How we handle your data
Zero document retention architecture
Your documents are NOT stored on our servers. Documents are processed in real-time during each processing run, then immediately deleted. Zero document retention.
Processing results are encrypted with YOUR unique customer-specific keys and stored in YOUR Google Drive AppData (not our servers). You control access and can revoke permissions anytime.
Borrower names, addresses, SSNs, financial data, and other sensitive information from loan documents are NOT stored on our servers. All data is encrypted and stored in YOUR Google Drive.
We NEVER use your documents or extracted data for AI model training. Third-party AI services are contractually prohibited from using your data for training and process data ephemerally.
Minimal data necessary to provide service
Email address, name, and Google account ID when you sign in with Google OAuth.
Billing handled by Stripe (PCI-compliant). We store only your Stripe customer ID - never credit card numbers.
Your customer-specific encryption keys are stored in YOUR Google Drive AppData folder. Keys are automatically rotated after every processing run. We can't access your encrypted data without your Google OAuth permissions.
Encrypted processing results (dashboard data, extracted information) are stored in YOUR Google Drive AppData. All data encrypted throughout the entire process with your unique keys.
Document counts, processing times, API calls for billing and service monitoring. No document content is logged.
Error logs, performance metrics, and system diagnostics. Logs are retained for 30 days maximum.
If you enable Google Drive integration, we store encrypted OAuth tokens to access your designated Drive folder. You can revoke access anytime.
We will never use your data for marketing, advertising, or sell it to third parties.
Services we use to operate
PCI-compliant payment processor. See Stripe's privacy policy at stripe.com/privacy.
OAuth authentication and optional Drive API access. See Google's privacy policy at policies.google.com/privacy.
We use proprietary algorithms and signal systems to ensure data accuracy and quality. Third-party AI services are SOC 2 Type I and Type II certified, contractually prohibited from using your data for training, and process data ephemerally with encryption in transit.
We do not sell or share your data with any other third parties.
Control your data
Request a copy of your account data via email to [email protected]
Delete your account anytime from Dashboard → Settings. All data deleted within 24 hours.
API responses and Google Sheets integration provide real-time export of all processed data.
Disconnect Google Drive integration anytime from Dashboard → Settings → Google Drive.
Don't use the service = no data collected. Zero retention means no ongoing data storage.
Zero retention architecture ensures compliance. You have rights to access, deletion, portability, and restriction of processing.
We do not sell personal information. California residents have rights to know what data is collected, delete data, and opt-out.
Zero-retention architecture with customer-specific encryption. All data encrypted throughout the entire process. Encryption keys automatically rotated after every processing run. OAuth tokens stored with AES-256 encryption. All data in transit encrypted via HTTPS/TLS. See /security for full details.
View Security DetailsWe may update this policy as our service evolves. Material changes will be announced via email 30 days before taking effect. Continued use after changes constitutes acceptance.
Need help?
Email our legal team at [email protected] and we'll get back to you within one business day.
We respond within one business day.