Policies.life processes your uploaded policy PDFs, extracts the details using AI, and shows them in one dashboard. Your data never leaves your control.
The Pipeline
Step 1
Upload
Securely upload your policy PDFs directly from your device
→
Step 2
Verify
We check passwords locally and ensure it's a valid policy
→
Step 3
Extract
Downloads PDFs and extracts policy details with AI
→
Step 4
Deduplicate
Merges renewals, fixes statuses, shows your final dashboard
Where Your Data Goes
your device→local password check→upload to server policy PDFs→AI extraction→encrypted with your vault key→database final policies→encrypted→database
vault key:never stored// exists only in memory PDFs:deleted instantly// processed locally, text sent to AI, then file is removed database without key:unreadable encrypted blobs
Privacy & Security
Secure Uploads
We process your uploaded PDFs securely. Passwords for encrypted PDFs are checked locally in your browser first before being securely transmitted for extraction.
Vault Key Encryption
All sensitive policy data is encrypted with AES-256-GCM using a key derived from your vault password. Without it, stored data is gibberish.
No PDF Storage
PDF files are downloaded temporarily to extract text, then kept only on your machine. They are never uploaded to any server or database.
Your Key, Your Data
The vault key is never stored anywhere — not in the database, not in cookies. If you forget it, even we can't read your cached policy data.
Common Questions
What does the AI see?
The AI (Grok) receives the extracted text from your PDF to pull out policy details. It does not store or train on your personal documents.
What happens to my PDF after upload?
Your PDF is processed immediately to extract the text and then deleted from our servers. We only store the encrypted extracted data in our database.
What happens if I use a wrong vault key?
The app will detect the mismatch and show an error. It won't corrupt your data — the encrypted cache remains intact for when you use the correct key.