Privacy Policy

Last updated: September 13, 2026

What this policy covers

This policy covers VersePDF document/PDF tools and WiseSuite features, including Wise Docs, Wise Sheets, Wise Slides, Wise Publish, image and Photo Studio tools, audio and video processing, generators, field and CAD-related utilities, Automate with Code, Developer API and Enterprise Automation features.

Files and media you upload

Documents, images, audio, video, archives, CAD files and other uploads are processed only to perform the task you request. Server-processed files and generated outputs are temporary and are normally cleaned up automatically within about one hour, unless a feature explicitly saves content for longer. We do not sell uploaded content or use uploaded file contents to train our document-AI systems.

Some editing and analysis features can run inside your browser. In those cases the source content does not need to be sent to the server unless you start a server-backed operation. Export and conversion steps that require server processing follow the temporary-file rules above.

Automate with Code

Automate with Code accepts Wise Script, Python, JavaScript, VBA-style compatibility syntax and Shell-style document commands. These modes are limited to the current document through the protected document bridge. Python and JavaScript do not receive unrestricted network, page-DOM, browser-storage or host-filesystem access; VBA-style does not execute Microsoft Office macros; and Shell-style does not execute an operating-system shell. Pasted code runs for the current document and is not automatically saved as a reusable macro or automatic trigger.

Changes are staged first. Preview mode does not commit them, and a normal run only commits after the script completes successfully, requests the selected language's apply operation, and passes the applicable structural checks. Advanced custom instructions can still create unexpected document formatting or behavior, so users should review code before running it.

Browser-local settings and recovery data

Some preferences, editor state, trust decisions, recovery drafts and design settings can be stored on the user's device so the workspace can restore or remember choices. Browser-local data remains subject to the user's browser/device controls and can be cleared by the user. A server-side operation is only started when the feature explicitly requires it.

Life Archive and intentionally saved content

If you use Life Archive to intentionally save content for later search or retrieval, that content is retained until you delete it. This is a deliberate exception to the normal temporary-file cleanup and only happens when you explicitly choose to save something.

Land & Area Measurement and location

The Land & Area Measurement tool asks your browser for location permission. Live coordinates and measurements are processed in the browser for the measurement session. If you export location data and later upload that exported file into another tool, the normal upload policy applies to that later upload.

Self-hosted private AI processing

Production document-AI processing is configured in a self-hosted, fail-closed mode within VersePDF-controlled infrastructure. Uploaded document content and document-AI prompts are not routed to third-party AI model APIs in the normal production private-AI path. The service is designed so merely configuring an external credential does not silently turn external document-AI routing on.

Software and model packages may be obtained during system provisioning or maintenance. That infrastructure activity is separate from processing a customer's uploaded document or prompt. See the Private AI page for the current public boundary.

Optional external integrations

Self-hosted document processing does not mean every optional product feature is air-gapped. Features such as payment, third-party sign-in, user-requested design export, public video/caption retrieval, live web search, public timestamping, advertising or optional diagnostics can involve an external service. Those integrations are separate from normal document-AI inference and receive only the information needed for the specific feature that is enabled or requested.

Enterprise Document Automation and APIs

API usage can record the account or API-key identifier, selected operation or professional environment, task identifier, timestamps, usage counts, file metadata and processing status needed to authenticate requests, enforce limits, operate the service and support customers. API secrets use separate key families for standard Developer API and Enterprise Automation. The full secret is only returned when a key is created or rotated; stored records use non-secret identifiers and protected verification values rather than retaining the reusable secret in plain text.

API-enabled Enterprise plans can use the environment-based document-automation API and the supported platform-tool API. Enterprise API keys do not turn Automate with Code into a remote arbitrary-code service: all accepted automation modes remain sandboxed, document-local features.

Account information

If you create an account, we store the account information needed to provide the service, such as your email address, name, plan and usage state, and basic profile information supplied by a sign-in provider. Passwords are not stored in plain text.

Session and security cookies

Signed-in sessions use security cookies and request-protection controls so the browser can authenticate account actions. Sensitive session cookies use Secure/HttpOnly protections where applicable to the deployment. These controls are used for authentication and security, not for advertising profiling by VersePDF.

Payments and subscriptions

Purchases are completed through a payment-processing service. VersePDF stores the transaction and subscription information needed to activate and manage access, but does not need to receive full payment-card details from the processor.

Advertising

Ad-supported browser plans may load Google AdSense or other configured advertising technology. Paid/ad-free entitlements do not intentionally fall back to advertising when a plan check fails. Advertising providers can process browser/device information under their own policies when advertising is enabled for the user's plan.

Security and retention

We use access controls, upload checks, task ownership checks, temporary-file cleanup, API rate limits and other safeguards appropriate to the service. No online service can guarantee absolute security. Enterprise customers may have additional contractual retention, deployment or security terms that apply to their organization.

Your choices

You can choose whether to upload content, enable optional integrations, save content intentionally, use API access, or run Automate with Code in one of its supported sandboxed language modes. You can also contact us about account or privacy questions through the Contact page.

Changes to this policy

We may update this policy as the platform, plans or data flows change. The date at the top identifies the current published version.