CComplyAssist
Privacy policy

Privacy Policy

Effective July 2, 2026 · ComplyAssist (complyassist.ai) · Contact: support@complyassist.ai

The short version

ComplyAssist stores the documents you choose to certify, your review decisions, and your account details — and nothing it doesn't need. Your documents are never used to train AI models, never sold, and never shared except with the service providers listed below. Deleting a certification deletes its stored files, and you can ask us to delete your whole account at any time.

What we collect

  • Account details — your email address and password (stored as a hash by our authentication provider), and the reviewer profile you enter: reviewer name, bar number / license ID, and firm name.
  • Your documents — the PDFs you upload (or push through a connected app such as Claude), the source documents and URLs you attach, the items and claims extracted from them, and your review decisions and signatures.
  • Certification records — when you sign a certification, we record your typed signature, the time, and your IP address and browser identifier as part of the tamper-evident record.
  • Usage and billing data — AI-extraction usage against your plan allowance, plan tier, and payment status. Card details go directly to Stripe; we never see or store your card number.
  • Standard technical logs — server logs (IP, request path, time) kept briefly for security and debugging.

We use no advertising trackers. Cookies are used only to keep you signed in.

How we use it

Only to run the service: extracting checkable items from your documents, powering the review workspace, generating your certification records, metering plan usage, billing, support, and keeping the service secure. We do not sell personal data, do not share it for advertising, and do not use your documents to train AI models.

AI processing

When you upload or push a document, its text is sent to a large-language model to extract citations, references, or claims. This goes through Vercel's AI Gateway with zero data retention — the model provider processes the text to return the extraction and does not retain it or train on it. Extraction is the only AI step; your review, marks, and signatures never leave ComplyAssist.

Where your data lives

Documents and records are stored in a private, access-controlled database and file store hosted by Supabase in the United States, encrypted at rest and in transit. Every record is scoped to your account — other users can never access your documents.

Service providers (subprocessors)

VercelApplication hosting and AI Gateway (zero-retention AI processing).
SupabaseDatabase, authentication, and encrypted file storage (US region).
StripePayment processing. Card details are handled entirely by Stripe.
ResendTransactional email (sign-up confirmations, password resets).

Each provider processes data only to deliver its function for us. We share nothing with anyone else unless required by law.

Connected apps (the Claude connector)

If you connect an app such as Claude, it receives a revocable access token scoped to creating certifications and reading their status only — it can never sign, delete, change your account, or access billing. We store only a cryptographic hash of the token. We never receive your Claude (or other app) login, and the connected app never receives your ComplyAssist password. Documents a connected app pushes are treated exactly like documents you upload. Revoke any connection at Account → Connected apps.

Retention and deletion

  • Documents and certifications stay until you delete them. Deleting a certification deletes its stored PDF and source files.
  • Your account — email support@complyassist.ai to delete your account and all associated data. We complete deletion requests within 30 days.
  • Billing records are retained as required by tax and accounting law.

Security

Encryption in transit and at rest, row-level access control on every record, private owner-scoped file storage, one active login per account, and hashed credentials and tokens throughout. If we ever become aware of a breach affecting your data, we will notify you without undue delay.

Your rights

You can access and export your data from the app (your documents and records are downloadable), correct your profile in Account, and request deletion or a full copy of your data by emailing support@complyassist.ai. Depending on where you live (e.g. GDPR, CCPA, PIPEDA), you may have additional statutory rights; we honor them regardless of jurisdiction.

Changes

If this policy changes materially, we'll note the new effective date here and notify active accounts by email. ComplyAssist is a workflow and record-keeping tool, not a law firm, and does not provide legal advice.