← Back

Privacy Policy

Last updated: July 2026

1. What We Collect

We collect: (a) account information (name, email, firm name) provided at registration; (b) audit data and files you upload to the Service; (c) usage data (page views, feature use) for product improvement; (d) payment information processed by Stripe (we do not store card numbers).

2. How We Use Your Data

We use your data to: provide and operate the Service; send transactional emails (verification, password reset, notifications); process billing; improve the platform. We do not sell your data to third parties.

3. AI Processing

Some features send excerpts of your audit data to the Anthropic API to generate AI-assisted content. Anthropic's data handling is governed by their privacy policy. We recommend not uploading personally identifiable information beyond what is necessary for audit purposes.

4. Data Storage and Security

Data is stored in encrypted PostgreSQL databases (Neon) and file storage (AWS S3, us-west-2). All data is encrypted in transit (TLS 1.2+) and at rest. Access is restricted to authorized personnel and governed by least-privilege policies.

5. Data Retention

We retain your data for the duration of your subscription plus 90 days after cancellation, to allow export. You may request deletion at any time by contacting support.

6. Third-Party Services

We use: Stripe (payments), Resend (email), AWS S3 (file storage), Upstash (rate limiting), Pusher (real-time), Sentry (error monitoring). Each service has its own privacy policy governing their handling of data.

7. Your Rights

You have the right to: access, correct, or delete your personal data; export your firm's data; opt out of non-essential communications. Contact us at privacy@auditai.app to exercise these rights.

8. Cookies

We use session cookies for authentication (NextAuth) and no advertising or tracking cookies. Analytics, if enabled, uses privacy-preserving aggregation only.

9. Contact

Privacy questions: privacy@auditai.app
See also our Terms of Service.