugging. Account records needed for tax or accounting are kept as long as the law requires. We will confirm deletion in writing on request.
If your records-retention policy needs a different period — longer or shorter — ask, and we will agree it in writing.
11. Security
Single-tenant environments; authentication in front of everything; TLS in transit and AES-256 at rest; least-privilege access with managed secrets; a full, non-repudiable audit trail. Access by our own personnel is limited to those who need it to operate the service or to support you, and is logged. We have no certification to claim yet — no SOC 2, no ISO 27001 — and we would rather say so than imply otherwise.
12. If something goes wrong
If we become aware of a personal-data breach or of unauthorized access to customer documents, we will notify your designated contact without undue delay and in any event within 72 hours of becoming aware — not within 72 hours of finishing our investigation. We will tell you what we know, what we are doing, and what we recommend you do, and we will keep telling you as we learn more. We will assist you with your own notification obligations.
You can report a suspected vulnerability to legal@xorah.net. We will not pursue a researcher who reports one in good faith and gives us reasonable time to fix it.
13. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent where we relied on it. Write to legal@xorah.net. We will acknowledge within 10 business days and respond within 30 days, or sooner where the law requires it, and we may need to verify your identity first. We will not discriminate against you for exercising a right.
Two honest limits. Where we hold the data as a processor for your employer, we will refer the request to them and act on their instructions. And where data forms part of an audit trail that must be retained, deleting it may not be possible while the underlying record must be kept — we will say so plainly rather than quietly declining.
14. California residents
Under the CCPA/CPRA you may request the categories and specific pieces of personal information we have collected, its sources, our purposes, and the categories of third parties it was disclosed to; request deletion or correction; and appoint an authorized agent. We do not sell or share personal information, and we have not in the preceding twelve months. We do not offer financial incentives for personal information.
The categories we collect are identifiers (name, work email), professional or employment information (employer, role), and internet or network activity limited to service and access logs. Each is retained for the periods in clause 10. We do not collect sensitive personal information as the CPRA defines it, so the right to limit its use has nothing to apply to — save that a document you upload may incidentally contain such information, which we handle only as part of that document.
15. International transfers
The service is hosted in the United States and data is processed there. If you are in the EEA, UK or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses, with the UK Addendum or Swiss amendments as applicable, available in our DPA, together with the supplementary measures described in clauses 6 and 11. If you require processing in another region, ask before you upload anything — it is a deployment decision, and the answer is not automatically yes.
16. Cookies and Do Not Track
The application sets one cookie, to keep you signed in — a random token, HttpOnly, Secure and SameSite=Lax, revocable on our side and expiring 12 hours after sign-in. That is all. There are no advertising or analytics cookies anywhere on this site or in the application, and no consent banner, because there is nothing to consent to. The full detail, including what we deliberately do not use, is in the Cookie Policy. Since we do not track you across sites, a browser Do Not Track signal has nothing to change here, and we do not respond to one.
17. Automated processing
The service makes automated assessments about parts and documents, not about people. It grades a measured value against a requirement; it does not profile users, score individuals, or make any decision producing legal or similarly significant effects concerning a person. Every graded item is a recommendation a human reviewer confirms, so there is no solely automated decision-making of the kind Article 22 GDPR addresses.
18. Children
The service is a business tool, is not directed to children, and we do not knowingly collect personal data from anyone under 16. If we learn we have, we will delete it.
19. Changes
We will post any update here and change the effective date above, and keep the previous version available on request. Where a change materially affects how we handle your data we will give notice at least 30 days before it takes effect. We will not apply a materially less protective version to data already collected without your agreement.
20. Contact, and a DPA
Questions, or a request under clause 13: legal@xorah.net. A Data Processing Addendum incorporating the Standard Contractual Clauses is available on request — ask and we will send it, whatever the size of your account. See also the Terms of Service.