Privacy Policy

Last updated: 2026-08-25

BALMAS exists to keep sensitive data out of the wrong places, so this policy starts with the most important fact: your document content never reaches our servers.

1. What we never collect

Documents you clean are processed entirely in your browser (or, in the desktop app, on your device). The original file, the extracted text, the preview and the original-to-replacement map are never uploaded, logged or stored by us, and disappear when you close the page. We cannot see them, so we also cannot use them — not for analytics and not for training AI models.

2. What we do collect

Account details: your full name, the organization you work at, your email address and, if you chose to provide it, your phone number.

Anonymous usage counters: when a document is cleaned we record only the file type and item counts (for example: "a DOCX was cleaned, 12 items replaced") to enforce plan quotas and understand usage. No document content, file names or replacement values are included.

Billing details for paid plans: payer name, email, phone and subscription status. Card numbers are tokenized directly between your browser and Sumit, our payment processor — they never pass through our servers.

Technical basics: essential cookies for your login session and language preference, and standard server logs (such as IP address and time) used for security and rate limiting.

3. How we use it

We use this data to operate the service: authentication emails (verification codes and links), quota enforcement, billing and invoices, team management, support, and service announcements. We do not sell personal data and do not use it for third-party advertising.

4. Where it lives and who processes it

Account and usage data is stored in a managed database (Supabase) with access controls and row-level security. The site is hosted on Vercel. Payments and invoices are processed by Sumit. These providers process data on our behalf under their own security and privacy commitments. Beyond them, we share data only if the law requires it.

5. Retention and deletion

Account data is kept while your account is active. You can update your details in the profile page at any time, and request full account deletion by emailing support@balmasai.com — we will delete your personal data, keeping only what billing or tax law requires us to retain (such as issued invoices) and aggregate, non-identifying counters.

6. Your rights

Under the Israeli Privacy Protection Law (including Amendment 13) and, where applicable, the GDPR, you may request access to, correction of, or deletion of your personal data. Write to support@balmasai.com and we will respond within a reasonable time.

7. Cookies

We use essential cookies for your login session and your language preference. On marketing pages we also load Google Tag Manager for aggregate visit analytics; it is never loaded on the document-cleaning screen or on any page where documents are processed, and we do not use advertising cookies.

8. Security

All traffic is encrypted in transit (TLS). Database access is restricted by row-level security and least-privilege keys, and card data never touches our servers. No system is perfectly secure, but our architecture is built so that the most sensitive thing — your documents — is never in our hands at all.

9. Changes and contact

We may update this policy; material changes will be posted here with an updated date. Questions about privacy: support@balmasai.com.