Privacy Policy
Last updated: 14 August 2026
This policy explains what UpScan does with information when you use our file-scanning service. It is written to be read, not to be survived.
The short version. Files you send us are scanned and then deleted — deletion is a step in the code that runs on every scan, including ones that fail. We keep the file's fingerprint (a SHA-256 hash), its name, size, the verdict, and — where a document was flagged for prompt injection — the type and location of what was found, never the text itself. Scanning happens on servers we operate in the United Kingdom. We do not sell data, and we do not share your files with antivirus vendors or anyone else.
1. Who we are
[COMPANY NAME] ("UpScan", "we", "us") is the data controller for information about your account, and a data processor for the files you submit for scanning. Company number [COMPANY NUMBER], registered at [REGISTERED ADDRESS]. Contact: [CONTACT EMAIL].
2. What we collect
Account information
Your email address, a hashed version of your password, your API keys (stored hashed, never in readable form), your plan, and records of your scan usage for billing and fair-use limits.
Files you submit for scanning
The file itself, held only for as long as scanning takes — typically a few seconds. We also record its filename, size, SHA-256 fingerprint, the verdict, and any threat name.
Technical information
Server logs containing IP addresses, timestamps, and request paths, kept for security and troubleshooting. Logs do not contain file contents.
3. What happens to your files
| Data | Kept for | Why |
|---|---|---|
| The file's contents | The duration of the scan only, then deleted | Scanning cannot happen without temporarily holding the file |
| SHA-256 fingerprint | Retained | Lets you look up past results and lets us avoid rescanning identical files. A hash cannot be turned back into the file |
| Filename, size, verdict, threat name | Retained | Your scan history and audit trail |
| Injection finding types and locations — never the text | Retained | Tells you why a document was flagged: that white text was found on page 2, how many characters it ran to, which category of instruction it matched. The words themselves are not recorded |
| Account and billing records | While your account is active, then as tax law requires | Running your account; legal obligation |
| Server logs | Up to 30 days | Security and diagnostics |
Filenames sometimes contain personal information (for example jane-smith-cv.pdf). If that matters to you, send files under a neutral name — the scan result is identical.
4. Where scanning happens
Files are scanned on servers we operate in the United Kingdom. They are not forwarded to overseas scanning engines, and they are not shared with antivirus vendors or threat-intelligence platforms.
Two clarifications, in the interest of being accurate rather than flattering:
- Threat-intelligence lookups. To improve detection we may check a file's SHA-256 fingerprint against public malware databases. Only the fingerprint is sent — never the file, its name, or its contents. A hash cannot be reversed into the original file.
- Prompt-injection scanning. If you enable our AI injection detection, text extracted from documents may be sent to our AI provider (Anthropic) for classification, under terms that prohibit training on it. This feature is optional and off unless enabled. If you would rather no text left our servers at all, leave it off. We ask that provider only for categories and counts, never for quotations, and nothing it returns that could contain your document's wording is stored.
5. Why we are allowed to process this
- Contract — we cannot provide scanning without processing the files you send and the account you hold.
- Legitimate interests — keeping the service secure, preventing abuse, and improving detection.
- Legal obligation — retaining billing records.
6. If you are scanning other people's files
When you use UpScan to scan uploads from your own users, you are the data controller and we act as your processor. We process files only to perform the scan you asked for, and only on your instructions. Our terms of service form the processing agreement; a separate signed data processing agreement is available on request at [CONTACT EMAIL].
7. Sub-processors
We keep this list short deliberately.
| Provider | Purpose | Location |
|---|---|---|
| Our hosting provider | Servers running the scanning service | United Kingdom |
| Email provider | Account verification and password resets | [CONFIRM LOCATION] |
| Payment provider | Subscription billing — they handle card details; we never see them | [CONFIRM WHEN LIVE] |
| Anthropic | AI injection detection, only if you enable it | United States |
8. Your rights
Under UK GDPR you may ask for a copy of your data, ask us to correct or delete it, object to processing, or ask for it in a portable format. Email [CONTACT EMAIL] and we will respond within one month.
Deleting your account removes your scan history and account details. Note that we cannot delete files we no longer hold — they were deleted at scan time.
If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.
9. Security
Traffic is encrypted in transit. Passwords are hashed with bcrypt; API keys are stored as hashes and shown once at creation. Files awaiting scanning are held on encrypted storage and deleted immediately afterwards. Components that parse untrusted files run in isolated, unprivileged containers.
No system is perfectly secure. If you find a vulnerability, please tell us at [CONTACT EMAIL] — we will work with you and we will not pursue researchers acting in good faith.
10. Children
UpScan is a service for businesses and developers. It is not intended for anyone under 18, and we do not knowingly hold data about children.
11. Changes
If we change this policy we will update the date above, and for significant changes we will email account holders. We will not make a change that quietly weakens the deletion promise — that promise is the product.