Privacy Policy
Last updated: September 4, 2026
Standraft ("we", "us") provides an automated document-formatting service at standraft.com. This page explains what data we collect, why, and how long we keep it. It's written to match exactly how the service works — not a generic template.
The short version: we don't store the documents you upload. They're processed in memory, written to a temporary file only for the seconds it takes to check or fix them, and deleted immediately afterward. We keep account details if you register, and the formatting rules extracted from a university guideline you ask us to read — never the guideline file itself.
1. What we collect
Documents you upload for checking or fixing. Your .docx file is uploaded, processed, and the temporary copy on our server is deleted right after the response is sent. We do not keep a copy, and we do not read its contents for any purpose other than producing the formatting report or the corrected file you asked for.
University guideline files (methodology analysis). When you use the AI guideline-reading feature, the file's text is sent to our AI provider to extract formatting rules (margins, fonts, spacing, and similar). We store the resulting rules — not the original file — so you and, if the guideline is reused, other users of the same institution don't pay to have the same document analysed twice.
Account information. If you register, we store your email address, a securely hashed password (we never store the password itself), and any optional profile details you add (display name, university, status).
Payment information. Payments are handled by Paddle.com Market Limited, our payment provider and merchant of record. We never see or store your card details — Paddle processes the transaction and shares with us only what's needed to confirm your purchase (email, amount, and a transaction reference).
Basic technical data. Standard web server logs (IP address, browser type, request timestamps) for security and abuse prevention, kept only as long as needed for that purpose.
Cookies. A single session cookie keeps you signed in. It's essential to the service and isn't used for advertising or tracking across other sites. We don't use analytics or advertising cookies.
2. Why we collect it
- To check and correct the formatting of the document you upload
- To extract and reuse your university's formatting rules when you ask us to read a guideline
- To create and secure your account, if you choose to register
- To process payment for the paid features of the service
- To keep the service secure and prevent abuse
3. Who we share it with
We use a small number of service providers to run Standraft, and share only what each one needs to do its job:
- Anthropic — processes the text of a guideline file (or a raw citation you ask us to format) to extract formatting rules or citation data. Anthropic does not receive the documents you check or fix.
- Paddle.com Market Limited — our merchant of record for payments; handles your card details and payment processing directly.
- Our hosting provider — runs the server that powers the service.
We do not sell your data, and we do not share it with anyone else for marketing purposes.
4. How long we keep it
- Uploaded documents: deleted immediately after processing — typically within seconds.
- Extracted guideline rules: kept until you delete them from your account, or indefinitely if left unused — they contain no personal data, only formatting rules.
- Account data: kept until you ask us to delete your account.
- Payment records: kept as required by law and by our payment provider's own retention rules.
5. Your rights
You can ask us at any time to:
- Tell you what data we hold about you
- Correct inaccurate account details
- Delete your account and associated data
- Delete a specific saved guideline profile
If you're in the EU/EEA or UK, these are your rights under GDPR/UK GDPR; we honor the same requests for everyone regardless of location. Contact us at the address below to make a request.
6. Security
Passwords are hashed with bcrypt and never stored in plain text. Connections to the site are encrypted (HTTPS). Access to the server is restricted. No system is perfectly secure, but we take reasonable technical measures to protect your data.
7. Children
Standraft is intended for university students and is not directed at children under 16. We don't knowingly collect data from children.
8. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify registered users by email.
9. Contact
Questions about this policy or your data: support@standraft.com.
Data controller: [legal entity name and registration details to be added here].