← Back

Security & privacy

The plain version. The full legal text is in the privacy policy.

What we don't do

No AI training
We don't use your documents to train AI models, and our contracts with our providers prohibit them from doing so.
No marketing use
We don't look at document contents for ad targeting, profile-building, or "improving the service."
No human review
Our access controls are designed so staff don't read your documents — except when you ask support for help, or where we must to operate the service, prevent abuse, or comply with law.
No selling data
We don't sell or rent your personal data.

What we collect

Your email address (for login).
Your default mailing address (CASS-verified by our print partner).
Payment methods, handled by Stripe — we never see your full card number.
The documents you print — kept so you can reprint them, until you delete them.
Basic device metadata: platform, app version, last-seen timestamp.

How a document flows

Your computer renders the document to PDF — the contents stay on your machine until you print.
When you print, it's uploaded to your account encrypted over TLS. Nothing is mailed yet.
Held in your account, encrypted at rest (AES-256), with a 10-minute hold you can cancel.
Only after the hold ends — i.e. after you confirm — is it forwarded over TLS to our print partner.
Printed, folded, enveloped, and mailed by our print partner.
Kept so you can reprint the letter later — and deleted the moment you delete it yourself (or close your account).

Uploaded at print time, mailed only on confirm

When you hit Print, the rendered PDF is uploaded to your account encrypted over TLS — that upload is the print step. Nothing is sent to our print partner or put in the mail until the 10-minute hold ends and you've confirmed. Cancel inside that window and the document is dropped, never mailed, never charged. We treat an uploaded-but-unconfirmed document with the same care as any other: encrypted at rest, no human review, and kept only until you delete it.

What our print partner sees

Our partner (PostGrid) sees the PDF, your name, and your address — the same information any printer-and-mailer would need. PostGrid states that it maintains SOC 2 Type II compliance and has its own retention policies. We're working toward bringing more of the print pipeline in-house as we scale.

Sensitive documents

Plenty of people use us for tax forms, medical letters, legal documents. The system is designed for that — the privacy posture above isn't marketing, it's how the code is wired.

That said, we're not a HIPAA Business Associate today. If you're a healthcare provider, contact us — there's an enterprise path with a BAA.

Infrastructure & security

HostingUS-based
DatabasePostgreSQL · encrypted at rest (AES-256)
TransitTLS 1.2+ in transit
AuthSession cookies · device bearer tokens stored securely on your device
PaymentsStripe · we never see your full card number
SOC 2Not yet audited. We intend to pursue SOC 2 as we scale.

Disclosures & legal process

We respond to valid subpoenas and court orders. We don't proactively scan documents. Our transparency report tracks every such request — as of its last update, we have received none.

Operated by Deep Thought Technologies Inc. Questions? security@printwhisk.com · all legal docs