Privacy Policy
Last updated July 11, 2026
What we collect
Account details (name, email, company), the compliance records and files you upload, standard server logs (IP address, browser, pages requested), and the usage analytics described below. Payment details are handled by Stripe and never touch our servers.
Cookies and analytics
We use cookies that are necessary to run the service — session and security (CSRF) cookies that keep you signed in. In production we also use Google Analytics, which sets its own cookies to help us understand how visitors find and use the site (pages viewed, approximate location, device type). We use this only to improve the site — not for advertising, and we do not sell analytics data.
You can opt out of analytics at any time: turn off analytics for this site (the choice is stored in your browser and takes effect on your next page view). You can also use Google's browser opt-out add-on or block analytics cookies in your browser; the service works fully without them. Google's handling of this data is described in its own privacy policy.
How we use your information
To run the service: storing your evidence vault, generating packets, sending deadline reminder and account emails, providing support, and keeping the service secure. We do not sell your data, share it for cross-context behavioral advertising, or use it for advertising of any kind.
Service providers (subprocessors)
We share data only with the providers needed to operate the service:
- Stripe — payment processing and billing.
- Resend — sending transactional email (reminders, receipts, account messages).
- Cloudflare — file storage (R2) for your uploaded evidence, plus DNS and email routing.
- Google Analytics — site usage analytics, as described above.
Each provider receives only what its function requires and is bound by its own contractual and legal obligations. We will update this list if our providers change.
Storage and security
Data is stored on managed infrastructure in the United States. Uploaded files are stored in access-controlled object storage and served through expiring signed links. Access to production systems is restricted and credentialed.
Retention and deletion
Because CHRO requires records to be retained for at least two years after it issues a Notice of File Closure letter, we keep project vaults intact by default — that retention is the point of the product. You can request full deletion of your account and data at any time by emailing [email protected]; we will delete it unless we are legally required to keep specific records (for example, billing records).
Your rights
You can access, correct, export, or delete your information — most of it directly in the app, or by emailing [email protected]. We do not sell personal information and have not sold it in the preceding 12 months, so there is nothing to opt out of. Depending on where you live (including under the Connecticut Data Privacy Act), you may have additional statutory rights; we honor requests to exercise them at the same address, and we will not discriminate against you for doing so.
Security incidents
If a breach affects your personal information, we will notify you and the relevant authorities as required by applicable law, without undue delay.
Children
The service is for businesses and is not directed to children. We do not knowingly collect information from anyone under 16.
Changes to this policy
We may update this policy as the service evolves. For material changes we will notify you by email or an in-app notice before they take effect. The "Last updated" date above always reflects the current version.