Privacy policy

How ADAComply PDF collects, uses, protects, and returns or deletes personal information. This policy applies to adacomplypdf.com, agency-branded portals operated on ADAComply PDF infrastructure, and the ADAComply PDF API. Last updated September 21, 2026.

Who we are

ADAComply PDF is a service of Vora Studios LLC, a privately held U.S. company. For questions about this policy or about your data, write to privacy@adacomplypdf.com.

What we collect

  • Account information: email address, hashed password (bcrypt), display name, organization name, and role within the organization.
  • Two-step sign-in: two-step sign-in with an authenticator app is required for every account that signs in with a password. An account that signs in through its organization's own sign-in system (single sign-on) follows that organization's two-step rules instead, and we hold no password for it. We store the authenticator secret encrypted, and we store your one-time backup codes only as one-way hashes.
  • Billing information: handled entirely by Stripe. We store your Stripe customer ID, a reference to your saved payment method, and receipt metadata; we never see or store your card number, CVV, or bank details.
  • Usage data: remediation jobs, credit balances, sign-in count, the time and IP address of your current and previous sign-in, and, if you accept analytics cookies, basic analytics about which pages of our own-branded site were viewed.
  • Activity log: a record of actions taken in your account (for example sign-ins, failed sign-in attempts, two-step sign-in checks, credit use, remediations, and dashboards created or deleted), with the IP address and browser type used. We record when you accept our Terms of Service. If you accept a partner agreement, we record the time and your IP address.
  • PDF files: source files you upload, public website PDFs you direct the Service to retrieve for auditing or remediation, and remediated outputs we return. Uploaded source files and remediated outputs are retained per your dashboard's retention settings; public website PDFs remain hosted by the source website unless uploaded directly.
  • Page search index: if page search is turned on, we store the text of each page of your documents and a numeric search index made from that text, so you can search inside your documents.
  • Remediate Now (no account): if you use Remediate Now without an account, we collect your email address (to send you the finished PDF), the PDF you upload, your IP address, and the Stripe payment reference. If you claim a free trial, we also store your email address, your IP address, and a one-way hash of your browser's user-agent text, so we can limit free trials to one per email address and three per IP address in any 30 days.
  • Support conversations: messages you send to our support, sales, partnership, or security addresses, along with any attachments you choose to include.
  • Helper bot questions: text you type into the in-app helper bot, your account role, the page you were viewing when you asked, and, if you ask about your own account, limited account data such as your credit balance or the names and status of your documents. These are sent to our third-party generative AI provider for processing. We ask you not to enter PII into the helper bot.

How we use it

  • To operate the service: authenticate your sessions, run audits, remediate documents, bill your account.
  • To provide support: respond to tickets and diagnose issues.
  • To keep the service safe: detect abuse, investigate security incidents, comply with legal obligations.
  • To improve the service: aggregated, de-identified usage patterns inform roadmap decisions.

We do not sell personal information and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under California law. We disclose your data to subprocessors only to deliver the service to you; our current subprocessor list is available on request.

Account activity and spend tracking

To keep billing accurate and accountable, we record how each account uses paid features. For every document submitted for remediation we log which signed-in user submitted it, when, the number of pages or tables processed, and the credits and dollar amount that action used. We also record credit purchases (who bought credits, when, and how many).

This activity is visible to the administrators of your organization's dashboards, so they can see who on their team is buying and spending credits and on which documents.

If your organization signed up through a white-label partner (an agency that resells ADAComply PDF under its own brand), that partner can see this spend activity across all of the customer dashboards under their brand. This means your account-activity and spend data is shared with the partner company your organization signed up under.

Our own staff can also see this activity, for support and billing operations.

We use this information only for billing, accountability, and support. We do not sell it, and we do not use it for advertising.

Secure dashboards. For dashboards marked "secure," anyone who has not been invited to the dashboard sees only aggregate totals — a single lump sum — and never the per-user detail or the names of individual documents. This protects the privacy of the activity inside a secure dashboard from people outside it.

If you use ADAComply PDF through your employer or organization, your organization's administrators control this activity data and can view it. Direct any requests about your account-activity or spend data to them.

AI processing of your documents

To remediate a document, the content of documents you upload or direct us to retrieve — including rendered page images and extracted text — is sent to Microsoft Azure OpenAI for generative accessibility analysis and to Google Document AI for text recognition (OCR), page-layout analysis, and page-orientation detection. This processing happens only to fulfill that remediation, and the providers do not use your document content to train their models under the terms governing our accounts. Microsoft has approved Modified Abuse Monitoring for our Azure subscription, so it does not store prompts or completions for abuse review. Queued Azure OpenAI jobs use content-bearing input, output, and error files in our provider account: we attempt deletion with retries as soon as a job ends, and every new file has a provider-enforced maximum lifetime of 14 days. Our Google Document AI integration uses synchronous processing, for which document bytes are processed in memory and are not persisted to disk; Google may temporarily log request metadata such as timing and request size. The resulting accessibility tags are applied to your document within our own U.S. systems. Google Gemini/Vertex is used only in manually started internal research over company-owned test documents and does not receive customer documents. If page search is turned on, the extracted text of each page is also sent to a United States Microsoft Azure OpenAI deployment to build the search index, which we store in our own systems. This is separate from the optional helper bot described below, which never receives document content.

When a remediation fails

If a document fails remediation or does not pass our automated compliance check, it stays on your dashboard. We copy it only when a member of your dashboard selects Share with support for that document, or when an administrator of your dashboard turns on Send every failed PDF to support. That setting applies to each document that fails while it is on, and we record who turned it on and when. We then copy that one document, its processed output, and the processing records to separate storage with our cloud provider. Our staff may then open it on a staff-operated machine in the same cloud to find and fix the fault. A document that our reviewers send back during review is copied in the same way, except on a secure dashboard. We do not copy these documents to personal devices. When a dashboard becomes secure, we delete any copies already made from it.

AI-assisted helper

The product includes an optional in-app helper bot that answers questions about how to use ADAComply PDF. The helper bot is powered by Microsoft Azure OpenAI, using a United States deployment. When you submit a question:

  • Your typed question, your account role (regular / site admin / user admin), and the URL path of the page you are viewing are sent to that provider for processing. Query strings are stripped before transmission to avoid leaking search terms or filenames.
  • If your question is about your own account — for example "how many credits do I have" or "why did this document fail" — the bot may include limited account-status data relevant to the question (for example, your remaining credit balance, or the names, status, and failure reasons of your recent documents) in the request sent to the provider so it can answer you. This lookup always uses the account you are signed in as: the bot can only ever retrieve your own organization's data, never another customer's, and it can only read this data — it cannot change or delete anything. Aside from this, we do not include the content of your documents, your email address, your name, or any other personal data in the helper bot prompt sent to the provider.
  • ADAComply PDF's account with the provider is on a paid tier, under which the provider does not use prompts to train its models. The provider's terms apply to that transmission and may change; we will update this page if our provider relationship changes materially.
  • Helper bot responses are generated by AI and may be wrong. The bot is a usability aid, not legal or compliance advice; do not rely on it for accessibility-compliance decisions.
  • Use of the helper bot is optional. Ignoring or closing the bot has no effect on your account.

We log helper bot interactions (the question, the response summary, account ID, timestamp) under our standard application logging, retained for the same window as our other authentication and security logs (12 months). Logs are accessible only to authorized ADAComply PDF personnel for debugging, abuse investigation, and quality improvement.

Service providers

We use these service providers to run ADAComply PDF. Each receives only the data it needs for its task.

  • Microsoft Azure (United States): hosting, database, file storage, encrypted backups, generative AI (Azure OpenAI), and delivery of account email (Azure Communication Services).
  • Google Cloud (United States): Document AI text recognition and page-layout analysis.
  • Stripe: payments and billing.
  • Brevo: backup delivery of account email, used only if our main email service is unavailable.
  • Sentry: error monitoring. Error reports contain technical details of the error and the page where it happened, which can sometimes include an email address. We do not send IP addresses to Sentry, and we remove document file names from error reports.
  • Google Analytics: page-visit analytics on our own-branded pages, only if you accept analytics cookies. It is never used on agency-branded portals.

Legal bases (GDPR)

For customers subject to GDPR, our legal bases are: contract performance (operating the service for you), legitimate interests (security monitoring and service improvement), consent (optional marketing communications, if you opt in), and legal obligation (tax, accounting, and regulatory record-keeping). You can withdraw consent at any time where consent is the basis we rely on; withdrawal does not affect processing done before the withdrawal. Personal information is collected directly from you when you register, use the service, or contact support. We do not engage in automated decision-making that produces legal or similarly significant effects on you.

Cookies and tracking

We use first-party cookies that are strictly necessary for session authentication and CSRF protection; these run without a separate consent prompt because the service cannot operate without them. On our own-branded pages we may use Google Analytics 4 (gtag.js) to measure which pages are visited and where visitors arrive from, when a GA property is configured. Analytics cookies are set only after you click "Accept all" in the cookie banner, for every visitor wherever they are located. If your browser sends a Global Privacy Control signal, we record your choice as "necessary only" until you change it. We never set advertising cookies. We do not use Google Analytics on agency-branded portals. GA4 does not store full visitor IP addresses. You can block analytics with a standard browser privacy extension; doing so does not affect your ability to use the product.

California and other U.S. residents with "do not sell or share" rights: you can opt out of any sharing for cross-context behavioral advertising by enabling the Global Privacy Control (GPC) signal in your browser, which we honor as a valid opt-out, or by emailing privacy@adacomplypdf.com with "Do Not Sell or Share" in the subject line. We do not currently engage in sale or cross-context behavioral sharing, and this mechanism remains available if that ever changes.

Retention

  • Account records are retained for the life of your account, plus up to 90 days after deletion to complete billing reconciliation.
  • Uploaded PDFs and remediated outputs are retained for as long as your account is active. Public website PDFs remain hosted by the source website unless uploaded directly. You can delete stored files at any time.
  • Audit results and job metadata are retained for as long as your account is active, then purged with the rest of your account data after closure.
  • The page search index is retained for as long as the document it was made from.
  • The account activity log is kept for as long as your account is active. IP addresses and browser types in the activity log, and the IP addresses of your sign-ins, are deleted after 90 days.
  • Remediate Now (no account): an upload that is never paid for is deleted after 3 days. The finished PDF and its download link are deleted 7 days after delivery, and we remove your email address from the order at the same time. When the file is deleted, we also remove the readable email address from the free-trial record. We keep a one-way hash of the email address, the IP address, the browser hash, and the claim date so the trial limit still works; you can ask us to delete these at any time.
  • Support conversations are retained for 3 years.
  • Security and authentication logs are retained for 12 months.
  • Copies of a failed document in separate storage are deleted when the document is approved, and in any case within 30 days. Copies on the staff-operated machine are deleted when we no longer need them to fix the document.
  • Working copies the remediation process makes (extracted text, layout and tag results, and intermediate PDFs) and the document's edit history are deleted when you delete the document or its dashboard.
  • Encrypted database backups age out within 30 days. Point-in-time database recovery covers the last 7 days. We do not edit backups; a deleted item leaves them when the backup that holds it ages out.

Your rights

Regardless of where you are located, you can request:

  • A copy of the personal information we hold about you (access / data export)
  • Correction of inaccurate information
  • Deletion of your account and its associated data
  • Restriction of processing while a dispute is being resolved
  • Portability in a commonly-used, machine-readable format
  • To object to processing based on our legitimate interests, including direct marketing (GDPR right to object)
  • To withdraw consent at any time, where consent is the legal basis for processing
  • To be free from retaliation for exercising any of these rights (CCPA right to non-discrimination)

Email privacy@adacomplypdf.com. We respond to GDPR requests within one month (extendable by up to two additional months for complex requests, with notice) and to CCPA/CPRA requests within 45 days (extendable by 45 additional days with notice). You may authorize an agent to submit a request on your behalf; we will ask for reasonable proof of authority. If you disagree with our decision on a CCPA/CPRA request, you may appeal by replying to our response email; we will confirm receipt and issue a decision within 60 days. If you believe we have handled your data improperly, residents of the EU/EEA may complain to their national data protection authority; UK residents may complain to the Information Commissioner's Office; California residents may contact the California Privacy Protection Agency or the California Attorney General.

International transfers

Our servers are in the United States. If you access ADAComply PDF from outside the U.S., your data will be transferred to and processed in the U.S. For EU/EEA data, we rely on Standard Contractual Clauses where required. Every customer dashboard currently sends generative remediation to a United States Azure OpenAI deployment, regardless of the dashboard's stored engine setting. Google Document AI page-layout analysis uses its United States multi-region. Google Gemini/Vertex is limited to manually started internal research over company-owned test documents and is not used for customer dashboards.

Children

ADAComply PDF is a business tool intended for adult users. We do not knowingly collect personal information from children under 13 (or, for users in the EU/EEA and the UK, under 16, or the applicable age set by the relevant member state). Accounts may only be created by individuals who are at least 18 years old or the age of majority in their jurisdiction. If you believe a child has provided personal information to us, email privacy@adacomplypdf.com and we will delete it.

Changes to this policy

We will post material changes to this page and update the "last updated" date at the top. Significant changes will be announced by email to active account holders at least 14 days before taking effect.

Contact

Privacy questions: privacy@adacomplypdf.com. Security reporting: security@adacomplypdf.com.

Postal contact:
Vora Studios LLC, Attn: Privacy, for a current mailing address email privacy@adacomplypdf.com and we will respond within two business days.

See also our Terms of Service.