Security and data handling
Your data does the work. Then it stops.
You're trusting us with wages, employer names, uploaded HR policies, and a due date. Here is exactly what we do with that information.
Principles
Principle 1
Collect the minimum
We only ask for the data the calculator actually needs. No date of birth, no Social Security Number, no address unless you buy and enter one.
Principle 2
Never sell your data
Not to insurance companies, not to employers, not to lead brokers, not to advertisers. Our revenue comes from customers who buy plans. That is the whole model.
Principle 3
Deletable on request
Email us at [email protected] and we will delete your account and everything tied to it within 7 days. No forms, no runaround.
What we collect, and only when
Data enters our servers only at these specific moments. Before that, your intake answers live in your browser only.
- When you use the free intake
- Your answers stay in your browser's local storage. Nothing is sent to our servers unless you create an account or upload an HR policy.
- When you create an account
- We collect your email address for authentication. We generate a unique user ID. No password is stored because we use magic-link sign-in.
- When you save your intake to an account
- We sync your intake answers to our database so you can return later. Fields include name, state, wages, employer name, due date, employment type, and partner details if you added them.
- When you upload an HR policy
- We store the PDF in Cloudflare R2 encrypted object storage. We use Anthropic Claude via API to extract structured coordination data from the document. The extracted data is stored with your account. Claude does not train on your document.
- When you purchase a plan
- Payment happens on Stripe. We never see or store your card details. Stripe returns a purchase confirmation with your email and the tier you bought. We store that record.
Where your data lives
We use professional infrastructure providers for the parts of our stack that touch your data. Each is contractually SOC 2 Type II certified for their platform.
Supabase (Postgres)
security page ↗Your account, intake answers, purchase records, and account settings. Row-level security policies enforce that only your account can read your rows. Encrypted at rest with AES-256, in transit with TLS 1.3. Hosted in US-East region.
Cloudflare R2 (object storage)
trust hub ↗Your uploaded HR policy PDFs. Server-side encrypted with AES-256. Private ACL: no public URLs. Accessed only by our extraction pipeline via signed request. Auto-deleted 90 days after your plan generation completes, sooner on request.
Stripe (payments)
privacy ↗All card and billing details. PCI DSS Level 1 certified. We never see or store your payment card. We receive back only a confirmation event with your email address and product purchased.
Anthropic Claude (AI extraction)
privacy ↗We send your uploaded HR policy text to Claude for structured extraction. Anthropic's API terms state that inputs are not used for model training. Data is retained by Anthropic for 30 days for trust and safety review, then deleted.
Klaviyo (transactional and marketing emails)
privacy ↗Your email and product events (purchase, milestone reminders) for authentication emails and the optional Welcome sequence. You can unsubscribe from marketing at any time; you cannot unsubscribe from transactional emails (magic-link, purchase receipt) without deleting your account.
Vercel (hosting)
security ↗The website itself. Runs on Vercel's serverless infrastructure. Request logs are retained for 30 days for debugging. We scrub known personally-identifiable fields from logs (email, tokens, session cookies) before they reach any dashboard.
Who can access your data
- You can access all your data at any time by logging in with a magic link to the email you registered.
- Christine and Steven are the only two people who can read customer data. We access it only when you request support that requires us to, and we don't open your row for any other reason.
- Infrastructure providers can access data only to the extent required to operate their platforms, under their published security programs.
- Your employer, HR department, or state agency cannot access any of your data through us. If you want them to, you send it to them yourself using the HR email we generate.
- Insurance companies, benefits brokers, and lead generators receive nothing from us. Ever.
- Advertisers cannot target you based on your intake. We do not run behavioral advertising or share any signal with ad platforms.
Authentication
We use magic-link authentication. When you sign in, we email you a one-time link that expires in 60 minutes and can only be used once. There are no passwords stored anywhere.
- No passwords means no password database to breach
- Sessions expire after 30 days of inactivity
- Auth emails sent via a verified sending domain (Resend) with SPF and DKIM configured
- Suspicious sign-in attempts are rate-limited at the auth service level
Deleting your data
You can request full deletion at any time. We honor the request within 7 business days.
How to request deletion
Email [email protected] from the address associated with your account with the subject Data deletion request. That's it. No form, no phone verification, no waiting queue.
We delete: your account row, your saved intake, your uploaded HR policy PDFs, your parent profiles, your purchase records, your Klaviyo profile, and your Sentry user ID. Anonymized aggregate statistics (which state received the most intake starts, average purchase value by tier) remain in our internal analytics. These cannot be traced back to you.
Payment records with Stripe are retained per their required legal window (7 years for tax and fraud purposes). This is Stripe's data on their infrastructure, not ours, and we do not have discretion over it.
If something goes wrong
We hope nothing does. If it does, here is what we commit to.
- If a security incident affects your data, we will notify you by email within 72 hours of detection and confirmation of scope.
- The notification will name exactly what data was involved, what mitigations we have taken, and what actions you can take (rotate email password, watch for phishing, etc).
- We use Sentry for error monitoring, with PII scrubbing enabled. If a bug ever exposes data to our logs, we get an alert and can respond immediately.
- You can report a suspected security issue to [email protected]. We will acknowledge within 48 hours.
What we are, and what we are not
We are not a covered entity under HIPAA.
We do not receive protected health information from healthcare providers or health plans. We do not need HIPAA compliance because HIPAA does not apply to us. Your due date and event type (birth, adoption, foster) are personal data protected under our privacy commitments below, not health information.
We are not SOC 2 certified.
SOC 2 Type II is on our roadmap for when the business scales, but it is not currently in place. We rely on our infrastructure providers' SOC 2 certifications for the components they operate. When we complete our own audit, we will link the report here.
We are PCI DSS SAQ-A eligible.
All card payment collection happens on Stripe's infrastructure, which is PCI DSS Level 1 certified. Our website qualifies for the simplest merchant category (SAQ-A) because we do not touch card data ourselves.
We are subject to state consumer privacy laws.
California residents have rights under CCPA/CPRA. Colorado residents under CPA. Connecticut residents under CTDPA. Virginia residents under VCDPA. If you exercise any of these rights, email [email protected].
Questions
If anything on this page is unclear, or you want to ask a specific question about how we handle your data, email [email protected]. We answer within one business day.
Related pages: Privacy Policy, Cookie Policy, Terms of Service.