Privacy policy
Whitney Solutions · Effective September 17, 2026
This is a plain-language statement of what Whitney Pages does with data, written to be accurate about the software as built.
The short version
Whitney Pages edits PDF files on your own computer. Your documents are never uploaded, transmitted, or seen by us. The only data we hold is what it takes to know who is allowed to sign in: an email address, which organization it belongs to, and a record of sessions and administrative actions.
What we collect, and why
- Your email address, given to us by your organization's administrator when they invite you. It is your account; there is no password.
- Sessions: when you signed in, when a session was last used, and when and why it ended. These let an administrator see who has access and sign a lost device out.
- Rate-limit counters keyed by email address and by network (IP) address, which stop anyone guessing sign-in codes.
- Administrative actions in your organization: who invited, removed, or changed the role of whom, and when. This is the audit trail your organization's administrators see.
- Technical logs kept by our hosting provider: request times, paths, network addresses, status codes, and errors, used for operating and securing the service.
We do not collect the contents, names, or metadata of any document you open in Whitney Pages. The application runs in your browser or on your desktop, and works with the network switched off.
Our role
For the people in a customer's organization, that organization decides who is invited and why, and we process their details on its behalf and on its instructions. In the language of data-protection law the organization is the controller and we are its processor. We process this data to provide the service your organization licensed; for our own customer contacts, our basis is that contract.
What stays on your device
If you turn on Remember my work on this device, the application stores your open documents and arrangement in your browser's own storage on your machine, so they come back after a reload. This never leaves your device and you can clear it at any time from the same setting.
Signing in to the website sets one cookie, which holds your session and is needed for sign-in to work. We use no analytics or advertising cookies.
Other services the software contacts
Two optional features fetch files from third parties. No document or account data is sent, but, as with any web request, those services see your network address:
- Reading scanned pages (OCR) downloads the text-recognition engine and language data from cdnjs (Cloudflare), jsDelivr, and projectnaptha.com the first time a page needs reading.
- Desktop updates are checked for and downloaded from GitHub.
Who processes data for us
The full list, including services the software contacts directly for optional features, is on our subprocessors page.
- Railway runs the sign-in service and website (United States).
- Neon hosts the database, on Amazon Web Services (United States).
- Resend delivers our email, such as sign-in codes and invitations.
- Cloudflare provides DNS for our domains.
We do not sell or share personal data for advertising, and share it with no one else except as required by law. Our servers are in the United States; if you are in the EU or UK, your details are transferred there under the safeguards data-protection law requires.
How long we keep it
Account and audit records are kept while your organization is a customer. Sessions that have ended and sign-in codes that were used or expired are removed after ninety days. When an organization stops being a customer, we delete its records on request, and an account that no longer belongs to any organization is anonymized after thirty days. Database backups roll off within days. Technical logs are kept only as long as our hosting provider retains them. Sign-in codes expire within minutes and invitation links within days; both are stored only as one-way hashes.
Your rights
You can ask us to show you, correct, or delete the personal data we hold about you. Because your account exists at your organization's request, removing you from an organization is done by its administrator; you can delete your own account from the account page, and your organization's administrator can pass any other request to us. Deleting your account removes your name and address from the account and from its invitations, and removes its passkeys; each organization's audit trail is that organization's record of who did what, so it keeps the address it recorded until the organization's own records are deleted. If you are in the EU or UK you also have the right to complain to your data protection authority. California residents have the rights the CCPA gives, including to know what we collect (listed above) and to have it deleted; we do not sell or share personal information.
Security
Sign-in is passwordless and rate-limited. Sessions are revocable server-side and end automatically when unused. Data in transit is encrypted with TLS; the database is encrypted at rest by its host. Report a security concern through your organization's administrator.
Changes
If this policy changes in a way that matters, we will tell your organization's administrators by email before the change takes effect.