Where a dropped file goes
This is the path that runs when you drop a file to make a report. Posh refuses an empty file. Posh refuses a file larger than 10 MB.
The server reads the file before it is saved. The PDF itself is sent to Posh AI. After the report is written, the server also reads a PDF's text to check each fact against it; that text is not stored and not sent anywhere. An image is sent the same way, as the image itself. For every other file, Posh takes the text out of the file and sends that text. If that text is longer than 80,000 characters, Posh AI receives the first 80,000 characters, plus a note that the text was cut. The message also names the file and its format.
Posh AI runs on a model provided by Anthropic, a US company. Posh calls it so it can write the report.
Several files dropped together are zipped and read as one pack. A pasted Google Sheets, Docs, or Slides link is downloaded from Google by the server, only from docs.google.com, and then read like an uploaded file. A scheduled report does the same on its day.
What Posh keeps depends on the account and on which storage is configured.
- If you are not signed in, Posh does not save the file and does not save the report. The file is still sent to Posh AI. If the database is configured, Posh can also write a usage row. That row stores the model, the format, token counts, and how long the call took. It does not store the file.
- If you are signed in and the database is not configured, Posh does not save the file and does not save the report. The file is still sent to Posh AI.
- If you are signed in, the database is configured, and the account has a monthly report limit that is already used, Posh stops before it saves the file and before it calls Posh AI.
- If you are signed in and the database is configured, and that limit has not stopped the request, Posh saves the report in Neon Postgres. The code does not name a region for that database. If the account has no active paid plan, and the person is not Posh staff, the stored report is cut to one section and 800 words. Otherwise the stored report is the text Posh AI returned. That cut applies to the stored report. It does not shorten a stored copy of the file. Posh can also write a usage row with the model, the format, token counts, and duration. That row does not include the file.
On that signed in save, the original file is stored in one of these ways.
- If the file is named pasted.txt and its type is text, the text is stored in the database. It is not uploaded to Vercel Blob.
- For any other file, if Vercel Blob is configured, the bytes are uploaded there. The file storage code says that store is provisioned in syd1. The upload sets access to public. Posh later reads the file back from that link without a Posh session, so anyone with the link can open the file. The database stores the link, the file name, the type, the size, and a content hash.
- If Vercel Blob is not configured, or the upload fails, Posh still saves a database record for the file and still sends the file to Posh AI. The stored link is empty.
If the finished result is missing, Posh deletes the new report record. The database record for the file stays. A Blob file, if one was uploaded, stays. If that save throws, Posh logs the error and leaves the report record in place.
A signed in owner can run the report again from the saved source. If the source is a file, Posh fetches the Blob link. If that link is missing, the run stops. If the source is text, Posh reads the text from the database. Either way, a successful run sends that material to Posh AI again.
Clips
A signed in person can also save a clip image. That save requires the database and Vercel Blob. The image goes to Vercel Blob with the same public access. Composing a report passes each clip image to the same Posh AI model, using the Blob link, with a text excerpt of up to 800 characters. Deleting a clip removes the clip row. It does not remove the Blob file.
What the privacy page and the security page say about training
That upload does not send a training setting to Anthropic. The privacy page and the security page say the same. Neither page claims what Anthropic keeps. This page does not add a separate check of the current terms published by Anthropic.
How long it stays
This code does not choose a number of days and then delete the file or the report. There is no scheduled deletion of uploads or reports in the app.
A report record stays until it is deleted. A signed in owner can delete it as described below. The upload path also deletes a new report record when the finished result is missing. Those deletes do not remove the uploaded file.
How a signed in owner deletes a report
You must be signed in, and you must own the report.
On the open report, Delete removes the report record. The same action is the Delete button on a library row, and Remove from library in the library card menu. The schema removes highlights and notes on that report with the record. The report leaves your library. The database record for the file stays. Earlier copies of the generated report stay in the database. The Blob file stays.
In the library card menu, Delete report only removes the generated report, the earlier copies of that report, and the highlights and notes. The library record stays. The original file stays, in Vercel Blob or as text in the database.
The code includes a function that can delete a Blob object. None of these delete actions call it. There is no separate control in this code that deletes the stored upload on its own.
Wording you can paste
The Tax Practitioners Board guidance TPB(GS) 55/2026 was issued on 22 July 2026. It says a tax practitioner must not disclose information relating to the affairs of a client to a third party without permission from that client, unless a legal duty requires the disclosure. It says this can include putting client information into an AI tool, depending on how the tool is configured and used. It recommends saying who will receive the information, where it will be stored, and that an AI tool may be used. It says permission can be an engagement letter, a signed consent, or another communication. It also says a general authority to disclose information to third parties may be acceptable.
The draft below is written in the voice of the practice, not of Posh. It describes the path on this page. It is not a Board template. It does not say that your practice meets the guidance. Edit it before you use it.
We may upload a file that contains your information to Posh so Posh can prepare a report. Posh reads that file on its server. It sends the file, or text taken from the file, to Posh AI, which runs on a model provided by Anthropic, a US company, to write the report. If we are signed in and the Posh database is configured, Posh stores the report in Neon Postgres. No region for that database is named in the app. If our account has no active paid plan, and the person using it is not Posh staff, the stored report is cut to one section and 800 words. That cut applies to the stored report. A stored copy of the file, when there is one, is the full file. If the file is named pasted.txt and its type is text, Posh stores that text in the database and does not upload it to Vercel Blob. For other files, if Vercel Blob is configured, Posh stores the file there with public access. The file storage code says that store is provisioned in syd1. Anyone with the link can open the file. Deleting the report in Posh does not delete the stored file. The privacy page says the app does not send a training setting. It does not say what Anthropic keeps. You can tell us to stop, and we will not upload further files that contain your information.