Privacy Policy
Last updated: September 18, 2026
This Privacy Policy describes how DefensibleHR LLC ("Company," "we," "us," or "our") collects, uses, and protects information when you use our AI-powered compliance scanning assistant platform, DefensibleHR.ai, and related services (the "Services"). Because our Services involve processing sensitive workplace documents, we take your privacy and data security seriously.
1. Scope
This policy applies to all users of DefensibleHR.ai, including visitors who use our free compliance scan, registered account holders, our website, application, and API. It does not cover third-party services that may integrate with our platform, each of which maintains its own privacy policy.
"Customer" means an organization that accesses or uses the Services under the Terms of Service or an applicable Order Form. Capitalized terms not defined in this Privacy Policy have the meanings given in the Terms of Service or the Data Processing Addendum, as applicable.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Full name and email address
- Company or organization name
- Hashed password (we never store plaintext passwords)
- Billing information processed through Stripe (we do not store credit card numbers)
- Terms of Service and Privacy Policy consent timestamp and IP address (recorded when you agree during signup)
2.2 Free Scan Information
The free compliance scan runs before any email address is collected. When you run a scan, we collect:
- Name and company name (optional)
- IP address, browser/device information (user agent), and referring page
- An indicator of whether the IP address belongs to hosting or VPN infrastructure (used for abuse prevention only)
- The filename of the document you upload and cryptographic fingerprints (hashes) of the file and its extracted text
- The risk level and issue count from your scan results
- Terms of Service and Privacy Policy consent timestamp, IP address, and document versions accepted
- Email address — only if you choose to receive the full report, in which case it must be verified
If you verify an email address, this information is stored in our leads database and used to deliver your scan results, prevent abuse of the free scan feature, and contact you about DefensibleHR.ai services. If you never provide an email address, we retain no contact information: the extracted document text is automatically deleted within 24 hours, and we keep only the consent and scan record described above (without any email) for abuse prevention and legal-compliance purposes. We do not store the full scan results or the extracted document text in association with you — only the summary metadata listed above is linked to your contact information. The same document processing and AI disclosure practices described in Section 3 apply to free scans.
Scan result cache: To make repeat scans of an identical document deterministic and efficient, we retain a copy of the full scan results in a result cache keyed to a cryptographic hash of the document's redacted text — not to your name, email, or account. Cached results are automatically deleted after 90 days and cannot be used to look up who submitted a document.
Guides, sample reports, tools, and demo requests: If you provide contact details to unlock guide materials or the sample report, to have a checklist emailed to you, or to request a demo, we collect the details you enter (which may include your name, work email address, firm or company, role, and message), your IP address and browser information, and which material or request it was. We store this in our leads database to deliver what you asked for, to send a follow-up about your request, and to contact you about DefensibleHR.ai services as described in Section 3.4. When you unlock the sample report we also set a cookie so that you are not asked for your details again for 180 days.
2.3 Uploaded Documents
You may upload workplace documents including investigation reports, termination letters, performance improvement plans (PIPs), and HR memos. These documents may contain:
- Employee names and personal information
- Allegations, complaints, and investigation findings
- References to protected characteristics (age, gender, race, disability, etc.)
- Medical or health-related information
- Legal claims or regulatory references
Important: You are responsible for ensuring you have proper authorization to upload any document containing employee or third-party personal data. By uploading a document, you represent that you have the legal authority to do so.
2.4 Scan Results
For registered users, we store Full Outputs — including the overall risk level, each flagged issue with its category label (required, recommended, or optional), jurisdiction, and cited authority, the passage of your document each finding rests on, and suggested remediation language — for the period stated in Section 4. For Free Compliance Scan users, Full Outputs are not stored in association with you after scan generation; we retain only the limited contact information and scan summary metadata identified in Section 2.2. In addition, the scan result cache described in Section 2.2 applies to all scans: a copy of the full results is retained for up to 90 days, keyed to a cryptographic hash of the document's redacted text rather than to your account, so that identical documents produce identical results on re-scan.
2.5 Usage Information
We automatically collect:
- IP address, from which approximate location may be inferred
- Browser type, device type, and operating system
- Pages visited, features used, and timestamps
- Scan frequency and document types processed
- Website conversion events (for example, that a visitor viewed the sample report or requested a checklist), recorded with a random session identifier generated in your browser, the referring page, any advertising campaign parameters in the URL, your browser's user-agent string, and an automated classification of whether the visit appears to come from a bot. These events do not include your IP address or email address and are deleted after 90 days.
- The scan settings you use (states of operation, headcount, and document-type selections) and the number of documents in a batch
2.6 Cookies
We use essential cookies for authentication and session management, including httpOnly, secure cookies for authentication tokens. We may also use non-essential cookies or similar technologies for analytics or advertising-conversion measurement as described below and only where permitted by Applicable Privacy Laws.
We use the Google Ads tag (gtag.js), which sets third-party cookies to measure advertising conversions — for example, whether a visit or signup originated from one of our ads. These cookies are used for advertising measurement and are set by Google; Google's use of this data is described in Google's advertising technologies policy. You can opt out of personalized advertising at Google Ads Settings or aboutads.info, and you can block third-party cookies entirely in your browser without affecting your ability to use the Services. Advertising cookies are never used on your uploaded documents or scan results, which are not shared with advertising providers.
Bot protection. Our contact, free-scan, and demo-request forms use Cloudflare Turnstile to distinguish people from automated traffic. Turnstile is provided by Cloudflare, Inc., evaluates browser and network signals including your IP address, and may set a Cloudflare cookie; Cloudflare\'s use of this data is described in its privacy policy.
Other first-party storage. We set a cookie for 180 days when you unlock the sample report so you are not asked to enter your details again; your browser\'s session storage holds the random session identifier used for the conversion events described in Section 2.5; and local storage holds your display-theme preference. None of these contains your documents or scan results.
2.7 SMS Information
If you separately opt in to receive SMS messages, we collect your mobile telephone number, consent status, consent timestamp, and records of messages and opt-out requests. We use this information to send the message types disclosed at the time of opt-in and to administer your preferences. SMS consent is not a condition of purchase. You may revoke consent by using the account setting identified at enrollment or by replying STOP. We share SMS information only with service providers that deliver or support the messaging program and retain it only as reasonably necessary for the program, compliance, and legal claims.
2.8 Feedback on Findings
If you use the "This rule looks out of date" control on a finding, we record your user and organization identifiers, the finding concerned, and the note you write in our internal rule-review queue. We use this to review and, where appropriate, update our rule library. Feedback is visible to the personnel and reviewers who maintain the rule library, is not published, and is retained as part of the rule library\'s editorial record. Please do not include employee names or other personal information in a feedback note.
2.9 Account Activity Record
For each account we keep a record of actions taken by its users — for example sign-ins, uploads, scans, report exports, and settings changes — with the user, timestamp, IP address, and browser information. The record cannot be edited, is retained for 365 days, and can be viewed and exported by the account\'s administrators for supervision and security purposes.
3. How We Use Your Information
3.1 Document Processing
Uploaded documents are processed as follows:
- Text is extracted from the uploaded file (PDF, DOCX, or TXT)
- The original file is deleted from our servers immediately after text extraction
- Personally identifiable information (9 categories: SSNs, phone numbers, email addresses, dates of birth, driver's license numbers, bank account numbers, credit card numbers, EINs, and passport numbers) is automatically redacted before AI processing
- Redacted text is sent to our AI provider (Anthropic) for compliance analysis
- Scan results are stored in our database and associated with your account
- Registered users may delete documents and associated Extracted Text and Full Output content through the account dashboard, subject to legal holds and the retention of Scan Metadata described in Section 4. Free Compliance Scan users do not receive a dashboard. Free-scan document text is held for up to 24 hours so that results can be claimed by email, then deleted; a free-scan user may request deletion of retained contact and lead data by contacting [email protected].
Redaction Limitations. Although Company uses automated measures designed to identify and redact certain categories of personally identifiable information before AI processing, automated redaction is not infallible and may fail to identify, redact, or accurately redact all personal information or other sensitive information. Customer is solely responsible for reviewing Customer Data before upload and for determining whether it is appropriate to submit any personal information, sensitive personal information, or other regulated data to the Services. Customer should avoid submitting personal information, sensitive personal information, or other regulated data unless submission is necessary for Customer's intended use of the Services, Customer is authorized to disclose that information, and Customer accepts the risk that automated redaction may be incomplete.
3.2 AI Processing Disclosure
Document text is processed using Anthropic's Claude API. Key facts about this processing:
- Company uses authorized AI/API providers to process Extracted Text. Company configures and contracts with those providers to process Customer Personal Data only as necessary to provide the Services, subject to the provider's applicable service terms and Company's DPA obligations.
- Anthropic does not use API-submitted data to train its models
- Data sent to Anthropic is encrypted in transit
- Anthropic retains API inputs per its then-current data retention policy (see Anthropic's Privacy Policy for details)
- PII (9 categories: SSNs, phone numbers, emails, dates of birth, driver's license numbers, bank accounts, credit cards, EINs, and passport numbers) is automatically redacted before text is sent to Anthropic. Redaction applies to the nine structured identifier categories listed above. Employee names, job titles, narrative descriptions, and other unstructured content are not redacted and are included in the text sent to our AI provider for analysis. Automated redaction is not infallible and may fail to identify, redact, or accurately redact personal information or other sensitive information.
- We send only the redacted extracted text, not your account information or the original file
- Company uses reasonable measures designed to evaluate and improve system performance, including periodic review of prompts, rulesets, and model configurations. Company does not warrant that Outputs are complete, current, unbiased, or error-free. Where available, scan results may include citations or links to public legal sources. References are provided for convenience only and may be incomplete, outdated, or inapplicable. Verify all legal authorities independently before relying on them. The Services do not evaluate, rank, score, profile, recommend, or make decisions about applicants, employees, contractors, or other individuals and must not be used as the sole or determinative basis for an employment decision.
For details on Anthropic's data practices, see Anthropic's Privacy Policy.
Automated decision-making: All scan results are AI-generated without human review by DefensibleHR LLC. However, we do not use AI to make automated decisions that produce legal or similarly significant effects about any individual. The Services analyze documents for your organization's human reviewers; they do not evaluate, score, or make decisions about employees or job applicants, and scan results are delivered only to your organization.
3.3 Other Uses
We also use your information to:
- Provide, maintain, and improve the Services
- Process payments and manage subscriptions
- Send transactional communications (account confirmations, scan results, billing notices)
- Respond to support requests
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
We do not use Customer Data containing personal information or Full Outputs for marketing purposes, and we do not sell Customer Personal Data. Subject to the Terms of Service, applicable law, and any applicable Enterprise opt-out, we may use De-Identified Data to operate, secure, test, validate, and improve the Services, including our rule library and prompts. We do not use your documents, extracted text, or scan results to train any artificial-intelligence or machine-learning model. We do not attempt to reidentify individuals or Customers from De-Identified Data. "De-Identified Data" means information that has been de-identified or anonymized, as applicable, in accordance with Applicable Privacy Laws and is not reasonably capable of being linked to, or used to infer information about, Customer or an identified or identifiable individual.
3.4 Lead Communications
We use the contact details you provide for a Free Compliance Scan, the sample report, an emailed checklist, a template, or a demo request to deliver what you asked for and to send related transactional messages. Where the page says so, we may send one personal follow-up about your request. We may also send marketing communications about DefensibleHR.ai services only where permitted by Applicable Privacy Laws. Every marketing email includes a one-click unsubscribe mechanism. You may also opt out by replying "unsubscribe" or contacting [email protected]. We honor opt-out requests within ten (10) business days. Opting out does not affect transactional, security, billing, or legally required communications.
4. Document Handling & Data Retention
Given the sensitive nature of workplace investigation documents, we apply the following retention practices:
| Data Type | Retention Period |
|---|---|
| Original uploaded files | Deleted immediately after text extraction |
| Extracted document text | Automatically deleted no later than 90 days after creation; immediately on document deletion or account deletion; subject to Legal Hold |
| Full Outputs | Retained for no longer than ninety (90) days after the applicable scan is generated — narrative findings (issue titles, document excerpts, suggestions, and example replacement language) are purged on that schedule even for active accounts; deleted without undue delay following a registered user's document-deletion request or account deletion; subject to Legal Hold |
| Scan Metadata | Retained for up to three (3) years following account closure for audit, security, legal-compliance, and dispute-resolution purposes. "Scan Metadata" means non-content operational and integrity information, including document hash, document filename, timestamps, rule and model version identifiers, issue counts, category labels, and internal severity values, but excluding Extracted Text, quoted document content, and narrative findings or remediation language. |
| Account information | Retained while your account is active; deleted within 90 days of account closure, except as required by law |
| Billing records | Retained for 7 years per tax and accounting requirements |
| Lead data (free scan, sample report, tools, templates, demo requests: email, name, company or firm, role, filename, risk summary) | Retained for lead management; IP address and user agent automatically scrubbed after 365 days; deleted upon request, except for Scan Metadata retained as stated above and records required to be retained by law or Legal Hold |
| Website conversion events | Automatically deleted after 90 days |
| Account activity record | Retained 365 days, then automatically deleted; cannot be edited during retention; subject to Legal Hold |
| Feedback on findings (user and organization identifiers, finding, note) | Retained as part of the rule library's editorial record for as long as the affected rule is maintained; identifiers removed on request where the record can still be understood without them |
| Client Workspace names and settings; report branding | Retained while your account is active; deleted within 90 days of account closure |
| Sample-report unlock cookie | 180 days |
| Free scan document text | Held for up to 24 hours after the scan so results can be claimed by email, then automatically deleted; deleted immediately once results are claimed |
| Terms/Privacy acceptance records (timestamp, IP address, name or email identifier, document version, and acceptance method) | Retained for the period reasonably necessary to demonstrate consent, enforce agreements, comply with law, and establish, exercise, or defend legal claims, and thereafter deleted or de-identified |
| Password reset tokens | Used and expired tokens automatically purged after 7 days |
| Server logs | Automatically purged after 90 days |
Legal hold. If a dispute, claim, or legal proceeding is pending or reasonably anticipated, we suspend the deletion timelines above for the affected records until the matter is resolved, as permitted or required by law. This preserves records we may need to establish, exercise, or defend legal claims.
You may request deletion of your documents and scan history at any time by contacting us at [email protected]. Deletion requests are honored subject to the legal-hold and integrity-record exceptions described above.
5. How We Share Information
We do not sell, rent, or trade your personal information or document data. We share information only in the following limited circumstances:
5.1 Service Providers
- Anthropic — AI processing of document text for compliance scanning
- Stripe — Payment processing (we never see or store your full card number)
- Railway — Cloud infrastructure hosting
- Cloudflare — DNS, CDN, DDoS protection, web application firewall, and Turnstile bot verification on our forms (IP address and browser signals)
- Postmark — Transactional email delivery (your email address and the content of account and scan notifications)
- Zoho — Business email and support correspondence (messages you send to our support and contact addresses)
- Google — Advertising conversion measurement via the Google Ads tag described in Section 2.6 (cookie identifiers and page-visit data, processed under restricted data processing; never your documents, scan results, or account contents)
Each provider processes data under contractual obligations to protect confidentiality and security. Company uses authorized AI/API providers to process Extracted Text. Company configures and contracts with those providers to process Customer Personal Data only as necessary to provide the Services, subject to the provider's applicable service terms and Company's DPA obligations.
5.2 Legal Requirements
We may disclose information if required by law, subpoena, or court order. Where legally permitted, we will notify you before disclosure and limit the scope of information shared.
5.3 Business Transfers
In the event of a merger, acquisition, or asset sale, your information may be transferred to the successor entity, subject to the same privacy protections described here. We will notify you of any such transfer.
5.4 With Your Consent
We may share information when you explicitly direct us to do so.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect Customer Personal Data against unauthorized access, use, alteration, disclosure, loss, or destruction, including encryption in transit and at rest and access controls appropriate to the Services. Subject to the scope of our then-current systems and the DPA:
- Data is encrypted in transit using TLS 1.2 or a stronger secure protocol, and database connections are encrypted
- Data at rest is protected by our hosting provider's platform-managed encryption and storage controls
- Access to production systems is limited through role-based access controls and least-privilege principles
- Multi-factor authentication is available to Customers within the application
- Passwords are hashed using bcrypt with a cost factor of 12
- Authentication tokens are stored in httpOnly, secure cookies; API endpoints are rate-limited; Content Security Policy (CSP) headers protect against cross-site scripting; and we use reasonable network, logging, monitoring, and vulnerability-management safeguards
In the event of a confirmed Security Breach involving Customer Personal Data, we will notify the affected Customer without undue delay and, where reasonably practicable, no later than seventy-two (72) hours after confirmation, as further described in the DPA. Customer remains responsible for determining and carrying out any required notifications to individuals or regulators, except to the extent applicable law requires otherwise.
While we work to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data and uploaded documents
- Portability: Request your data in a machine-readable format
- Objection: Object to certain processing of your personal data
To exercise privacy rights, contact [email protected]. We may verify your identity and authority before responding. We will respond within the period required by Applicable Privacy Laws, subject to any permitted extension. Where required by law, an authorized agent may submit a request on a consumer's behalf, subject to verification of the agent's authority. If we deny a request, users in jurisdictions that provide an appeal right may appeal by contacting [email protected] with the subject line "Privacy Appeal."
7.1 Customer Personal Data Requests
For personal information that Company controls directly, including account, billing, website, support, and marketing information, individuals may submit requests using the methods in this Section 7. For Customer Personal Data that Company processes on behalf of a Customer, including employee or applicant information contained in uploaded documents, the applicable Customer is ordinarily responsible for responding to rights requests. Company will, as required by Applicable Privacy Laws and the DPA, promptly forward the request to the Customer or assist the Customer in responding. Company may respond directly only where Company is legally required or authorized to do so.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know what personal information we collect and how it is used
- Right to delete your personal information
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your privacy rights
We do not sell personal information. We use the Google Ads conversion tag described in Section 2.6 to measure whether visits and signups originated from our advertising. We do not use it to build remarketing or other advertising audiences, and your uploaded documents and scan results are never shared with advertising providers. To opt out of advertising cookies, use the links in Section 2.6 or block third-party cookies in your browser.
To submit a request, email [email protected].
For Customer Personal Data processed on behalf of an employer or other business customer, DefensibleHR acts as a Service Provider or Contractor, as applicable, under the CCPA/CPRA. Company's contractual restrictions regarding such Customer Personal Data, including restrictions on selling, sharing, retaining, using, disclosing, and combining personal information, are set forth in the DPA.
We do not sell Customer Personal Data. We do not share uploaded documents, Extracted Text, Full Outputs, or account contents for cross-context behavioral advertising. Our use of advertising conversion technology is limited to website and advertising-measurement information as described in Section 2.6.
9. Employer and Employee Data
Our customers are employers, HR professionals, and legal teams. Documents uploaded to our platform typically contain information about employees who are not direct users of our Services.
- We process employee data solely on behalf of and at the direction of our customers (the employers)
- The customer acts as the data controller; we act as the data processor
- We do not contact, profile, or market to employees whose information appears in uploaded documents
- Customers are responsible for complying with their own obligations regarding employee data, including any required notices or consents
The Data Processing Addendum, incorporated automatically through the Terms of Service when Company processes Customer Personal Data on Customer's behalf, governs processing instructions, security measures, subprocessors, assistance, incident notification, retention, and deletion.
10. Health and Medical Information
Workplace investigation documents may incidentally contain references to medical conditions, disabilities, or health-related information. While DefensibleHR.ai is not a HIPAA-covered entity or business associate:
- We treat any health-related information in uploaded documents with the same security protections as all other document data
- Our AI scanner may flag references to medical conditions or disabilities that appear unnecessary, citing the applicable authority
- We do not extract, index, or separately process health information from your documents
- Customers must not submit Protected Health Information unless Company and Customer have executed a Business Associate Agreement and Company has agreed in writing to process that information
11. Children's Privacy
The Services are intended only for business users who are at least eighteen (18) years old, as provided in the Terms, and are not directed to children or other minors. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will delete it promptly.
12. Geographic Scope
Our Services are hosted in and offered exclusively within the United States, and are intended solely for businesses located in the United States. We do not target, market, or make the Services available to individuals or entities in the European Economic Area, the United Kingdom, or Switzerland, and we do not offer Standard Contractual Clauses or other cross-border transfer mechanisms. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with applicable local law; any information you submit will be transferred to and processed in the United States.
13. Changes to This Policy
We may update this Privacy Policy as our practices or legal requirements change. We will notify you of material changes by email or through a prominent notice on our website at least 10 days before the changes take effect. Your continued use of the Services after changes become effective constitutes acceptance of the updated policy. Where Applicable Privacy Laws require additional notice, consent, or another lawful basis before a material change in processing takes effect, we will take those steps before implementing that change.
14. Contact Us
For questions about this Privacy Policy, to exercise your data rights, or to report a privacy concern:
- Privacy questions, rights requests, and appeals: [email protected]
- General inquiries: [email protected]
- Support: [email protected]