What we hold, who reads it, where it lives, and how you take access back.
What we hold
Your account: how you sign in (an Apple or Google identity), your birth date, country, language and an email when you gave one. Your orders, each with the brief your agent sent and the document written for it. Your credit, with its deposits and charges, and the receipts. The agents you have allowed. That is all. We hold no name for you, and a professional never sees an email.
Health data
A brief carries what a professional must know to adapt to you: the answers to a short health declaration, and any diagnoses, medications and injuries you told your agent about. That is health data, and under GDPR it needs your explicit consent. You give it once, when you create your account, to the version of the health data notice in force at the time. One professional reads it, for that order, under a pseudonym. The notice is at the link below.
Where it lives, and how it is kept
Everything is stored in the EU. Connections are encrypted. Briefs, drafts and documents are sealed in the database with a key kept outside it, so a copy of the database cannot be read; we can unlock them, because a professional must be able to read your brief. Receipts are kept seven years, as bookkeeping law requires. Everything else is erased when you delete your account.
Your assistant's access
When you connect an agent, it gets a token for your client side only: it can order, read orders and see your credit. It cannot pay, cannot change your account, cannot see how you sign in. Tokens expire and are renewed while the agent is in use. You revoke an agent on your account page, and its access ends at once.
Who reads an order
Every professional is vetted and approved by us before they see an order. One professional takes an order, reads its brief under a pseudonym, writes, and delivers; the document is checked against its template and our rules before you get it. We, the operator, can see counts, statuses and money, and no action on our side returns a brief or a document. That is a rule in the code, not a promise.
Payments
Mollie handles the payment. It sees the amount and what your card or bank gives it. We never see your card, and Mollie never sees your brief. A receipt is mailed to you for every deposit.
Who else handles data
Who handles a part of your data on our behalf, and what each receives.
Fly.io
Hosts the service in Amsterdam, in the EU. Holds the sealed database and the server.
Mollie
Payments, from the Netherlands. Receives the amount, the currency and what your card or bank provides. Never the brief.
Resend
Mail. Receives your address and the text of the receipt and of the notice that a document is in. Never the brief or the document.
Apple and Google
Sign-in. We receive a stable identity and, when you allow it, your email. They receive nothing about your orders.
For organisations
When an organisation's product orders for its users, we hold for each user the birth date, country and language it gave us and the orders, under the organisation's own id. No name, no email. The organisation sees status and money, never the document. A data processing agreement is available on request.
Report a concern
Found something, or want to know more? Write to the address in the footer with security in the subject. You get an answer from a person.