1. Who we are
Otterdeck ("we", "our", "us") operates the Otterdeck service at https://otterdeck.io. This policy explains how we collect, use, and protect your data.
2. Data we collect
- Account data: email address, name, business name, and password (hashed — never stored in plaintext).
- Proposal data: project descriptions, client names, pricing, and proposal content you create.
- Invoice data: invoice amounts, due dates, notes, and the client email address invoices are sent to. Invoice PDFs are generated on-demand and not stored permanently.
- Usage data: pages visited, features used, and error reports — collected for product improvement.
- Newsletter data: if you subscribe to our newsletter, your email address and the date you consented. We use it only to send occasional product and pricing emails, and you can unsubscribe at any time via the link in every email.
- Payment data: subscription billing is handled by Stripe. We store only your Stripe customer ID — never your card number. Note: Stripe is used for Otterdeck subscription payments only. We do not process payments between you and your clients.
- Event data: when clients view, accept, or decline proposals, and when invoices are opened. IP addresses are one-way hashed (SHA-256) before storage and cannot be reversed.
- Contract data: if you use Contract Review, the contract files you upload and the text extracted from them are stored (encrypted at rest) so we can analyse them and show you the results. You can delete a contract and all of its analysis at any time. The public Contract Checker tool stores no contract content and does not identify you — the file and its text are analysed in memory and discarded. We keep only anonymous usage metrics (a timestamp, the risk level, the document's word count, and a one-way hashed IP) to monitor the tool's volume and reliability; these cannot be linked back to you or to any contract.
- Signature data: if you use E-Signature, we store the signer's name and email, the document sent, the signing status, and the completed signed document with its audit trail.
3. How we use your data
- To deliver and improve the Otterdeck service.
- To send transactional emails (proposal notifications, billing receipts).
- To generate AI proposals and analyse contracts using Anthropic's Claude API — your project descriptions and contract text are sent to Anthropic for processing. Anthropic does not use data submitted through its API to train its models. See Anthropic's Privacy Policy.
- To send documents for electronic signature via DocuSeal, when you use E-Signature.
- To detect fraud and enforce our Terms of Service.
4. Data sharing
We do not sell your personal data. We share data only with:
- Supabase — database and authentication hosting.
- Anthropic — AI proposal generation and contract analysis (not used to train models).
- DocuSeal — electronic signature processing (only when you use E-Signature).
- Stripe — payment processing.
- Resend — transactional email delivery.
- Sentry — error monitoring (anonymized stack traces).
- Vercel — application hosting and serverless functions.
5. Data retention
We retain your account, proposal, and invoice data while your account is active. After account deletion, data is removed within 30 days, except where retention is required by applicable law (e.g., financial and tax records). Invoice records may be retained for up to 7 years for legal compliance purposes — you can export them at any time via Settings → Export Data before deleting your account.
6. Your privacy rights
Depending on applicable law in your jurisdiction, you may have the right to:
- Access — request a copy of your personal data via Settings → Export Data.
- Deletion — delete your account and all associated data via Settings → Delete Account.
- Portability — export your data in JSON format at any time.
- Correction — update inaccurate personal data in your account settings.
- Opt-out — unsubscribe from non-essential communications via Settings → Notifications or the unsubscribe link in any marketing email.
- Non-discrimination — exercise any of the above rights without receiving diminished service.
To exercise rights not available through self-service tools above, email support@otterdeck.io. We will respond within the timeframe required by applicable law.
7. Cookies
We use only essential cookies required for authentication (managed by Supabase). We do not use advertising or tracking cookies.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed using bcrypt. We conduct regular security reviews and never store sensitive credentials in client-accessible code.
9. Changes to this policy
We will notify you by email at least 14 days before material changes take effect.