Privacy statement

Prototype-phase · 2026-07-13 · pending counsel review

A plain, honest description of what data we hold, where it lives, and who can see it — written for a reader, not a court. It will be reviewed by counsel before production use.

What data we hold

The documents your organisation uploads (payment applications, budgets, contracts, correspondence and similar), the data we extract from them, and the operational metadata needed to run the platform — who uploaded what, when, and the audit trail of changes.

Where it lives

In our own Amazon Web Services account, in the US East region, encrypted at rest with keys we control. It is not stored on any third party's product or platform.

How AI is used

We use AI models to read and structure documents. Every model call runs on Amazon Bedrock inside the same AWS account as your data. No document or extracted value is sent to any consumer AI product or to any endpoint outside that boundary. Under the AWS Service Terms, your inputs and outputs are not used to train any model and are not shared with model providers.

Who can see it

Only named, authenticated users your organisation has authorised, and the operator's personnel who run the platform. Access passes through a reverse proxy (Cloudflare) that decrypts traffic at its edge to apply security controls and then re-encrypts it to our origin; no document content is stored at that edge.

How long we keep it

For the life of the engagement. Audit logs are retained under lock for accountability. You can ask us to delete your data — see below.

What we do not do

We do not sell your data. We do not use it to train models. We do not share it with advertisers or data brokers. There are none involved.

Deletion & contact

To request deletion of your data, or to ask any privacy question: [email protected].