Solely to operate the Service: monitoring disputes, generating response evidence and rebuttal letters, submitting them to Stripe, showing your dashboard, and sending you service emails (dispute alerts, password resets, backups). We do not sell personal data and we do not use your data to advertise to anyone.
Rebuttal letters may be drafted by an AI model (Anthropic's Claude) using the dispute details and the business information you provided. This content is sent to Anthropic for processing under their commercial API terms; it is not used to train their models under those terms.
We share data with no one else, except where required by law.
One cookie: a signed session cookie that keeps you logged in. No analytics or advertising cookies, no cross-site tracking.
Account, workflow, and dispute data are retained while your account is active, because dispute history informs future cases. Encrypted database backups are kept on a rotating 14-day schedule. When you delete your account (or ask us to), we remove your data from the live database; it ages out of backups within the rotation window.
All traffic is encrypted in transit (HTTPS). Passwords are hashed with scrypt; API keys are encrypted at rest; sessions are revoked when a password is reset; credential endpoints are rate-limited. No system is perfectly secure — report concerns to the address below.
You can access and update your business data in the dashboard at any time. Email us to request a copy or deletion of your data. Depending on where you operate, you may have additional statutory rights (e.g., GDPR/UK GDPR, CCPA); we will honor verified requests.
If this policy changes materially we will notify you by email or in the dashboard before the change takes effect.