What we do with your documents

Current as of 22 September 2026.

This describes what actually happens to a document when you give it to ProcurePro. It was written by reading the code, not from a template, so it says some things a privacy notice usually does not: where the behaviour is limited, and where it is manual.

The short version. Your documents are stored for your workspace alone. Their text is sent to a model provider so it can be read, and to nobody else. We do not train any model on them. You can remove a document, which also deletes the text we extracted from it. There is no automatic deletion, so nothing disappears unless you or we delete it.

What we store

WhatWhy it exists
The file you uploaded, as you gave it to usSo a figure can be traced back to the page it came from, and so you can get it back.
Its text, and that text split into passagesSo it can be searched and quoted. Each passage carries a vector so similar wording can be found.
The fields read out of it, each with the exact sentence it came from and where in the document that sentence sitsSo every number on a screen can be checked against the source. A quote that is not in the document is rejected rather than shown.
What we worked out from it: contracts, quotes, spend lines, deadlines, savingsThis is the product.
A log of every action and every data accessSo you can answer who did what. The log is append-only and hash-chained, so an entry cannot be altered or removed without it being detectable.
The people in your workspace: name, work email, roleTo sign you in and to record who approved what.

Who can reach it

Only people invited to your workspace. Isolation is enforced in the database rather than in application code: every table carries the workspace it belongs to and refuses to return a row outside the current one. A query that forgets to filter returns nothing rather than returning somebody else’s contracts.

Prices, spend and savings sit behind a second, separate permission. A person in your workspace without it sees the document and not the money, and the product tells them a figure was withheld rather than showing a blank where a number should be.

We can reach your data, and we say so plainly because pretending otherwise would be false. Today that access is through operational tooling by a small number of people. The controls that will make it properly accountable, a separate back office, support access you grant rather than we assume, and every one of our reads written into a log you can see, are being built and are not finished. The current state is here.

What leaves our systems

Reading a contract means sending its text to a language model. That is the one place your document content leaves our infrastructure, and it goes to a model provider under that provider’s API terms.

  • We do not train any model on your documents, and nothing you give us is used to improve a model for anybody else.
  • The passage vectors are computed on our own servers, by a model that runs inside our infrastructure, so search does not send your text anywhere.
  • Nothing is sent to a supplier without a person approving it. Drafts are drafts. A message leaves only when somebody in your workspace reads it and says so.
  • No analytics tracker, no advertising pixel, no third-party script runs on this site or in the product.

Who we rely on

KindWhat they see
Language-model providerThe text of documents being read, and the drafts being written.
Cloud hosting and object storageThe stored files and the database, at rest.
Email deliveryMessages we send on your behalf, and their recipients.

This list is versioned and changes when a provider changes. If you are evaluating us and need the current named list with their locations, ask and you will get it in writing.

How long we keep it

Until you remove it. There is no automatic expiry: nothing in the product deletes anything on a schedule. That is a real limitation rather than a policy choice, and it is described the same way inside the product on the retention page so the two cannot drift apart.

The one exception is this website’s own counters, described below, which are deleted after 400 days by a job that runs every night. That is enforced in code rather than promised here, because an analytics table is the classic place where a retention promise quietly stops being true.

This website

We count page views so we can tell whether anything we write is read. The counting is deliberately poor at identifying you:

  • No cookie is set and no identifier is generated. There is nothing to link one visit to another, or to a person.
  • The referring site is recorded as a domain only, never the full address, because a full referrer can carry somebody else’s private path.
  • Your address is not stored. It is used once, mixed with a key that changes daily, to stop the contact form being used to send mail in bulk, and the result is discarded within hours.
  • Nothing is shared. No third-party analytics service, advertising network or script is involved, which is also why you are not being asked to accept cookies.

What that leaves is a count per day, per page, per referring domain. It is worth saying that this is the reason there is no consent banner on this site: there is nothing to consent to.

Removing a document, and what that does

Removal is not cosmetic, and it is not total. Precisely:

  • The document becomes unreachable and stops appearing anywhere in the product.
  • Every passage of its text is deleted, not hidden. Leaving copies of erased content in the database would make the erasure claim false in the way that matters most.
  • What was extracted from it stays, and visibly loses its source. A contract read out of a document you delete is not deleted with it. It remains, marked as standing on a source that has been removed. That is deliberate: silently deleting a contract because its PDF went would remove a deadline you are still bound by, and silently keeping it while it still looks sourced would be a lie.
  • The removal is logged, with who did it and what lost its source.

Before anything is removed, the product shows you what it will take with it. Nothing is deleted on the strength of a count alone.

Your rights

You can ask for a copy of everything in your workspace, or for the workspace to be deleted entirely. Neither is self-serve yet: ask and it is done by hand, within a working week. We would rather say that than put a button here that quietly opens a support ticket.

If you are a supplier contact or a colleague who received a survey and you want to know what is held about you, or want it removed, write to us. Your data sits inside a customer workspace, they are the controller of it, and we will act with them rather than around them.

Contacting us

Write to privacy@procurepro.app. A question about what the product does with a document will be answered with a reference to the mechanism, not a paraphrase of this page.

Privacy notice | ProcurePro