Back to home

Privacy Policy

Last updated: April 9, 2026

1. Information We Collect

Account Information: When you create an account, we collect your name, email address, and password (hashed).

Permit Data: We collect project details you provide (address, city, state, project type, square footage, estimated value) to generate permit analysis.

Payment Information: Payment processing is handled by Stripe. We do not store your credit card details. We retain your Stripe customer ID for subscription management.

Usage Data: We collect anonymous usage analytics via Vercel Analytics to improve the service.

2. How We Use Your Information

We use your information to:

  • Provide and improve our permit analysis service
  • Process payments and manage subscriptions
  • Send transactional emails (account confirmation, billing)
  • Analyze usage patterns to improve the product

3. AI Processing

Your project details are sent to third-party AI services (Anthropic Claude) and web scraping services (Firecrawl) to generate permit analysis. This data is processed in real-time and is not stored by these third parties beyond the request lifecycle.

4. Data Storage

Your data is stored securely on Supabase (PostgreSQL) with row-level security enabled. Each user can only access their own data. Generated documents are stored in encrypted cloud storage.

5. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We share data only with:

  • Stripe — payment processing
  • Supabase — database hosting
  • Vercel — application hosting
  • Anthropic — AI analysis (project details only)

6. Cookies

We use essential cookies for authentication session management. We use Vercel Analytics which may set anonymous performance cookies. We do not use advertising cookies.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data
  • Withdraw consent at any time

For GDPR requests, contact us at privacy@permitpilot.com.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion, all personal data is removed within 30 days. Anonymous usage analytics are retained indefinitely.

9. Security

We implement industry-standard security measures including encrypted connections (HTTPS), row-level security, hashed passwords, and secure API key management.

10. Changes

We may update this policy from time to time. We will notify you of significant changes via email or in-app notification.

Contact

Questions? Email privacy@permitpilot.com