Auto Redact — Privacy Policy
The privacy policy for the Auto Redact AI app · Last updated: July 2026
The short version: Auto Redact collects no data about you. The app has no user accounts, no analytics, no tracking, and no server of ours that your documents could ever reach. Everything — scanning, text recognition, and redaction — happens locally on your device.
One optional feature can send data off your device: “Ask AI” (section 5). It is off by default, uses your own API key, sends only redacted text, and asks your explicit permission first. Everything else works fully offline.
1. Data Controller
Tavlo - German Entity
Technologiezentrum Wuppertal
Heinz-Fangmann-Str. 2-6
42287 Wuppertal, Germany
E-Mail: contact@tavlo.tech
This policy covers the Auto Redact mobile and web app. The policy for the tavlo.tech website itself is available at /privacy/.
2. What the App Does With Your Documents
When you scan a letter with the camera, import a photo, or open a PDF, all processing happens on your device:
- Text recognition (OCR) runs locally — Apple/Google ML Kit on your phone, or a WebAssembly engine in your browser.
- Detection of personal data (names, IBANs, phone numbers, and so on) runs locally.
- Redaction — the black boxes — is applied locally.
Your document photos, PDFs, and their text are never uploaded to Tavlo or anyone else by the app. We could not read your documents if we wanted to.
3. What Is Stored on Your Device
Documents you save appear in the app's library, stored only on your device. The mapping between redacted placeholders and the original values is encrypted at rest with AES-256-GCM; the encryption key is stored in your device's secure Keychain/Keystore. You can protect the app with Face ID, fingerprint, or a PIN — biometric data is handled entirely by the operating system and never reaches the app or Tavlo.
Deleting a document in the app deletes it from your device. Uninstalling the app deletes the entire library.
4. When Data Leaves Your Device
Data leaves your device only when you explicitly send it somewhere. There are exactly two such paths, and both are started by you:
- Share & export. When you share a redacted image, PDF, or text through the operating system's share sheet, only the redacted version you approved is handed to the app you choose (for example a messaging app, an AI assistant, or email). You pick the destination in the system share sheet; from that point, the receiving app's own privacy policy applies.
- Optional “Ask AI”. Off by default. It requires you to enter your own API key for an AI provider you choose, and it asks for your explicit permission before the first send. Details below.
5. Optional “Ask AI” — Sharing With a Third-Party AI Service
“Ask AI” lets you ask questions about a document from inside the app. It is disabled by default, and using it requires two deliberate steps from you: enabling it in Settings with your own API key, and granting permission in a disclosure screen that appears before anything is sent. Nothing is transmitted unless you tap “Allow”.
5.1 What data is sent
- The redacted text of the document — every value the app blacked out is replaced by a placeholder such as [PERSON_1] or [IBAN_1] before sending.
- The text of the question you type (also passed through the same redaction engine).
- The model name you selected.
The following are never sent: your document photos or PDF pages, the original unredacted values, the mapping between placeholders and real values, your library, and any device or usage identifiers.
5.2 How the data is collected, and who receives it
The text is produced on your device by the on-device OCR and redaction steps described above; the app does not collect it from anywhere else. When you allow a send, the request goes directly from your device to the AI provider you configured, authenticated with your own API key. Depending on your choice, the recipient is the operator of that service — for example Anthropic (api.anthropic.com), OpenAI (api.openai.com), Google (generativelanguage.googleapis.com), or another provider you enter yourself. The in-app disclosure names the exact recipient and host before you consent.
Tavlo operates no server in this path and never receives, stores, or processes your text. We have no account system and no way to observe these requests.
5.3 All uses of the data
The redacted text is used for one purpose only: to obtain the AI provider's answer to your question, which is displayed in the app (with your real values restored locally on your device). Tavlo does not use it for anything — not analytics, not model training, not advertising, not profiling — because we never receive it.
5.4 Third-party protection
Because the request is made with your own API key directly to the provider you selected, your text is handled under that provider's privacy policy and API terms. The major providers offer business/API terms that are comparable in substance to the protections described here — including not using API inputs to train their models by default and deleting inputs after a limited retention period — but the terms are theirs, not ours, and they can change them. We therefore name the recipient in the app before you consent and ask you to review their policy. Links: Anthropic, OpenAI, Google. If you do not want any data shared with a third party, simply leave “Ask AI” off — every other feature of the app works fully offline.
5.5 Withdrawing permission
You can withdraw your permission at any time in Settings → Advanced · AI → Permission to send redacted text. Withdrawing takes effect immediately: the next question will ask for consent again before anything is sent. Choosing a different AI provider also requires fresh consent, because the recipient has changed. You can remove your stored API key in the same screen.
6. Component Downloads (Not Your Data)
On first use, the app may download software components: OCR language files and, if enabled, an on-device detection model (in the browser these come from public CDNs). These are downloads of program files only — none of your content is included in these requests.
7. Permissions
- Camera — to scan documents. Images are processed on-device.
- Photo library — to import pictures you pick. Read-only, processed on-device.
- Files — to import images and PDFs you pick, processed on-device.
8. Analytics, Advertising and Data Sharing
The app contains no analytics, no advertising SDKs, and no tracking of any kind. No user profiles are created, and no data is ever sold. Tavlo itself receives no data about you or your documents.
The single exception to sharing is the optional, off-by-default “Ask AI” feature described in section 5: if — and only if — you enable it, add your own API key and grant permission, the redacted text you submit is sent from your device to the AI provider you chose. No other data is shared with any third party under any circumstances.
9. Children
The app is not directed at children. Since the app collects no personal data, no data about children is collected either.
10. Your Rights
Because your data never reaches us, there is nothing for Tavlo to access, correct, export, or delete — you hold your data yourself, on your device. For any questions about data protection you can contact us at contact@tavlo.tech.
11. Changes
If the app's data handling ever changes, this policy will be updated here before such a change takes effect, with the “last updated” date above revised accordingly.