1. Who we are
DIGIDENT LTD operates PensionProof and is the data controller for the optional online service. For privacy requests, email digidentai@proton.me.
2. Information on your device
The app may hold document images you select, OCR text, pension contribution candidates, your corrections, aliases, settings and reconciliation records in app-private storage. Android backup is disabled for protected app data. Files you deliberately export or share are controlled by the destination you choose and may no longer be encrypted by PensionProof.
Do not add another person's information. Before optional AI extraction, inspect and edit the complete bounded OCR text, removing names, National Insurance numbers, member or policy numbers, employer identifiers, addresses, contact details, bank information and anything not needed to identify pension contribution lines. The automatic redactor is only a safety aid and can miss unusual details.
3. Optional AI extraction
Only after you review the complete editable text and affirmatively choose to send it, the app sends that reviewed text, en-GB locale, and optional document/provider hints. It does not send the original image. The request schema does not require your name, NI number, member ID, employer name or full address.
Separately, the app uses a non-exportable installation signing key and Google Play Integrity to attest the app, Play signing certificate, version, licence and device integrity. The attestation request contains no document text. Google decodes the encrypted Integrity token for the Worker. After successful verification, the Worker derives an app-scoped pseudonymous subject from the app ID and public-key thumbprint using a PensionProof-only secret. Android cannot choose this subject. OpenAI receives redacted text, hints and a separately derived safety value, but not the Integrity token or public key. The request uses the Responses API with store: false. AI never determines a reconciliation result, due date or legal conclusion; deterministic app code and your review remain separate.
4. Retention and logs
- Worker: document text and extraction content are handled in memory for the request and are not written to our application logs, database, cache or object storage.
- Authentication and rate limiting: Cloudflare stores a pseudonymous subject, public key/thumbprint, credential epoch and active/revoked status for authentication, replay defence and revocation while the beta security system operates. This record contains no document content or real-world identity. Proof-replay digests expire after the credential/replay window and rate counters use short fixed windows. Cloudflare also processes normal security/network metadata such as IP address and request timing.
- Google: Google decodes the Play Integrity token and processes the app, licence and device signals needed to return a verdict; the authentication request hash contains no document text.
- OpenAI: API processing and any limited abuse-monitoring retention are governed by OpenAI's API data controls and our account configuration.
store: falseprevents the response being stored for later retrieval; it is not a promise that network providers process no operational metadata. - Support: if you email us, we receive what you choose to send and retain it only as needed to respond and meet legal obligations.
5. Providers and international processing
We use Cloudflare to deliver and protect the Worker, Google to provide Play Integrity verification, and OpenAI to perform optional text extraction. Your device may use an on-device OCR library. These providers process limited data under their applicable contracts, terms and security arrangements and may process it outside the UK using applicable transfer safeguards.
6. Purpose and legal basis
We process optional document text to provide the extraction you request, and pseudonymous/security metadata to protect and operate the beta. Depending on the context, the relevant UK GDPR bases are performance of the requested service and our legitimate interests in security and abuse prevention. Please do not submit special-category or unnecessary identity data.
7. Your choices and rights
AI extraction is optional. You can inspect and edit the complete bounded OCR text before sending, delete local records, clear app data, or uninstall. Delete all also deletes the app-verification key and attempts to revoke a live server credential; a pseudonymous revoked security record may remain so that the old key cannot be reactivated. Subject to UK data-protection law, you may ask about access, correction, deletion, restriction, objection or portability. Because there is no PensionProof account and the authentication record contains no real-world identity, we may not be able to link a particular server record to you. You can complain to the UK Information Commissioner's Office.
8. Security and children
We use encrypted transport, Play Integrity, proof-of-possession authentication, strict request limits, no-content logging, HMAC pseudonymisation and layered rate limits. No system is completely secure. PensionProof is intended for adults managing their own workplace-pension records.
9. Changes
Material changes will be dated here and, where appropriate, shown in the app. Contact digidentai@proton.me with questions.