Privacy Policy
Last updated: September 4, 2026
This Privacy Policy describes how Unboxed Labs LLC ("we," "us," or "our") handles data in connection with PDM — PII Data Masking (the "Service").
1. What We Collect
- Files you upload. We process the content of files you submit for masking. This is processed transiently and is not retained beyond delivery of your masked file or 48 hours, whichever comes first (see Section 3).
- Payment information. Payments are processed directly by Stripe. We do not receive or store your full card details.
- Basic job metadata. We retain limited, non-content metadata about jobs — such as row count, which column names were flagged as containing sensitive data, and the price charged — for support and record-keeping. For a file routed to clinical coverage, this also includes the attestation record: whether you attested or declined the Business Associate Agreement, the time you did so, and the version of that agreement. It also includes the processing receipt for a completed job — the SHA-256 hashes of your input and masked output and the count of masked items in each category, never the values themselves. This metadata persists after your file content is deleted (see Section 3) and never includes the actual sensitive values from your file.
2. How Your File Is Processed
When you upload a file:
- A statistically valid sample is used to generate a free price estimate, using our proprietary deterministic algorithms only (no Google Cloud DLP call at this step). No file content leaves our infrastructure for this step. If the file's structure indicates a clinical (healthcare) record, you are asked to complete a Business Associate Agreement attestation before payment.
- Once you pay, the file is processed as a batch job — you receive a status link and can close the page while it runs. The full file is scanned, every row and every column, using Google Cloud DLP, our own validation algorithms, and our self-hosted AI detection model.
- Coverage adapts to the file: a clinical file receives clinical identifier coverage, a financial file receives financial identifier coverage, and other files receive the general set. Identified sensitive data is masked — structured fields in full, sensitive data in free text in place — leaving surrounding non-sensitive content unchanged.
- Your masked file is made available for download via a secure, one-time-use link. If a job cannot complete correctly, it stops and your payment is automatically refunded.
All detection, including our own AI model, runs inside our sealed cloud perimeter, on our infrastructure. Your file never goes to a public AI service, and nothing derived from it is ever used to train, improve, or fine-tune any model. Detection combines Google Cloud DLP, our own validation algorithms, and our self-hosted detection model.
3. Data Retention and Destruction
Your file and every intermediate copy are destroyed the moment your masked file is delivered — or automatically within 48 hours if you never download it. We do not keep backup copies of file content beyond this window. Limited non-content job metadata, including any attestation record described in Section 1, is retained after the file is deleted for support and record-keeping.
4. Where Your Data Is Processed
Processing occurs on Google Cloud Platform infrastructure with no public-facing IP address for our database or file storage — these are only reachable from within our own private network, not from the open internet.
5. PHI (Protected Health Information)
Files that indicate health data are routed to the attestation step before any payment. You either accept the Business Associate Agreement or state that the file contains no Protected Health Information. Either way the file is processed and the choice is recorded with the job. This detection is a good-faith technical measure and not a guarantee of complete identification.
6. Third-Party Processors
We rely on the following third parties to operate the Service:
- Google Cloud Platform — infrastructure, storage, and Data Loss Prevention processing
- Stripe — payment processing
- Umami — cookieless analytics tool which captures usage data only and does not store or read PHI
Each operates under its own privacy and security practices.
7. Your Rights
Since we do not require an account and do not retain your file content beyond the destruction window described above, there is generally no ongoing personal data of yours for us to access, correct, or delete after that point. If you have questions about data submitted for a specific job, contact us via our Contact page with your job reference number.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date.
9. Contact
Questions about this Privacy Policy can be directed to us via our Contact page.