Our full privacy policy is with counsel and is not published yet. Rather than link you to a page that does not exist, this one says so plainly.
What we can tell you today, and can demonstrate: documents you upload are readable only inside your own workspace, enforced by the database rather than by application code remembering to ask. Connections are encrypted in transit. Deleting a document clears the file, the extracted text and the stored key, and leaves a dated record that it was removed.
There are things we are deliberately not claiming yet, because we cannot yet prove them to the standard a published policy demands. Those claims will appear when they are true and tested, and not before.
If you need the policy before it is published, ask and we will send the current draft.