PDM

Privacy Policy

Last updated: July 13, 2026

Draft — pending attorney review. Last updated: July 13, 2026.

This Privacy Policy describes how Unboxed Labs LLC ("we," "us," or "our") handles data in connection with PDM — PII Data Masking (the "Service").

1. What We Collect

  • Files you upload. We process the content of files you submit for masking. This is processed transiently and is not retained beyond delivery of your masked file or 48 hours, whichever comes first (see Section 3).
  • Payment information. Payments are processed directly by Stripe. We do not receive or store your full card details.
  • Basic job metadata. We retain limited, non-content metadata about completed jobs — such as row count, which column names were flagged as containing sensitive data, and the price charged — for support and record-keeping. This metadata never includes the actual sensitive values from your file.

2. How Your File Is Processed

When you upload a file:

  1. A statistically valid sample is used to generate a free price estimate, using our proprietary deterministic algorithms only (no Google Cloud DLP call at this step). No file content leaves our infrastructure for this step.
  2. Once you pay, the full file is scanned — every row, every column — using Google Cloud DLP + proprietary deterministic algorithms to identify sensitive data.
  3. Identified sensitive data is masked. Structured fields are replaced in full; sensitive data embedded within free-text fields is masked in place, leaving surrounding non-sensitive content unchanged.
  4. Your masked file is made available for download via a secure, one-time-use link.

No LLM. No generative AI. Nothing that trains on, remembers, or improvises with your data. Detection is deterministic — pattern, structure, and context matching via Google Cloud DLP plus our own validation algorithms. The same file produces the same result, every time.

3. Data Retention and Destruction

Your file and every intermediate copy are destroyed the moment your masked file is delivered — or automatically within 48 hours if you never download it. We do not keep backup copies of file content beyond this window.

4. Where Your Data Is Processed

Processing occurs on Google Cloud Platform infrastructure with no public-facing IP address for our database or file storage — these are only reachable from within our own private network, not from the open internet.

5. PHI (Protected Health Information)

The Service includes automated detection intended to identify likely indicators of PHI (such as diagnosis codes or medical record number patterns). If detected, we decline to process the file rather than proceeding. This detection is a good-faith technical measure and not a guarantee of complete identification.

6. Third-Party Processors

We rely on the following third parties to operate the Service:

  • Google Cloud Platform — infrastructure, storage, and Data Loss Prevention processing
  • Stripe — payment processing

Each operates under its own privacy and security practices.

7. Your Rights

Since we do not require an account and do not retain your file content beyond the destruction window described above, there is generally no ongoing personal data of yours for us to access, correct, or delete after that point. If you have questions about data submitted for a specific job, contact us via our Contact page with your job reference number.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date.

9. Contact

Questions about this Privacy Policy can be directed to us via our Contact page.