Template, have a lawyer review before use. This draft is written in plain language for a prototype and has not been reviewed by counsel.

Privacy.

What we store about you, who can see it, how long it is kept, and how to have it deleted.

Last updated September 2026. Facts about storage and access are the ones on the trust page; where the two differ, the trust page is the one kept current.

1. What we store

Account. Your email address, display name, a hash of your password, when the address was verified, and sign-in sessions (14 days each). Password reset and verification links are stored as hashes and expire.

Deals and documents. The files you upload, the text and cells read from them, the claims, metrics, decisions, scenario runs, reports, and chat threads built from them. Storage keys are generated by the server; nothing is addressed by a name you chose.

Audit history. Who did what in a deal and when: uploads, deletions, decisions, exports, member changes, and every assistant reply. Members' actions are recorded under their own account.

Purchases. For a pilot, the amount, currency, status, and Stripe's session and payment identifiers. Card details never reach our server; Stripe handles them.

Usage. Counts of assistant answers per month and per deal, tokens and tool calls, and document sizes, to enforce quotas and estimate cost.

2. Who can see it

The owner of a deal and the members the owner invited, each within their role. Nobody else in the app: another account asking for your deal gets “not found”. The operator of the deployment can reach the database and storage as any operator can; there is no admin view in the product.

A connected model provider receives claim text, evidence snippets, and the deal brief for chat, and document text if the reader is switched to a model. The provider and model are named in the panel. Free tiers may use inputs to improve the provider's products; a paid pilot runs on a paid tier. Stripe receives what a payment needs. Resend, when configured, receives the address and content of verification, reset, and invite emails.

3. How long we keep it

Documents in a signed-in account are kept until you delete them; there is no automatic purge and no backup, so the server holding your files is the only copy. Demo identities, deals, and files are deleted 14 days after the visitor's newest session expired. Audit rows for a deal live as long as the deal. Purchase records are kept for accounting.

4. Deleting

Deleting a document removes the file, every stored version, the evidence read from it, and the claims that came from it with their links and decisions; the audit history keeps the fact that it was deleted, with the name and time. Deleting a deal removes everything in it. To delete an account, write to us and we remove the account, its deals, and its files; purchase records stay for accounting.

5. Cookies and storage in your browser

One session cookie keeps you signed in. The browser also remembers small preferences (the collapsed navigation, the model you picked, the last conversation) in local storage. There is no analytics or advertising tracking.

6. Security

Passwords are hashed, sessions expire, deal access is checked on every request, uploads are validated and read within size budgets, and documents are never executed. The full list of controls and the reporting address are in the repository's security policy. No system is free of risk; the trust page states the limits plainly.

7. Your rights and contact

You can see and export what a deal holds from the app, correct your display name, and ask for a copy or deletion of your account data. Write to the contact address on the pilot page. Depending on where you live, data-protection law may give you further rights; this template does not name a legal basis or a supervisory authority, which is one of the things a lawyer should add.