The Burn After Reading Policy
Encrypted. Printed. Posted. Deleted within 24 hours.
We believe your documents belong to you. Once we’ve done our job, your file has no reason to exist on our systems.
What the Burn After Reading Policy means for you
Every document uploaded to PostMyDoc goes through a strict 3-step process.
Upload
You upload your PDF securely through our encrypted checkout. Your document is transmitted using 256-bit SSL encryption, the same standard used by banks and financial institutions. Nobody can intercept it in transit.
Prepare & Dispatch
Your document is printed once by our team and prepared for dispatch. It is never shared, stored unnecessarily or viewed beyond what is required to complete your order. It is then sealed and posted via Australia Post to your recipient.
Delete
Within 24 hours of your order being completed, your document is permanently and automatically deleted from our systems. No copies are retained. No backups. No archives. Gone.
We Print. We Post. We Delete.
Why we built it this way
PostMyDoc exists to handle documents that matter: legal correspondence, medical records, financial statements, formal notices, personal letters. These are not files you want sitting on someone else’s server.
For businesses handling client-sensitive documents, like legal firms, medical practices and financial advisors, the Burn After Reading Policy provides the document security assurance your compliance requirements demand.
Most digital services retain your data indefinitely. We built PostMyDoc differently from the ground up. The Burn After Reading Policy isn’t a feature we added, it’s a core architectural decision baked into how the service works.
Your privacy is our promise.
How it works, the technical details
For customers who want to better understand the implementation, those little technical details.
Encryption in transit
All file uploads use HTTPS with 256-bit SSL encryption. Your document cannot be intercepted between your device and our server.
Secure storage
Uploaded documents are stored in a restricted server directory that is not publicly accessible. Files cannot be accessed via direct URL, they require authenticated server-side access only.
File type validation
Only PDF files are accepted. File type is validated server-side, not just in the browser, before any upload is processed.
Automated deletion
A scheduled automated process runs every 24 hours and permanently deletes all uploaded documents associated with completed orders. This is not a manual process. It happens automatically regardless of whether our team takes any action.
No third-party access
Your documents are never shared with third parties, advertising networks or data brokers. The only external service that processes your order data is Stripe for payment, and Stripe never receives your document.
What we do keep
In the interest of full transparency, here is what we do retain after your order is complete.
We do not retain your document. Ever.
A note from our founder
“We built PostMyDoc because we needed this service ourselves and couldn’t find it. We know what it feels like to trust a company with something important. That’s why the Burn After Reading Policy isn’t just a marketing line, it’s a commitment we’ve built into the technical architecture of the service itself.”
Jonelle R, Founder, PostMyDoc
Questions about privacy and security
Can PostMyDoc staff read my document?
Our team prints your document as part of the order process. Beyond what is necessary to print and prepare your document for posting, your file is not viewed, shared or stored. It is deleted within 24 hours.
What if I need to send the same document again?
You would need to upload it again. We do not retain copies of previous documents. This is by design.
Is my payment information secure?
All payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. PostMyDoc never stores your full card details.
What happens if my order is incomplete or payment fails?
In the event of an incomplete or failed order your uploaded document is still deleted within 24 hours. We do not retain documents for incomplete orders.
Is PostMyDoc compliant with Australian privacy law?
Yes. PostMyDoc operates in accordance with the Australian Privacy Act 1988. Our full Privacy Policy is available here.
Still have more questions? Visit our FAQs page, or reach out using our Contact form.
The Burn After Reading Policy applies to every order
Whether you send via the website or the PostMyDoc app, every order is encrypted, printed once, and permanently deleted within 24 hours.
Encrypted. Printed. Posted. Deleted within 24 hours.