Privacy
Privacy policy
What we collect, what we don't, how long we keep it, and how to ask us to delete it.
Draft v0.1 — pre-launch draft
This policy describes how we intend to operate and is published for transparency while we're still pre-launch. The final, binding version will be reviewed by counsel before the application opens to customers.
1. What we collect
From the public site (revrecengine.com):
- Page-view analytics via Plausible — cookieless, IP-anonymized, GDPR/CCPA-compliant by default. No cross-site tracking, no individual user profiles.
The marketing site itself does NOT collect any personal data from you — no signup form, no email capture, no contact form posting to our servers. Reach out via X DMs or the email address on the contact page if you want to talk before launch.
From inside the product (app.revrecengine.com) when you sign up:
- Account info — email address, name (optional), organization name, password hash (or OAuth identity, depending on sign-in method).
- Your data— the contracts you upload, your billing/CRM/GL data we sync from connected platforms, the journal entries and workpapers we generate from them. This is the substance of the product; it's yours.
- OAuth tokens for connected third parties (Stripe, QuickBooks, HubSpot, etc.). Encrypted at rest via Supabase Vault; never logged or returned in API responses.
- Operational logs — request paths, error traces, anonymized performance metrics. Required for debugging and uptime.
We do not collect: SSNs, financial-account credentials (we use OAuth, never passwords), location data, biometrics, device fingerprints, or anything via third-party trackers.
2. How we use what we collect
- To operate the product — extract ASC 606 treatment from your contracts, generate schedules and journal entries, sync to your GL, produce workpapers.
- To communicate with you — service emails (a contract finished processing, an approval needs your attention), transactional notifications, and the occasional product update. You can opt out of non-essential email from inside the app.
- To improve the product— aggregate, anonymized usage patterns (e.g., “how many contracts per org typically use variable consideration”). Never individual-identified data.
- To comply with the law— respond to lawful requests, fulfill tax obligations, defend legal claims. We'll tell you about any request unless legally prohibited.
3. AI providers — we do not train models on your data
RevRec Engine uses Anthropic's Claude to read your contracts. Our API calls to Anthropic use the equivalent of anthropic-no-train settings — your contract text and the resulting analysis are not used to train any model, ours or Anthropic's.
Anthropic retains API request data for a limited period for abuse-detection purposes per their commercial terms. We don't share customer identity with Anthropic; the API call contains only the contract text.
4. Cookies and tracking
Public site: no tracking cookies. Plausible is cookieless. We do not run Google Analytics, Facebook Pixel, LinkedIn Insight, or any cross-site tracker.
Product (app):we set a session cookie for authentication and CSRF protection. That's it. No third-party cookies inside the product either.
5. Sub-processors — who else touches your data
To operate, we use the following sub-processors. Each is contractually obligated to protect your data under their own security commitments (SOC 2, ISO 27001, or equivalent). See our Security page for the authoritative current list.
- Vercel — hosting, edge network, CDN
- Supabase — Postgres database, authentication, file storage
- Anthropic — Claude API for contract extraction (no training)
- Resend — transactional email delivery
- Plausible — privacy-friendly analytics (public site only, cookieless)
We'll update this list when sub-processors change. For paid customers, material additions will get advance notice.
6. How long we keep your data
- Active account data— for the life of your account. Your contracts, schedules, journal entries, and workpapers stay accessible while you're a customer.
- Deleted account data — we hard-delete within 30 days of account closure and confirm in writing. After deletion, your data is unrecoverable from backups within an additional 30 days (standard backup-retention cycle).
- Aggregate analytics— anonymized counts may survive deletion (e.g., “3 organizations had this contract shape last quarter”) because they don't identify you.
- Legal-hold exceptions— narrow cases where we're legally required to keep specific records (e.g., tax invoices). These are deleted as soon as the obligation expires.
7. Your rights
Regardless of where you live, you can:
- Access the data we have about you — export from inside the app at any time, or email us.
- Correct inaccurate data — edit it in the app, or email us.
- Deleteyour account and your data — from inside the app, or email us. We'll hard-delete within 30 days.
- Export your data in a portable format (CSV, JSON, .docx for workpapers).
- Objectto specific processing — tell us and we'll explain what we can stop doing while keeping the product useful to you.
If you're in the EU/UK (GDPR) or California (CCPA/CPRA), you have additional rights, including the right to lodge a complaint with your data protection authority. We process all requests within 30 days at no cost. Email us at the address below to invoke any right.
8. Security
We use TLS 1.3 in transit, AES-256 at rest, Postgres row-level security for tenant isolation, and Supabase Vault for OAuth tokens. The full picture — including incident response and SOC 2 progress — lives on our Security page.
If you discover a security issue, please report it before disclosing publicly. Contact info below; we aim to respond within 24 hours.
9. Children
RevRec Engine is for business use. We don't knowingly collect data from anyone under 18. If you believe a child's data has been provided to us, contact us and we'll delete it.
10. International data transfers
Our infrastructure is hosted in the United States. If you're outside the US, using the product means your data is transferred to and processed in the US. We implement standard contractual protections with our sub-processors for cross-border transfers. When we expand to EU-hosted infrastructure (planned post-GA), we'll update this section.
11. Changes to this policy
We may update this policy from time to time. The “last updated” date below always reflects the current version. For material changes, we'll notify you by email and/or an in-app notice before they take effect. If you don't agree with a change, you can delete your account before it takes effect; otherwise continued use means you accept the updated policy.
12. Contact
For anything privacy-related — questions, data requests, complaints, or just curiosity — email us. We read every message and reply personally.
Privacy questions, requests, or complaints
chris@revrecengine.comWe aim to acknowledge within 24 hours and resolve formal requests within 30 days.