Integrity Scan: processing stays on-device
When you select a file in the public scanner, your browser reads that file on your device. Ocolta does not receive the document bytes, values you enter into the math or cross-document checks, the resulting findings, or the SHA-256 file fingerprint. Results remain in page memory until you close or refresh the page. A report is saved only when you choose to download it to your device.
AI Deep Review: explicit upload and model processing
AI Deep Review is separate from Integrity Scan and does not begin until you select a supported file and accept the current versioned upload disclosure. The selected file, filename, and file type leave your device and go to Ocolta's Cloudflare Worker. Turnstile also sends its security token and standard request information, including the connecting IP address, to Cloudflare for abuse verification. Ocolta validates and scans the file in memory, then sends the full file and, for PDFs, the filename to OpenRouter for a model review requested as openai/gpt-5.6-terra. OpenRouter routes the request to a compatible downstream model endpoint. Use this feature only when you are authorized to share the file through that chain, and remove personal data the review does not need.
Ocolta does not save the submitted AI-review document or provide a cloud document library. The immediate response includes the deterministic scan and its combined assessment; the 24-hour recovery copy omits both, including the scan's structured filename, file type, size, and SHA-256 fields. The recovery copy contains the normalized model-authored report and, for Deep Review+, its corroboration appendix, plus the server-recorded consent version and time and safe requested/served provider, model, usage, and cost metadata when supplied. The appendix can retain model-extracted institution names, printed business addresses, domains or payroll descriptors, and public-source outcomes and URLs. Model-authored text and the appendix can repeat information visible in the document, so the recovery copy must not be treated as content-free merely because the scan fields are absent. Recovery access ends 24 hours after delivery and is available only to the browser holding the secure purchase-access cookie. Bounded maintenance clears the expired report payload; transaction and entitlement rows remain, and physical database-space reclamation can occur later. Responses use no-store browser-cache headers. A downloaded JSON copy is under your control.
OpenRouter routing and retention controls
Every production OpenRouter request requires a downstream endpoint that advertises Zero Data Retention, denies data-collecting endpoints, supports every requested parameter, uses the default service tier, and stays within Ocolta's configured per-token rate ceilings. Those controls restrict endpoint selection; they do not impose a total token or dollar cap and do not pin one downstream company. The delivered report records the downstream provider and served model only when OpenRouter reports them.
OpenRouter states that it does not retain prompt or response content unless prompt logging is enabled for the account, while it retains non-content request metadata such as model, token counts, latency, and cost. The per-request routing controls do not themselves prove the account-level logging setting, so do not treat this public service as contractually guaranteed end-to-end Zero Data Retention without written confirmation. Eligible downstream endpoints remain subject to their legal and safety obligations. Do not submit prohibited content or data whose policy requires a specifically named processor, region, or signed retention commitment.
Document requests: collecting a file from someone else
A document request is different from every other Ocolta workflow, because the person who supplies the document is not the person using Ocolta. A requester enters their own email address, the recipient's email address, an optional name, an optional reference, and an optional note. Ocolta emails the recipient a private upload link on the requester's behalf, with the requester's address shown as the sender of the request and set as the reply-to address. Notes may not contain links, and no account is created for either party.
When a recipient uploads a file, the document is transmitted to an Ocolta server and the Integrity Scan runs there rather than in the recipient's browser. This is deliberate: the requester is relying on the result, so it cannot be computed on the device of the party whose document is being checked. The scan produces structural findings and a SHA-256 fingerprint of the file.
Retention is the requester's choice, and it is off by default. With retention off, Ocolta scans the document and discards the bytes; it keeps the filename, size, content type, SHA-256 fingerprint, and findings during the bounded request-results window. With retention on, the bytes are additionally stored in encrypted object storage. Download access ends fourteen days after upload. An hourly Worker sweep then deletes eligible objects; a checked-in fourteen-day R2 lifecycle configuration is provided for an operator to apply as an independent backstop, but this source audit did not verify that lifecycle as active in production. Physical deletion is asynchronous and can occur after the access cutoff. The recipient sees the applicable path before uploading.
Upload, requester-results, and file-download access end thirty days after request creation or immediately on cancellation. Ocolta's request-database rows for request/contact data, file metadata, fingerprints, and findings become eligible for bounded-batch deletion fourteen days after that link access closes; physical deletion can occur later under retry or backlog. Each request has separate upload and requester tokens, and the database stores only their hashes. A database read alone cannot reconstruct either link. For newer requests, the Worker can rederive the requester token using its deployment secret so a delivery email can link to results; anyone holding an active link can use it.
Request and delivery emails pass through Resend. A delivery email can contain the requester and recipient addresses, filename, score or priority label, scan summary, flagged-finding titles, and an active requester link. The request-database purge does not delete copies already held by Resend or in sender and recipient mailboxes; those copies follow the provider's retention and the mailbox holder's controls.
Ocolta does not use returned documents for analytics, advertising, or model training. A request is not a background check: Ocolta reports structural signals about a file and does not make, or assist in making, a decision about a person. Ocolta is not a consumer reporting agency and its output is not a consumer report.
Optional Google Analytics
Google Analytics runs only after you accept optional analytics. It measures selected public page visits and navigation links using cookies that expire after 90 days. We exclude private application pages, document-processing routes, query strings and fragments, and do not send form values or document contents. Automatic form, search and download tracking and advertising personalization are disabled. Use Analytics choices to decline or withdraw; withdrawal stops collection and removes Google Analytics cookies. Global Privacy Control and Do Not Track override acceptance.
Website request data
Cloudflare hosts the site, Worker, database, object storage, Turnstile, and cookieless Web Analytics and may process standard request information needed to deliver and protect them, such as IP address, timestamp, requested path, device or browser information, and security events. Stripe processes checkout; Resend processes document-request email contents; OpenRouter and a policy-eligible model endpoint process AI-review documents. Deep Review+ may send an institution-typed name and that institution's printed business address to Exa when configured; a public RDAP service receives a printed institution domain used for domain-registration lookup. These are the intended categories, but automated extraction and classification can be wrong; remove personal data the review does not need. Ocolta does not use document contents for advertising or model training.
Messages you send
If you email Ocolta, the message, address, and information you include are processed to reply and maintain a business record. Do not email applicant documents, credentials, or unredacted financial information. Business correspondence may be retained while relevant to the request and legal or security obligations.
Payment processing
AI Deep Review checkout is hosted by Stripe. Stripe receives the payment, contact, device, and transaction information needed to process the purchase, prevent fraud, and provide a receipt under its own privacy terms. Ocolta receives transaction identifiers, payment status, amount, currency, and limited checkout metadata used to grant one review; Ocolta does not receive or store full card details.
Cookies and local storage
The standalone public website and its public tools do not create an Ocolta account or advertising profile. The pay-per-use workspace uses strictly necessary, secure HTTP-only cookies to connect Stripe checkout returns to the same browser, track purchased reviews, and recover a completed report during its 24-hour window. Because there is no account, purchase access is not transferred across devices; clearing Ocolta site cookies can remove browser access. If paid access is missing, contact Ocolta with the Stripe receipt and do not email the document. Ocolta stores hashed purchase-access tokens, transaction state, and the temporary normalized report—including any Deep Review+ corroboration appendix—in its hosted database; it does not store the selected document or provide a persistent report library.
Choices and requests
You can use Integrity Scan without choosing AI Deep Review. You can cancel an AI review request while it is in progress, although cancellation may not reverse processing already completed by a provider. Closing or refreshing Integrity Scan clears its result; AI Deep Review can recover its normalized result, including any Deep Review+ corroboration appendix, in the purchasing browser for up to 24 hours. You control and can delete any report downloaded to your device. For questions or a request concerning information in an email or business record, contact hello@ocolta.com. Identity verification may be required before fulfilling a request.
Changes
Ocolta will update the effective date and this page before materially changing how either review workflow handles document data. Future cloud storage or shared-workspace features will not inherit the local scanner's “zero document upload” statement; their specific data flow and retention controls must be disclosed separately.