Put plainly
We hold your conversation for as short a time as the work allows, encrypt it while we do, log every access to it, and delete it on a schedule you control.
Time is the control that matters most
Encryption, access control and audit logging all matter and we do all three. But they are mitigations — the data is still there, and a sufficiently bad day exposes it. That is true of us as it is of anyone.
So the control we lean on hardest is how long the data exists at all. Three days by default, from the end of processing. A conversation that is gone cannot be breached, subpoenaed, or read by an employee who should not have. Every other measure on this page is there to protect it during the window where it does exist.
What protects it while we have it
Encrypted in transit and at rest. Identifiers we detect — phone numbers, email addresses, account and case numbers — are removed or replaced with a one-way token before storage, and every removal is recorded so it can be audited. Detection is strongest on English and Latin-script text.
Message text itself is not redacted, because translating and searching it is the entire purpose of the product. Encryption, named-account access and a short retention window are what protect it.
A small number of named engineers can reach stored conversations. Every access is logged. Support staff cannot read case content.
Translation and the model provider
If you use translation, the messages you select are sent to a model provider under a zero-retention agreement: they are not stored by the provider and not used to train anything. Identifiers are removed first.
We cannot promise that no human at a provider ever sees a message — no one who uses a third-party model can honestly promise that. What we can say is which provider, on what terms, and that you can decline translation entirely and still use the rest of the product.
Where the work happens
Your upload is processed on our own servers, not on your computer. It travels over an encrypted connection, is encrypted again in storage under a key we control, and is reachable only by the people working on your matter.
Your original export stays exactly where you keep it — we work from the copy you send us. That copy, and everything produced from it, is deleted at the end of the retention period you chose.
The account side
For the information we do hold — your email, your plan, your payment record — we use an established identity provider and an established payment processor rather than rolling our own. Card details never touch our systems. Traffic to this site is encrypted in transit.
Reporting a problem
If you believe you have found a security issue, please write to contact@bonafiles.com and give us enough detail to reproduce it. We will acknowledge you, work on it, and we will not take legal action against anyone who reports a genuine issue in good faith and does not exploit it.
Questions about this document? Write to legal@bonafiles.com and a person will answer.
Contact us