Privacy Policy

Last updated: March 11, 2026

1. Information We Collect

We collect information you provide directly: account details (name, email), documents you upload, extraction configurations, and corrections you make. We also collect usage data: extraction counts, feature usage, device information, IP addresses, and browser type. When you connect Gmail, we access email metadata and attachments based on rules you configure.

2. How We Use Your Information

We use your information to: (a) provide and improve the Service; (b) process document extractions using AI; (c) learn from your corrections to improve extraction accuracy for your account; (d) communicate with you about the Service; (e) monitor usage for billing and plan enforcement; (f) detect and prevent fraud or abuse.

3. AI Processing

Documents you upload are processed by AI models (including third-party AI services such as Anthropic's Claude and Google's Document AI) to extract structured data. Document content is sent to these AI providers solely for processing and is not used to train their models. We retain AI processing results to improve your extraction accuracy over time.

4. Data Storage and Security

Your documents and data are stored on secure cloud infrastructure (Supabase). We use encryption in transit (TLS) and at rest. Access to your data is restricted to authorized personnel only. We implement industry-standard security measures including access controls, audit logging, and regular security reviews.

5. Data Retention

We retain your documents and extraction data for as long as your account is active. You can delete individual documents at any time. Upon account deletion, we permanently remove your data within 30 days. Some anonymized, aggregated data may be retained for analytics purposes.

6. Data Sharing

We do not sell your personal information. We share data only with: (a) service providers necessary to operate the Service (cloud hosting, AI processing, authentication); (b) when required by law or legal process; (c) to protect our rights or safety; (d) with your explicit consent. All service providers are bound by data processing agreements.

7. Gmail Integration

When you connect Gmail, we access your email only through rules you configure (sender filters, subject filters, label filters). We process only email attachments that match your rules. We do not read email body content beyond what is necessary for rule matching. You can disconnect Gmail at any time, which immediately stops all email access.

8. Cookies and Tracking

We use essential cookies for authentication and session management. We may use analytics cookies to understand how you use the Service. You can control cookie preferences through your browser settings.

9. Your Rights

You have the right to: (a) access your personal data; (b) correct inaccurate data; (c) delete your data; (d) export your data in a portable format; (e) object to processing; (f) withdraw consent. To exercise these rights, use the account settings page or contact us at nechemiaai@gmail.com.

10. International Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses where required.

11. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children. If we discover we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use after changes constitutes acceptance.

13. Contact

For privacy-related questions, contact us at nechemiaai@gmail.com.