Privacy Policy
Last updated: July 29, 2026
This Privacy Policy describes how DefensibleHR LLC ("Company," "we," "us," or "our") collects, uses, and protects information when you use our AI-powered compliance scanning assistant platform, DefensibleHR.ai, and related services (the "Services"). Because our Services involve processing sensitive workplace documents, we take your privacy and data security seriously.
1. Scope
This policy applies to all users of DefensibleHR.ai, including visitors who use our free compliance scan, registered account holders, our website, application, and API. It does not cover third-party services that may integrate with our platform, each of which maintains its own privacy policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Full name and email address
- Company or organization name
- Hashed password (we never store plaintext passwords)
- Billing information processed through Stripe (we do not store credit card numbers)
- Terms of Service and Privacy Policy consent timestamp and IP address (recorded when you agree during signup)
2.2 Free Scan Information
If you use our free compliance scan without creating an account, we collect:
- Email address (required)
- Name and company name (optional)
- IP address
- The filename of the document you upload
- The risk level and issue count from your scan results
- Terms of Service and Privacy Policy consent timestamp and IP address
This information is stored in our leads database. We use it to deliver your scan results, prevent abuse of the free scan feature, and contact you about DefensibleHR.ai services. We do not store the full scan results or the extracted document text for free scan users — only the summary metadata listed above. The same document processing and AI disclosure practices described in Section 3 apply to free scans.
2.3 Uploaded Documents
You may upload workplace documents including investigation reports, termination letters, performance improvement plans (PIPs), and HR memos. These documents may contain:
- Employee names and personal information
- Allegations, complaints, and investigation findings
- References to protected characteristics (age, gender, race, disability, etc.)
- Medical or health-related information
- Legal claims or regulatory references
Important: You are responsible for ensuring you have proper authorization to upload any document containing employee or third-party personal data. By uploading a document, you represent that you have the legal authority to do so.
2.4 Scan Results
We store the results of each compliance scan, including risk levels, flagged issues, severity ratings, and suggested remediation actions.
2.5 Usage Information
We automatically collect:
- IP address and approximate location
- Browser type, device type, and operating system
- Pages visited, features used, and timestamps
- Scan frequency and document types processed
2.6 Cookies
We use essential cookies for authentication and session management. We use httpOnly, secure cookies for authentication tokens.
We also use the Google Ads tag (gtag.js), which sets third-party cookies to measure advertising conversions — for example, whether a visit or signup originated from one of our ads. These cookies are used for advertising measurement and are set by Google; Google's use of this data is described in Google's advertising technologies policy. You can opt out of personalized advertising at Google Ads Settings or aboutads.info, and you can block third-party cookies entirely in your browser without affecting your ability to use the Services. Advertising cookies are never used on your uploaded documents or scan results, which are not shared with advertising providers.
3. How We Use Your Information
3.1 Document Processing
Uploaded documents are processed as follows:
- Text is extracted from the uploaded file (PDF, DOCX, or TXT)
- The original file is deleted from our servers immediately after text extraction
- Personally identifiable information (9 categories: SSNs, phone numbers, email addresses, dates of birth, driver's license numbers, bank account numbers, credit card numbers, EINs, and passport numbers) is automatically redacted before AI processing
- Redacted text is sent to our AI provider (Anthropic) for compliance analysis
- Scan results are stored in our database and associated with your account
- You may delete any document and its associated data at any time from your dashboard
3.2 AI Processing Disclosure
Document text is processed using Anthropic's Claude API. Key facts about this processing:
- Anthropic does not use API-submitted data to train its models
- Data sent to Anthropic is encrypted in transit
- Anthropic retains API inputs per its then-current data retention policy (see Anthropic's Privacy Policy for details)
- PII (9 categories: SSNs, phone numbers, emails, dates of birth, driver's license numbers, bank accounts, credit cards, EINs, and passport numbers) is automatically redacted before text is sent to Anthropic. Redaction applies to the nine structured identifier categories listed above. Employee names, job titles, narrative descriptions, and other unstructured content are not redacted and are included in the text sent to our AI provider for analysis.
- We send only the redacted extracted text, not your account information or the original file
For details on Anthropic's data practices, see Anthropic's Privacy Policy.
Automated decision-making: All scan results are AI-generated without human review by DefensibleHR LLC. However, we do not use AI to make automated decisions that produce legal or similarly significant effects about any individual. The Services analyze documents for your organization's human reviewers; they do not evaluate, score, or make decisions about employees or job applicants, and scan results are delivered only to your organization.
3.3 Other Uses
We also use your information to:
- Provide, maintain, and improve the Services
- Process payments and manage subscriptions
- Send transactional communications (account confirmations, scan results, billing notices)
- Respond to support requests
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
We do not use your uploaded documents or scan results for marketing purposes, and we do not sell your data.
3.4 Free Scan Lead Communications
If you use our free scan, we may use the email address you provide to:
- Deliver your scan results
- Send follow-up information about DefensibleHR.ai services
- Invite you to create a full account
You may opt out of marketing communications at any time by replying "unsubscribe" or contacting [email protected]. Opting out does not affect transactional messages related to your scan results.
4. Document Handling & Data Retention
Given the sensitive nature of workplace investigation documents, we apply the following retention practices:
| Data Type | Retention Period |
|---|---|
| Original uploaded files | Deleted immediately after text extraction |
| Extracted document text | Automatically purged after 90 days; immediately purged on document deletion; deleted within 30 days of account closure |
| Scan result records | Scan result records — findings, severity ratings, rule and model version identifiers, document filename, document hash, and timestamps — are retained for three (3) years following account closure for audit, legal compliance, and dispute-resolution purposes. Full scan result text and extracted document text are deleted within 30 days of account closure. |
| Account information | Retained while your account is active; deleted within 90 days of account closure, except as required by law |
| Billing records | Retained for 7 years per tax and accounting requirements |
| Free scan lead data (email, name, company, filename, risk summary) | Retained for lead management; IP address and user agent automatically scrubbed after 365 days; deleted upon request, except the scan result records described above |
| Free scan document text | Not retained — discarded immediately after scan results are generated |
| Terms/Privacy consent records (timestamp, IP, name, email) | Retained indefinitely as legal proof of agreement |
| Password reset tokens | Used and expired tokens automatically purged after 7 days |
| Server logs | Automatically purged after 90 days |
Legal hold. If a dispute, claim, or legal proceeding is pending or reasonably anticipated, we suspend the deletion timelines above for the affected records until the matter is resolved, as permitted or required by law. This preserves records we may need to establish, exercise, or defend legal claims.
You may request deletion of your documents and scan history at any time by contacting us at [email protected]. Deletion requests are honored subject to the legal-hold and integrity-record exceptions described above.
5. How We Share Information
We do not sell, rent, or trade your personal information or document data. We share information only in the following limited circumstances:
5.1 Service Providers
- Anthropic — AI processing of document text for compliance scanning
- Stripe — Payment processing (we never see or store your full card number)
- Railway — Cloud infrastructure hosting
- Cloudflare — DNS, CDN, and DDoS protection
- Postmark — Transactional email delivery (your email address and the content of account and scan notifications)
- Google — Advertising conversion measurement via the Google Ads tag described in Section 2.6 (cookie identifiers and page-visit data, processed under restricted data processing; never your documents, scan results, or account contents)
Each provider processes data under contractual obligations to protect confidentiality and security.
5.2 Legal Requirements
We may disclose information if required by law, subpoena, or court order. Where legally permitted, we will notify you before disclosure and limit the scope of information shared.
5.3 Business Transfers
In the event of a merger, acquisition, or asset sale, your information may be transferred to the successor entity, subject to the same privacy protections described here. We will notify you of any such transfer.
5.4 With Your Consent
We may share information when you explicitly direct us to do so.
6. Security
We implement industry-standard technical and organizational safeguards to protect your data:
- All data is encrypted in transit (TLS 1.2+)
- Database connections are encrypted
- Authentication tokens are stored in httpOnly, secure cookies
- Passwords are hashed using bcrypt with a cost factor of 12
- API endpoints are rate-limited to prevent abuse
- Content Security Policy (CSP) headers protect against XSS attacks
While we work to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data and uploaded documents
- Portability: Request your data in a machine-readable format
- Objection: Object to certain processing of your personal data
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know what personal information we collect and how it is used
- Right to delete your personal information
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your privacy rights
We do not sell personal information. We use the Google Ads conversion tag described in Section 2.6 to measure whether visits and signups originated from our advertising. We do not use it to build remarketing or other advertising audiences, and your uploaded documents and scan results are never shared with advertising providers. To opt out of advertising cookies, use the links in Section 2.6 or block third-party cookies in your browser.
To submit a request, email [email protected].
9. Employer and Employee Data
Our customers are employers, HR professionals, and legal teams. Documents uploaded to our platform typically contain information about employees who are not direct users of our Services.
- We process employee data solely on behalf of and at the direction of our customers (the employers)
- The customer acts as the data controller; we act as the data processor
- We do not contact, profile, or market to employees whose information appears in uploaded documents
- Customers are responsible for complying with their own obligations regarding employee data, including any required notices or consents
The terms governing our processing of personal data on behalf of customers — including processing instructions, subprocessors, security measures, breach notification, and deletion — are set out in our Data Processing Addendum, available upon request at [email protected].
10. Health and Medical Information
Workplace investigation documents may incidentally contain references to medical conditions, disabilities, or health-related information. While DefensibleHR.ai is not a HIPAA-covered entity or business associate:
- We treat any health-related information in uploaded documents with the same security protections as all other document data
- Our AI scanner flags unnecessary references to medical conditions or disabilities as a compliance risk (Protected Class References category)
- We do not extract, index, or separately process health information from your documents
11. Children's Privacy
Our Services are designed for business use and are not directed at individuals under 18. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will delete it promptly.
12. International Data Transfers
Our Services are hosted in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. By using our Services, you consent to this transfer. We apply the same privacy and security protections regardless of where your data originates.
13. Changes to This Policy
We may update this Privacy Policy as our practices or legal requirements change. We will notify you of material changes by email or through a prominent notice on our website at least 10 days before the changes take effect. Your continued use of the Services after changes become effective constitutes acceptance of the updated policy.
14. Contact Us
For questions about this Privacy Policy, to exercise your data rights, or to report a privacy concern:
- General: [email protected]
- Support: [email protected]