# Data handling

> What touches a document between upload and redline, and what is kept afterwards: the deterministic engine, training, human access, zero-day retention, and where it runs.

Law firms send privileged documents through this API. This page says exactly what happens to
a document from the moment it is uploaded, what does not happen to it, and what is left
afterwards. The compliance side (SOC 2 Type 2, encryption, penetration testing) is on the
[Security page](/security).

## What happens to a comparison

1. `POST /v1/compare` stores the two files in S3, encrypted at rest.
2. The comparison engine, a rules-based program written in Rust, computes the redline. It is
   deterministic: the same two versions always produce the same redline.
3. The renderings you asked for (Word with tracked changes, PDF, changed pages only, Markdown,
   JSON) are written to S3.
4. `GET /v1/compare/{comparison_id}` mints signed download URLs, each valid for one hour.

No language model is involved in any of these steps, and nothing about the documents' contents
is logged for AI. Version Story is not an AI application. It is an application that AIs and
people can use.

## AI is off by default

Nothing goes through a model unless your organization asks us to turn on an AI feature. Two
exist: AI conversion of scanned PDFs, and Analytics reports. Neither is on for a new
organization, and neither is used by compare, merge, or version history. With them off, which
is the default, no document you send ever reaches a model.

## Training and human access

- Nothing you upload is used to train or improve any model, ours or a vendor's.
- No person reads your documents to produce a redline. There is no human review step, no
  contractors, and no crowd workers anywhere in the process.
- Access by Version Story staff is role-based and recorded in audit logs.

## Retention

By default, a comparison's documents and redline are kept so you can come back for fresh
download URLs. Organizations that would rather keep nothing turn on **zero-day retention** on
the web app's **Developer** page.

With it on, every new `POST /v1/compare` comparison is deleted permanently once you have its
result: the source documents, the redline, and every rendering. Only a record that the
comparison existed remains. Deletion happens at whichever comes first:

- **One hour after the comparison finishes.** Each download's `expires_at` is that deadline.
- **When you acknowledge the download** with
  [`POST /v1/compare/{comparison_id}/acknowledge`](/developers/rest/compare#zero-day-retention).
  Call it as soon as you have saved what you need.

After deletion, `GET /v1/compare/{comparison_id}` answers `410 CONTENT_DELETED`. The setting is
stamped onto each comparison when it is created, so turning it on or off never changes
comparisons that already exist. It applies to `POST /v1/compare` only, not to merges.

In the web app, documents stay in your workspace until you delete them, and organization admins
can set automatic deletion for inactive projects.

## Where it runs

- Comparisons run on AWS inside a private VPC.
- Files are held in S3 only while they move between services, encrypted in transit (TLS) and
  at rest (AES-256).
- Two regions. US organizations use `api.versionstory.com`; UK organizations use
  `api.uk.versionstory.com`, and their documents stay in the UK region.

## Agreements

Our [terms of use](/legal/terms) and [privacy policy](/legal/privacy) cover confidentiality.
Firms that need their own agreement for privileged work can have one; write to
[security@versionstory.com](mailto:security@versionstory.com).

## Related

- [Security](/security)
- [Formats & limits](/developers/reference/formats-and-limits)
- [Compare](/developers/rest/compare), including the zero-day retention endpoints
