Data processing and account security.
This page explains the technical boundary for private tool accounts. It is a public service description, not a signed data processing agreement.
Last updated September 6, 2026
What account sync covers
Google sign-in is optional. Signed-out visitors can use every available tool locally.
When a signed-in visitor chooses account sync, we store only the structured fields that the source-controlled tool schema classifies as cloud data. Drafts and completed records use the same field rules.
Each account is personal and private. We do not offer shared organizations, invitations, team roles or operator impersonation.
What stays on the device
- Uploaded file bytes and local evidence files.
- Filenames, file hashes and file metadata.
- Extracted text and imported datasets.
- Generated documents, spreadsheets, PDFs and ZIP packs.
- Tool-finder searches and unmatched queries.
These items remain in browser storage or the files you download. Family exports combine cloud-safe records with local-only material inside the browser.
Account controls
- Every draft and record uses a revision number to detect conflicting edits.
- Repeated requests use idempotency keys so a retry cannot silently create another record.
- Deleted records remain recoverable for 30 days unless the account holder permanently deletes them sooner.
- The latest 20 versions remain available for up to 90 days.
- A streamed JSON account export goes directly to the account holder’s browser.
- Account deletion revokes managed-tool access immediately and queues new workspace content for deletion within 24 hours.
Operator access
Authorized operators receive metadata-only views for account status, record counts, storage use, schema versions, timestamps, trash counts and background-job health.
Those views cannot retrieve record answers, drafts, filenames, finder searches or generated outputs. Operators cannot edit customer answers or impersonate an account holder.
Operator actions require an allowlisted Google account, recent reauthentication, a recorded reason and an audit event.
Review reminders
Review timing is stored as a month. The service treats the final calendar day of that month in the account timezone as the operational due date.
In-account reminders remain visible. Email reminders are off by default. If enabled, the email is generic and excludes tool names, record names and answers.
Service providers
Vercel hosts the website and server functions. Neon hosts private structured account data. Clerk and Google provide account authentication. Paddle handles paid checkout as merchant of record. Resend will deliver optional reminder email only after its sending domain and no-cost service configuration pass production checks.
We do not send managed records to an AI model or use them to train an AI system.
Questions and agreements
The privacy notice explains purposes, retention, rights and international processing. Contact hello@businesscompliancetools.com about a privacy request or a proposed data processing agreement.