Skip to content
Bowstack
Your data

What leaves, what doesn't, and what we won't claim.

Written to be checkable rather than reassuring. If any sentence here reads two ways, tell us and we will fix it.

The flow, end to end
  1. 01

    Your computer

    You select a PDF. Text is extracted in the browser with PDF.js. The PDF file itself never leaves the machine.

  2. 02

    Bowstack service — Google Cloud Run

    The extracted text is sent to our access-controlled service. It is processed in transit and not intentionally persisted. Access logs may retain metadata such as timestamp, status and latency.

  3. 03

    Hosted language model

    The text is sent to the model to be turned into structured fields, with store: false set on the request. We have not opted into any training programme. The provider's own abuse-monitoring logs may retain content for up to 30 days.

  4. 04

    Back in your browser

    Parsed values are held in memory for the current tab only and shown to you for review. Closing the tab clears them. Nothing is written to your job until you approve it.

Controls
The PDF never leaves your computer
Text is extracted in your browser with PDF.js. The file itself is never uploaded to us or to anyone else.
The extracted text does leave — here is where it goes
It is sent through our access-controlled service on Google Cloud Run to a hosted language model, which returns structured fields. We state this plainly, because a vendor who is vague about it is hiding something.
We never train on your data
Not a toggle. The API request sets store: false, and we have not opted into any training programme.
No credentials, ever
Bowstack works inside the session you are already signed in to. It never sees, stores or transmits your username or password.
Nothing is submitted on your behalf
Fill-only by design. Every Save, Commit and Mark as Final is a human decision — which is also what makes it defensible to your insurer partners.
No analytics, no advertising, no resale
There is no telemetry in the extension. Your claim data is not a product we sell, profile, or share beyond the processors named in our privacy policy.
What we will not claim

Published deliberately. If another vendor tells you any of the following, ask them to put it in the contract.

  • “Your data never leaves your computer”

    The PDF does not. The text extracted from it does. Conflating those two is the most common misleading claim in this category, and we will not make it.

  • “We are compliant with Alberta PIPA”

    Compliance is a status your shop holds, not one a vendor can hold for you. We can describe our data flow accurately so your own assessment is easy; we cannot confer a status.

  • “Certified” or “bank-grade security”

    We hold no certification for this product. Naming actual controls is more useful than a phrase that invites a questionnaire we would then have to survive.

  • “Guaranteed accurate extraction”

    No language model guarantees that, which is exactly why Bowstack is fill-only and shows you every value before it is written.

Under review

We are auditing our own request logs, error traces and retention settings, and will update this page and the privacy policy with what that audit finds. We would rather publish a correction than leave a claim standing that we have not verified. Last reviewed 31 July 2026.

Ask the hard one

Bring your toughest data question.

The specific ones are the good ones: this carrier, this document, this obligation. Those are the conversations worth having.

Bowstack is independent software. Not affiliated with, endorsed by, or sponsored by Mitchell International, Inc. or Enlyte. “Mitchell Connect” is referenced only to state what Bowstack is compatible with.