Attachment Binder privacy
Effective September 1, 2026
Data processed and stored
We store an installation ID and Airtable base ID; selected table, record, and field IDs; source filenames, attachment IDs, declared sizes, order, and a source hash; job status and verified write-back attachment ID; and Cazimedia billing customer, subscription, and entitlement identifiers. Signed Airtable attachment URLs are stored only while a merge runs and are then removed. PDF bytes are processed transiently. The merged output is stored for no more than 24 hours.
Purpose
We use this data only to validate and merge the selected PDFs in order, deliver the result for write-back, verify completion, prevent duplicate work, enforce safety limits, provide support, and manage the Attachment Binder subscription.
Retention and deletion
Source URLs are removed when a job becomes ready, succeeds, or fails. Merged outputs and job records expire after 24 hours. Authenticated account controls permanently delete installation data after any active subscription is cancelled.
Processors
Cloudflare hosts the Worker, Durable Object rate limiter, Queue, D1 database, R2 temporary output storage, and operational logs. Stripe processes subscription billing. Airtable hosts the extension and source attachments. We use Turnstile for one-time activation bot checks. We use no analytics, advertising, tracking, or AI service.
Security
Attachment Binder never requests or stores an Airtable API token. Write-back runs in Airtable under the current user's permissions. Records are isolated by installation, database queries are parameterized, source hosts and redirect destinations are allowlisted, public and expensive routes are strictly limited, Stripe webhooks require signatures, and billing and download links are short-lived and scoped.
Privacy requests: [email protected]