Privacy Policy
Last updated August 8, 2026
The short version
We do not store the documents you send. A PDF is processed in memory, the extraction comes back to you, and the content is gone from our systems when the request ends. A document too large to send in one piece is uploaded to private storage first and deleted as we read it, which is seconds of custody rather than a copy we keep. What we keep is a usage ledger: the document's file name, token counts, processing time, and a timestamp, tied to your API key. Land records are usually public documents, but nothing about our design depends on that.
What we process, and where it goes
Extraction runs on Anthropic's Claude API: the document you send is transmitted to Anthropic for the extraction step, under Anthropic's commercial terms, which do not use API content to train models. The deterministic validation that produces the GroundTruth verdict runs on our own infrastructure and has no external dependencies. No other third party sees document content. If you submit documents as a batch, Anthropic holds them for that batch's lifetime (under 24 hours) while it works through them; Easting still stores none of them.
A document too large to send in one request takes a short detour: your software uploads it straight to private, encrypted storage and hands us a reference. The request that extracts it deletes it as it reads it, on every plan, before any processing begins. Custody there is seconds, and a crash mid-extraction leaves nothing behind. If an upload is never extracted at all, it expires within a day on its own.
Customers whose documents carry retention obligations used to buy a separate tier for faster deletion. That tier is gone, because the control it sold now belongs to everybody: you delete your own results, whenever you want, one at a time or all at once, from the run history at app.easting.ai. Nothing expires on a clock and nothing waits for a sweep. What survives a deletion is the record that the work happened, because your invoice refers to it.
Batch and large uploads are included on this tier; the customers who most need them are exactly the compliance-sensitive ones.
What we store
- Usage ledger. Per extraction: the file name you supplied, input and output token counts, processing seconds, the model used, and a timestamp, tied to your key's prefix. This is what metering, quotas, and your usage endpoint run on.
- Results. We hold each document's extraction and verdicts (the answer, never the document) until you delete them. Nothing expires on a clock: your run history at app.easting.ai lists everything this account has run, and a Delete button on any run clears its result, with a Delete all results button that clears the account. The record that the work happened stays, because your invoice refers to it; what goes is the extraction itself.
- Key records. A fingerprint (hash) of your API key, its display prefix, a name, and its quota numbers. We cannot recover a lost key from what we store.
- Billing. Subscriptions run on Stripe; Stripe holds your payment details and email under its own privacy policy. We store the Stripe customer and subscription identifiers and the tier you chose, not card data.
- Email. If you write to us, we keep the correspondence. Sample documents sent by email for testing are deleted after the test unless we agree otherwise.
- Server logs. Standard operational logs (request paths, status codes, key prefixes, never document content), retained for one month.
What we do not do
- No selling or sharing of data with advertisers or brokers.
- No training of models on your documents.
- No analytics scripts or tracking cookies on this site. The one third-party request anywhere in Easting is the browser app at app.easting.ai fetching basemap tiles from Esri and OpenStreetMap, and the PLSS survey grid from the BLM, when you have the map open. Those services see your browser asking for map tiles; they never see your document, and nothing about it is sent with the request.
- No storage of the documents themselves, on any plan, at any price point. Results are the one place we hold anything quoted from a document, because an extraction includes the wording of each call verbatim, and we keep those until you delete them. Deleting is one button on any run, and one button for the whole account. Large uploads are deleted as they are read, on every plan.
Data location and security
Infrastructure runs on AWS in the United States (us-east-1). The usage ledger lives in a database that is not reachable from the internet; API keys are stored only as hashes; secrets live in AWS Secrets Manager. Transport is TLS 1.2 or newer everywhere.
Your choices
The ledger's file names come from you: send a
X-Document-Name header of your choosing (or
none) and that is all we ever see of the name. To have your ledger rows
or key records deleted, or to ask what we hold, email
support@easting.ai from the address on your subscription; billing records stay as long as
tax law requires.
Changes
Material changes will be dated here and announced to subscribers by email before they take effect. This policy is part of the Terms of Service.