Digident · PensionProof

Privacy policy

What stays on your device and what is processed only when you choose optional document extraction.

Effective 15 August 2026 · Version 1.1

Short version. You can use PensionProof without AI. If you choose optional extraction, the app first shows the complete bounded OCR text in an editable review. Only the text visible when you confirm—not the image—is sent to our Cloudflare Worker. The Worker redacts common identifiers again, sends the text to OpenAI with storage disabled for the API response, and does not place document content in our logs or storage.

1. Who we are

DIGIDENT LTD operates PensionProof and is the data controller for the optional online service. For privacy requests, email digidentai@proton.me.

2. Information on your device

The app may hold document images you select, OCR text, pension contribution candidates, your corrections, aliases, settings and reconciliation records in app-private storage. Android backup is disabled for protected app data. Files you deliberately export or share are controlled by the destination you choose and may no longer be encrypted by PensionProof.

Do not add another person's information. Before optional AI extraction, inspect and edit the complete bounded OCR text, removing names, National Insurance numbers, member or policy numbers, employer identifiers, addresses, contact details, bank information and anything not needed to identify pension contribution lines. The automatic redactor is only a safety aid and can miss unusual details.

3. Optional AI extraction

Only after you review the complete editable text and affirmatively choose to send it, the app sends that reviewed text, en-GB locale, and optional document/provider hints. It does not send the original image. The request schema does not require your name, NI number, member ID, employer name or full address.

Separately, the app uses a non-exportable installation signing key and Google Play Integrity to attest the app, Play signing certificate, version, licence and device integrity. The attestation request contains no document text. Google decodes the encrypted Integrity token for the Worker. After successful verification, the Worker derives an app-scoped pseudonymous subject from the app ID and public-key thumbprint using a PensionProof-only secret. Android cannot choose this subject. OpenAI receives redacted text, hints and a separately derived safety value, but not the Integrity token or public key. The request uses the Responses API with store: false. AI never determines a reconciliation result, due date or legal conclusion; deterministic app code and your review remain separate.

4. Retention and logs

5. Providers and international processing

We use Cloudflare to deliver and protect the Worker, Google to provide Play Integrity verification, and OpenAI to perform optional text extraction. Your device may use an on-device OCR library. These providers process limited data under their applicable contracts, terms and security arrangements and may process it outside the UK using applicable transfer safeguards.

6. Purpose and legal basis

We process optional document text to provide the extraction you request, and pseudonymous/security metadata to protect and operate the beta. Depending on the context, the relevant UK GDPR bases are performance of the requested service and our legitimate interests in security and abuse prevention. Please do not submit special-category or unnecessary identity data.

7. Your choices and rights

AI extraction is optional. You can inspect and edit the complete bounded OCR text before sending, delete local records, clear app data, or uninstall. Delete all also deletes the app-verification key and attempts to revoke a live server credential; a pseudonymous revoked security record may remain so that the old key cannot be reactivated. Subject to UK data-protection law, you may ask about access, correction, deletion, restriction, objection or portability. Because there is no PensionProof account and the authentication record contains no real-world identity, we may not be able to link a particular server record to you. You can complain to the UK Information Commissioner's Office.

8. Security and children

We use encrypted transport, Play Integrity, proof-of-possession authentication, strict request limits, no-content logging, HMAC pseudonymisation and layered rate limits. No system is completely secure. PensionProof is intended for adults managing their own workplace-pension records.

9. Changes

Material changes will be dated here and, where appropriate, shown in the app. Contact digidentai@proton.me with questions.