Terms of Use and Data and Privacy Policy
THIS SOFTWARE IS UNDER DEVELOPMENT AND TERMS AND CONDITIONS ARE DRAFT, USAGE IS CURRENTLY ONLY ALLOWED FOR TESTING PURPOSES.
Terms and Conditions
0. Scope
This tool is currently only intended for the usage by data editors and repositories to evaluate data that are already public, or are imminently about to be made public.
1. Acceptance of terms
By registering for an account or otherwise using PII Checker, operated by David Valenta, University of Ottawa, you agree to these terms and to the data handling described in the sections above. If you do not agree, do not use the service.
2. Acceptable use
PII Checker is provided for screening research data for personally identifiable information prior to publication, sharing, or use. You agree that you:
- are authorized to upload and process the data you submit;
- will not use this service to attempt to identify, locate, or single out any individual, or otherwise collect personally identifiable information;
- will not attempt to disrupt or circumvent the rate limits, quotas, or other technical controls of this tool;
- will not use this service to process data on behalf of a third party without that party's authorization to do so.
3. Ownership of uploaded data
You retain all rights to the data you upload. PII Checker claims no ownership interest in it. As described above, the underlying data and the classification reasoning generated from it are not retained beyond the windows stated in this policy, and are not used for any other purpose.
4. No warranty
PII Checker is under active development. Classifications are produced by a language model and are probabilistic, not a certification; they are provided to assist review, not to replace it. The service is provided "as is," without warranty of correctness, completeness, availability, or fitness for any particular compliance requirement.
5. Limitation of liability
To the maximum extent permitted by law, PII Checker and its operators are not liable for any damages — direct, indirect, incidental, or consequential — arising from use of the service, including reliance on a classification result.
6. Indemnification
You agree to defend, indemnify, and hold harmless PII Checker and its operators from any third-party claim, demand, loss, liability, or expense (including reasonable legal fees) arising from your use of the service — including, without limitation, from your decision to publish, share, or otherwise release a dataset after using the service, regardless of the classification result produced. As stated above, the service is a screening aid, not a certification; the decision to publish or share any dataset, and responsibility for any resulting exposure of personally identifiable information, remains yours.
7. Availability and termination
The service may be unavailable at any time, for any reason, without advance notice. An account may be suspended or terminated at our discretion, including for violation of the acceptable-use terms above.
7. Governing law
These Terms are governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Subject to any mandatory applicable law, the parties irrevocably submit to the exclusive jurisdiction of the courts of Ontario, Canada, and any action, suit, or proceeding arising out of or relating to these Terms shall be brought exclusively in Ontario, Canada.
8. Changes to these terms
These terms may change as the system changes. Material changes to retention behavior or acceptable use will be reflected on this page; continued use of the service after a change constitutes acceptance of the revised terms.
Data and Privacy Policy
What is uploaded
When a package is uploaded, PII Checker stores the raw archive on disk, extracts it into a working directory, and screens every column of every supported data file for personally identifiable information. Screened columns judged worth checking are sent — as a tabulation of their values, not the original file — to a language model for classification.
What is deleted, and when
- The uploaded package is deleted the moment its processing job reaches a final state — completed, failed, or cancelled — regardless of outcome. There is no delay.
- Extracted working files are deleted at the same point, for the same reason.
- The values and reasoning behind each classification are written only to the downloadable report (Excel file). The report is kept for one week before it is automatically deleted permanently. It can be deleted at any time by the user, and doing so removes the file immediately.
- Cancelling a running job deletes any partial report immediately and unconditionally — a cancelled job never leaves a partial result behind to be downloaded later.
As an additional safeguard, an automated check runs periodically to confirm scheduled deletions actually completed — catching rare cases like a crashed process. This is a backup, not the primary deletion method.
What is not done with your data
- Uploaded data and the tabulations sent for classification are not used for any other purpose than to evaluate presence of PII.
- Data is not shared with any third party.
- In PII Checker's reference deployment, classification is performed by an open source model (Gemma 4) we operate using our servers hosted on the Google Cloud infrastructure. The data is not evaluated using API of a third-party vendor such as Anthropic or OpenAI.
Account information
Creating an account stores your email address, a securely hashed password, and the full name, organization, position/title, and intended use case you provide at registration. This information is retained for as long as your account exists, and the full name/organization/position/use case are visible to the administrator who reviews your registration request (see "Account approval" below). You can delete your account yourself at any time from the account settings page (see "Your controls" below), which removes this information immediately.
Account approval
New accounts are not active immediately. Registration requests are reviewed by an administrator before an account can log in; you'll be notified that your account is pending if you attempt to log in before that review is complete. A rejected request is not deleted - the account record is kept, inactive, for audit purposes - but it will not be able to log in.
Rate limits and account activity
Upload, download, and login activity are rate-limited to prevent abuse. Usage activity records are kept to enforce these policies.
Your controls
- You can delete any package and its files at any time, whatever its status.
- You can cancel a package while it is actively processing; this stops the job and deletes any partial output.
- You can edit your full name, organization, position/title, and use case, and change your password, from the account settings page (the gear icon next to your email once logged in).
- You can delete your own account at any time from that same page, without contacting anyone. Deletion is immediate and permanent: your account, all of your uploaded packages, and all of your results are removed at once — there is no waiting period and no way to undo it. You'll be asked to type your email address to confirm before it happens.
Data processing location
Data is processed and stored on Google Cloud servers located in Canada. This is subject to change as the system's infrastructure evolves.