This is a working policy structure and has not been represented as legally approved. It should be reviewed by qualified counsel before production launch.
Information we collect
Identral may collect account information you provide, such as your name and email address; profile details you add to your vault; documents and images you upload; extracted document information; saved website login details; support communications; and limited technical information required to operate and protect the service.
- Account and profile information
- Uploaded files and extracted fields
- Document labels, categories, quality notes, and relevant dates
- Share-link settings and access activity
- Support messages and operational logs
How information is used
Information is used to provide the vault, process documents, match form fields, generate requested guidance or drafts, manage controlled sharing, display reminders and relevant notices, authenticate accounts, maintain the service, and respond to support requests.
- Sensitive document content should not be sent to analytics tools.
- AI features may send necessary task context to the configured AI service when you request processing.
- We do not describe personal information as being sold because no verified implementation supports such a practice.
Document and file handling
The current application is configured to store uploaded documents in cloud object storage and related structured data in a database. Public product demonstrations use fictional sample information and should never expose a real user’s document.
Retention periods, production storage regions, backup practices, and deletion schedules must be confirmed by the product owner before this policy is finalized.
Sharing
When you create a share link, people who receive an active link may access the selected information until the link expires, reaches its access limit, or is revoked. You are responsible for choosing recipients and sending links carefully.
Service providers and international processing
Identral relies on service providers for infrastructure and product functions, including database hosting, cloud file storage, email delivery, and AI processing. The final policy should identify production providers, processing locations, and transfer safeguards after deployment choices are confirmed.
Security
The application uses password hashing, authenticated protected routes, encrypted storage for saved login passwords, upload type and size limits, and environment-based secret management. No system can guarantee absolute security. Additional production controls should be reviewed before launch.
Your choices and rights
You may update information through the product and contact Identral about access, correction, deletion, objection, restriction, or portability requests that apply under relevant law. Identity verification may be required before completing a request.
Children, changes, and contact
The intended minimum user age and children’s-data approach require product-owner and legal confirmation. Material changes should be posted with a revised date. Privacy questions and account requests can be submitted through the Identral contact page.