Legal

Security at Posh.

What the code does with a file, and what this page does not claim.

Last updated: 2026-09-28

The short versionA dropped file is sent to Posh AI. If you are signed in and file storage is configured, the upload is stored with a public link. Anyone with that link can open the file. This page does not claim a certificate or a reply time.

File links

When Vercel Blob is configured, a file other than pasted text is uploaded with public access. The file storage code says that store is provisioned in syd1. Posh reads the file back from that link without a Posh session. The database stores the link.

Pasted text named pasted.txt stays in the database. It is not uploaded to Vercel Blob.

Who can open a report

The app checks the owner before it shows a saved report, renames it, or deletes it. A share link is a separate token. Anyone with that token can read the report. The schema file in this repo does not turn on row level security.

Sign in

Sign in is Clerk. This code does not store its own password. It does not describe how long a Clerk session lasts.

The model

Posh AI runs on a model provided by Anthropic, a US company, and calls it to write the report. The call does not send a training setting. This page does not claim what Anthropic keeps. That was not checked against Anthropic's current terms.

Other companies

  • Anthropic receives the file, or text taken from the file, so it can write the report.
  • Neon Postgres stores the report when you are signed in and the database is configured. This code does not name a region.
  • Vercel runs the app. Vercel Blob stores uploads when that token is set.
  • Stripe processes a card when checkout is connected. The database can store a Stripe customer id. It does not store a card number.
  • Resend sends a shared report email only when a sender address is saved. Sign in email is not sent by this code.
  • Google serves a pasted Sheets, Docs, or Slides link. Posh only fetches docs.google.com links, and every redirect must stay on a Google host.
  • Vercel Cron starts scheduled reports once a day. The job runs only with a secret that Vercel sends.

The same list, with the delete path, is on the privacy page and where your files go.

What this page does not claim

  • It does not name a TLS version, and this app does not set a strict transport header.
  • It does not claim encryption at rest, a backup schedule, or a failover time.
  • It does not claim SOC 2 or ISO 27001.
  • It does not promise a reply time for a vulnerability report.

Reporting a problem

This site does not list an email address. This page does not promise when you will hear back.

Ready when you are
Drop a file. Get a report.
Try Posh →