Loading page…
Loading page…
The processing boundary depends on the product and the mode your application chooses.
Local mode maps and validates on-device, then calls your application with accepted batches. Optional device drafts store the source, corrections, and progress in IndexedDB for up to 24 hours; expired drafts are removed when the importer next opens, and Discard removes them immediately. Tokens are never stored there.
Parsing and conversion run in the selected browser or Node.js runtime. Your application controls its inputs, outputs, and onward transmission. The local website tool does not upload file content.
The browser worker downloads and verifies the selected model assets when you run recognition, then processes images locally. Verified models may be cached on your device and can be cleared. Images and recognized text are not persisted by the local tool. Model downloads are not document uploads.
Redaction targets supported content and selected fields. Findings and outputs may still contain sensitive information; keep them out of telemetry. Redaction does not sanitize the original image or PDF.
Accepted batches transit the relay for schema validation and signed delivery to one approved HTTPS destination. This widget delivery mode does not persist source files, rows, rejected values, or destination response bodies. Configuration, encrypted destination secrets, and operational metadata are stored.
A short-lived session and publishable key are both required. The session pins the importer version, origin, destination, and budgets. Receivers must verify signatures and durably deduplicate retries. Cancellation cannot recall delivered data.
OCR can misread text. Redaction can miss sensitive content or remove too much. Choose and evaluate profiles against representative data; a completed operation is not a guarantee of anonymity.
Host applications control onward transmission and local storage. Keep real values out of schema labels and analytics. Hosted OCR has a separate authenticated image-upload integration and is disabled until configured for an environment. The direct OCR gateway processes images transiently. Separately enabled asynchronous /v2/processing jobs persist source and result files in private R2 for the configured retention periods; their access, retry, and deletion rules differ from widget delivery. The public OCR tool remains local. Hosted anonymizer processing remains unavailable. Cloud AI mapping, when explicitly enabled, sends a bounded sample of up to 30 records to Workers AI to suggest mappings. Review suggestions before importing; samples are not persisted by the mapping service. Production operational controls remain launch requirements.
Contact bruno@prompt-buddy.io. Send a minimal reproduction without customer files or credentials.