FaxMyDoc
Security

What we hold, and for how long

You may be uploading a tax return, a medical form or an identity document. The honest way to earn that is to hold as little as possible, for as short a time as possible, and to say precisely what that means.

The short version

Your document
Deleted 24 hours after transmission completes
An abandoned upload
Deleted within 2 hours, whether or not you paid
Card details
Never touch our servers — Stripe handles payment
Account
There isn't one. No password to breach
Transmission record
Kept, and contains no document content
Document hashes
Kept — 64 characters that identify a file without revealing it

In transit and at rest

Uploads travel over TLS and are stored encrypted in a private bucket. No public link to a customer document is ever created. When the fax network needs your pages it is given a URL that is signed for a single attempt and expires in minutes.

Deletion is a job, not a promise

The document is destroyed on a timer after your transmission settles, and each deletion writes an audit row recording what was removed and when. A second sweep runs hourly and catches anything the timer missed. An upload you abandoned before paying is covered by the same sweep — the promise was made before you decided, so it holds either way.

What survives is the record: the destination, the page count, the timestamps, the network transaction ID, and the two hashes. That is enough to prove what happened and not enough to reconstruct what you sent.

Why the hashes matter

Before your file is deleted we compute a SHA-256 of the original and of the exact pages transmitted, and both go on your record. You keep the sensitive document; we keep a fingerprint of it. If you ever need to show that the copy in your files is the one that went, the record ties them together without us having retained anything.

Payment

Card details are entered into Stripe and never reach us — we do not see, store, or transmit them. Your card is authorized when you press send and charged only after the receiving fax system confirms. Nothing is stored for a future charge, because there is never a future charge.

Healthcare and other regulated use

We do not market this service as HIPAA compliant and you should not treat it as such. We have not put the vendor agreements, policies and operational practices in place that would support that claim, and we would rather say so than let the omission pass. If you are a covered entity sending protected health information, use a service that will sign a business associate agreement.

What we ask of you

  • Check the destination number against the letter or form you are responding to — we send wherever you tell us, and a confirmed transmission to the wrong office is still confirmed.
  • Do not use this service for unsolicited fax advertising. See the acceptable use policy.
  • Keep your own copy of anything you send. We delete ours on purpose.

Reporting something

If you find a security problem, write to support@faxmydoc.com and say so in the subject line. A person reads it. Related reading: the retention policy, the privacy policy, and acceptable use.

Last reviewed September 10, 2026