Privacy policy
Last updated 2026-07-16.
This page describes what txtfetch processes when you use the API or the website, who controls that data, and how long it's kept. It's written to be read, not just filed — if anything here is unclear, ask us via /contact.
What we process
Document content. When you send a file or a URL to the extraction API, txtfetch reads the bytes into memory, runs them through the extraction engine, and returns the resulting text. That content is processed in memory and discarded — we do not persist document content to any datastore. We are in the process of removing a request-logging path that could otherwise capture raw request data in operational logs (see /security for status); until that lands, treat "not retained" as our enforced target rather than a fully audited guarantee.
Contact-form submissions. If you submit /contact, we process the name, email address, and message you provide, and relay it by email via AWS SES. We keep these messages to answer you and to operate support — not for marketing.
Site analytics. The marketing site uses cookieless, aggregate analytics (Plausible) to see which pages get traffic. No cookies are set, no individual visitors are identified, and no personal data is collected — so there's no cookie or consent banner.
Controller and processor roles
For document content sent through the API, you (or your organization) are the data controller and txtfetch is the data processor acting on your instructions. For contact-form submissions and site analytics, txtfetch is the controller. See the Data Processing Addendum for the contractual detail behind the processor relationship.
Retention
- Document content: not retained. Processed in memory for the duration of a single request and discarded.
- Contact-form messages: retained for as long as needed to respond and provide support, then deleted.
- Analytics: aggregate counts only; no per-visitor records to retain or delete.
Sub-processors
txtfetch runs on a small set of infrastructure providers — AWS (compute, CDN, storage, email delivery) and Plausible (analytics). The full list, with purpose, data handled, and region, is on the sub-processors page.
Your rights and requests
To exercise a data-subject request (access, deletion, correction) for information we hold as controller, or to report a security concern, reach us through /contact — there's no separate email address to look up. We'll acknowledge requests within a reasonable time and follow up with next steps.
Changes to this policy
We'll update the "last updated" date above whenever this policy changes materially, and note significant changes here rather than silently editing history.