THE DETAILS, IN PLAIN LANGUAGE

Your documents.
Your information.

What the current website and application services handle, and where other providers come into the picture.

Who operates Pellucid

Pellucid is a product of JordanSoft LLC, based in Murphy, North Carolina, USA. Privacy questions can be sent to [email protected].

When you visit this website

The site is hosted on Cloudflare Pages, with Cloudflare R2 configured to host release downloads. Requests to load pages, images, or download files provide Cloudflare with technical information such as your IP address, requested address, request time, and browser information. Cloudflare handles this traffic to deliver and protect the site.

The current site does not include advertising trackers, third-party analytics scripts, contact forms, or a website account system. Fonts are served through your device’s system font stack rather than an external font service. This does not mean the hosting provider receives no request data.

Read Cloudflare’s privacy policy for its handling of information.

Documents in the desktop app

Opening and working on a local PDF does not require uploading that PDF to this website. Local document operations and license verification are separate: the licensing request does not contain your PDF’s contents.

Online integrations are different. If you configure an assistant or use a provider-backed storage workflow, the relevant provider can receive information required for that operation. Don’t assume every application workflow is entirely offline.

Trials, activation, and license verification

The licensing service, hosted on Microsoft Azure, uses installation identifiers and cryptographic installation proofs to issue trials, manage computer activations, and verify access.

For a paid activation, the license key is sent to the licensing service and validated with Lemon Squeezy. The service checks license and purchase records, including purchase dates, update eligibility, and refund or revocation status. Its ledger records license identifiers, installation associations, activation state, trial dates, verification information, and request-replay protection data.

These records support trial continuity, the three-computer allowance, license verification, and recovery. Deactivating a computer does not erase its historical licensing record. The service and hosting infrastructure also process the technical network information needed to handle requests.

Purchases

Lemon Squeezy is the checkout provider and merchant of record. It processes the purchase information needed for payment, tax, receipts, licensing, and refunds under its own terms and privacy policy.

JordanSoft uses relevant purchase and license information to provide access and support. Official purchase links open Lemon Squeezy’s checkout. See Lemon Squeezy’s privacy policy.

Assistant providers and local records

Assistant use requires a configured provider. Prompts, conversation context, document text, rendered page images, and tool results may be sent to that provider as part of an interaction. The information involved depends on the requested task and configuration.

Review the provider’s privacy and retention terms before using confidential documents. Pellucid’s trust and approval controls govern supported actions; they are not a promise that a provider receives no document information.

The revised integrations request disabled Claude ACP session persistence and Codex ephemeral threads, apply documented child-process telemetry/history controls, and disable OpenCode conversation sharing. These controls do not guarantee zero provider retention. Hermes and OpenCode can retain local conversation history; Hermes can also retain content-bearing error dumps. Configured API services have their own retention rules. Pellucid’s diagnostic switch does not disable independently managed provider records or erase existing histories.

The application maintains local settings, license state and a minimized in-memory command history for its workflows. Review any diagnostic files before choosing to share them with support.

Optional local diagnostics

In the revised release under qualification, diagnostic recording is off by default. You can explicitly enable it in Settings → Privacy & diagnostics for the current session. Closing Pellucid resets that choice. Recording writes local troubleshooting files; it does not automatically upload or send them to JordanSoft.

We minimize diagnostic data, but files may still contain personally identifiable information (PII) or other sensitive information. You are responsible for reviewing every file and removing sensitive information before sharing it with support. The revised logger excludes conversation text, document-bearing tool payloads and filenames, and retains structural troubleshooting information such as application failure classifications and timing/count data. This is not a guarantee that every sensitive value can be detected or removed.

Logs are limited to approximately 16 MiB each, normally retaining five recent files through best-effort pruning when recording starts. There is no age-based expiration. Stopping recording does not delete existing files. Logs from older versions may contain more detailed conversation or document information and must also be reviewed before sharing. Independently configured AI providers and your operating system have their own data-handling and diagnostic behavior.

When you contact support

Email support receives your address, message, and anything you attach. JordanSoft’s support mailbox uses Microsoft-hosted email. Include only what is needed to investigate the issue; avoid sending passwords, API credentials, or confidential documents.

If we discover sensitive information in a diagnostic submission, we will immediately stop using it and remove it from active systems we control. Restricted backup and email-provider recovery copies may remain until their retention periods expire; they must not be restored into active use. We will explain any remaining retention limits. Your responsibility to review a submission does not remove our obligations to handle it appropriately.

For purchase or device-recovery requests, we use your purchase email and order record to check ownership.

Licensing history and recovery records

The licensing ledger retains the original trial dates and the paid license’s purchase, coverage, activation, verification, and revocation history. Deactivated installations remain in that history. The current application does not automatically delete these records when a trial or update period ends.

Support-assisted lost-computer recovery records the support case reference, license and installation identifiers, operator, time, and state fingerprints. The recovery audit is retained with the ledger. It does not contain the PDF you were working on.

Short-lived request identifiers prevent replay of licensing requests. The service removes expired identifiers during later successful licensing operations, rather than through a fixed-time background deletion job. Ledger backups can retain earlier copies.

Approved retention schedule

Routine support correspondence is scheduled for deletion 24 months after a case closes. Submitted documents, diagnostic attachments, and working copies are scheduled for deletion within 30 days after closure. A specific ongoing investigation, dispute, or legal requirement can require a limited exception, recorded with a reason and review date. Controlled-file and authenticated mailbox procedures have been rehearsed with owned synthetic data. Customer cases still require individual review; unattended customer-mail deletion is not enabled.

Minimum entitlement, activation, revocation, and recovery history is retained while needed to service the license. Minimum trial history is retained while needed for trial continuity. Necessity is reviewed annually, and individual privacy requests are reviewed for deletion or further minimization. The end of update coverage does not itself end an eligible-version entitlement.

Server operational logs have a 30-day retention target, with limited incident evidence held separately when necessary. Age-based journal retention and scheduled rotation are now configured, alongside size limits that can shorten available history. Legacy logs have a separate scheduled retirement path. This is not a guarantee of deletion at the exact age boundary.

Backups and deletion timing

The licensing ledger is backed up for recovery. Local rolling backup pruning and Azure lifecycle rules are configured for snapshots older than 30 days, including cloud snapshots and previous versions in the managed backup paths. Processing is scheduled, not an instant deletion at the exact age boundary. Local pruning refuses to remove the last retained snapshot when no recent backup is available; that failure requires operator attention.

Azure also has a 30-day soft-delete recovery window. Deleted cloud copies may remain recoverable during that additional period. Deleting a record from the active ledger does not immediately remove its copies from backups, and uninstalling or deactivating a computer is not a service-record deletion request.

Cloudflare, Microsoft, Lemon Squeezy, and any assistant or storage provider you configure have their own retention arrangements. A JordanSoft retention policy cannot erase records another provider is independently required to keep.

Request access, correction, or deletion

Email [email protected] and describe the information or request involved. For a purchase-related request, use the purchase email if available and include the order reference. For a trial-only request, say that you have no purchase record so support can identify the appropriate verification route.

Do not send a license key, password, installation private key, full payment-card details, or a confidential PDF to prove ownership. If you no longer have access to your purchase email, explain that rather than sending more sensitive information.

Requests may concern local information on your computer, JordanSoft service/support records, or records held by another provider. These need different handling. Deleting information needed to verify a license can affect continued activation or recovery; it is not the same as moving an activation slot.

We review requests under the verification, response, deletion, and backup-restoration procedure described below. Applicable privacy rights and response deadlines depend on the request and jurisdiction; this policy does not replace or limit those rights.

Response targets and operational limits

Our approved internal targets are to acknowledge a privacy request within five business days and complete the response within 30 calendar days, subject to any applicable shorter deadline or lawful extension. If an extension is needed, it must be explained within the applicable deadline. These targets do not reduce your legal rights.

The operating procedure requires proportionate identity verification, a minimal case record, documented decisions, and reconciliation of approved erasures before a restored backup is returned to service. Protected case backups, independent privacy-decision authority, controlled-file suppression and guarded restoration have been deployed and rehearsed with synthetic records. Minimal suppression decisions are retained as needed to prevent erased material returning through restoration; they are protected records, not assumed anonymous data.

Trial-only support verification checks possession of an existing installation key and a trial record as of a verified backup. It does not prove legal identity or authorize deletion by itself. Scoped mailbox access and removal have been rehearsed with owned synthetic records; customer cases require individual review. Provider recovery copies can remain accessible to privileged administrative tools after removal from ordinary mailbox access. Unsupported destructive ledger erasure or trial reset is refused. We explain any retention or deletion limits when handling the request.

Questions?

Contact JordanSoft LLC at [email protected].