Back to homepage

Stript as a technical and organizational measure (Art. 32 GDPR)

The document for your internal sign-off. Introducing Stript in a firm, practice, or company means answering two sets of questions: your data protection officer’s and your IT or vendor assessment’s. This page answers both. You are welcome to adapt the text for internal use.

Note: This document is factual information about Stript’s architecture and a drafting aid. It is not legal advice. The data protection assessment of your specific case remains yours and your DPO’s.

The core statement in one paragraph

Stript is a local desktop application that detects personal data in documents and replaces it with placeholders before a text is given to an external AI tool. All document processing (analysis, anonymization, restoration) happens exclusively on the user’s device. Document content is never transmitted to the vendor or to any third party. Using Stript is therefore data minimization at the source: what leaves the device toward an AI service no longer contains real names.

Where this sits under the GDPR

Why no data processing agreement is needed for document processing

A data processing agreement under Art. 28 GDPR is required when a third party processes personal data on your behalf. With Stript, no such processing by the vendor takes place: the application runs entirely locally, like a word processor, and document content never reaches the vendor’s servers. Where no processing by a third party occurs, no processor relationship arises. This distinguishes Stript from cloud-based anonymization services (including those hosted in Germany), where the document is uploaded for processing and a DPA is therefore required.

For the few peripheral processes that have nothing to do with document content, including Free Evaluation activation and aggregate grant synchronization, purchase and licensing, updates, and optional crash reports, the vendor’s Privacy Policy applies.

Vendor-assessment answer sheet

The typical questions of a vendor or tool assessment, with the answers that apply to Stript:

Assessment questionAnswer for Stript
Where are documents processed?Exclusively on the user’s device. No upload, no cloud processing.
Where are documents stored?Locally on the device and encrypted with AES-256-GCM. Keys are held in the operating system keychain. The user can delete documents at any time.
Which subprocessors have access to document content?None. Document content does not leave the device.
Is a DPA under Art. 28 GDPR required?Not for document processing, since no processing by the vendor takes place (see above).
Is document content transferred to third countries?No.
Which network connections does the application make?A one-time AI model download, Free Evaluation activation and periodic aggregate grant synchronization, separate Pro license verification, an update check, an update download only at the user’s initiative, and optional crash reports that are off by default. None contains document data. Details appear in Section 2.6 of the Privacy Policy.
Can this be verified?Yes. Document processing works offline, and network activity can be inspected with built-in tools or Little Snitch and Wireshark. Walkthrough: How to verify our claims.
Is there telemetry or usage data?Stript does not receive document or activity telemetry. For the Free Evaluation, it synchronizes only the aggregate used count from zero to five, pending reservation count, and signed security state. Optional crash reports require explicit opt-in and contain no content or identifiers.
How is accountability supported?The application keeps a tamper-evident processing log based on a hash chain and containing no content data. Mapping tables can be exported and demonstrably destroyed with a destruction certificate.
What is the human’s role?Every detection is reviewable by the user before anonymization. The user can confirm, reject, reclassify, or adjust the threshold. The application never decides alone.

Suggested wording for your records of processing / TOM list

“Before external AI services are used, documents are processed with anonymization software running locally on the device. Personal data is detected, reviewed by the operator, and replaced with consistent placeholders. Only the cleaned text is passed to the AI service. The mapping table remains encrypted with AES-256-GCM on the device and is not transmitted to third parties. The software transmits no document content to its vendor. Document processing runs locally and can be verified to work offline.”

Limits you should know

Honesty is part of a defensible TOM description:

As of July 2026. This document is maintained. The current version lives at this address.