Legal

Privacy Notice

Effective July 24, 2026

Pre-activation notice

No account, upload, payment, or subscription service is currently available. Final customer terms become operative only when production activation is completed and an account is expressly accepted.

1. Scope and controller

This notice describes how the CertDraft beta operator processes personal information in the CertDraft private beta. Contracting association-management customers control the document sets they upload; we process those files to provide the service.

2. Information we process

We process verified account identity, tenant membership and role, subscription references, document-job metadata, source documents and ledgers, derived OCR and coordinates, source indexes, cited or flagged field results, customer/counsel corrections, formula inputs, approvals, outputs, usage, and content-safe audit events. Stripe processes raw payment-card data.

3. Purpose

  • Authenticate users and enforce product, tenant, and role separation.
  • Validate, OCR, extract, verify, review, approve, render, retain, and delete customer-directed drafts.
  • Operate subscriptions, usage limits, support, security, and legal compliance.
  • Diagnose service health using events that never contain filenames, source contents, answers, prompts, or quotes.

4. Service providers

Vercel, Convex, WorkOS, Amazon Web Services, Stripe, and Resend provide hosting and content-safe runtime logs, the isolated database and durable processing, authentication, private storage/OCR/model processing, billing, and email. Provider access is limited to the configured service purpose.

5. Retention and deletion

Private-beta access requests are retained for no more than 90 days. CertDraft customers select 7, 30, or 90 days after completion; 30 days is the default. Deletion revokes application access immediately and schedules active and recoverable backup copies for purge within eight days. After the final job purge, standalone Auth identities are removed; an identity that still belongs to another live workspace is retained. A content-free completion record may remain for 24 months.

6. Security

Controls include verified-email authentication, mandatory TOTP, server-side tenant authorization, a separate Convex deployment and encrypted CertDraft bucket, short-lived URLs, strict file validation, capability-scoped tasks, exact citation and derivation checks, revision-aware approval, and immutable content-safe audit history. No system offers absolute security.

7. Rights and choices

Authorized Owners and Admins can select retention, export eligible outputs, delete jobs, and request tenant deletion. Individuals may contact support@certdraft.com for applicable access, correction, deletion, or restriction requests; requests may be referred to the customer controlling the data.

8. Contact

Email support@certdraft.com. Paid production checkout remains disabled until the operator mailing address is disclosed.