Current service components
- Application and marketing hosting
- Cloudflare Workers. Our public website and the app you sign in to are hosted separately.
- Application records
- Cloudflare D1 stores workspace membership, case records, and request progress.
- Request files
- Cloudflare R2 stores private case files. The app checks permission before team members or requesters can access these files.
- Background processing
- Cloudflare Queues handles background tasks. We use Cloudflare to deliver service emails.
In-app AI assistance
The in-app assistant sends your conversation and information retrieved through permitted workspace tools to OpenAI through Cloudflare AI Gateway. Depending on your question and access, this can include case details and other personal information. Consider that processing before using the assistant with sensitive records.
The app requests that OpenAI responses are not stored and disables Cloudflare AI Gateway logging and caching for these requests. These request settings do not establish a contractual retention period or a provider guarantee. Confirm applicable provider terms and account settings with us before relying on a particular retention commitment.
Billing and customer-selected destinations
The app integrates with Stripe for subscription checkout and billing management. Paid upgrades are currently unavailable. When billing is enabled, the app shares billing account information and workspace references with Stripe; payment details are entered on Stripe-hosted pages. Case files are not part of the billing integration.
If your team enables an outgoing webhook, event information is sent to the destination you configure. Review who controls that destination before enabling it.
This is a technical service inventory, not an approved or exhaustive contractual subprocessor schedule. It does not establish a fixed processing location.
What is available today
- Product security controls: role-based access, delivery expiry and revocation, and case history.
- Published privacy information and service terms.
- Guidance on sending responses and keeping case records.
What requires a separate review
An approved data processing agreement (DPA), contractual subprocessor schedule, fixed residency commitment, certification, penetration-test report, and backup/recovery commitment are not currently published. Do not treat this page as any of those documents.
Retention and recovery
Workspace retention settings identify closed cases for review. They do not automatically erase cases when a review date is reached. Legal holds and documented review remain part of the workflow.
Case records and uploaded files use separate storage systems. A database recovery does not by itself recover a deleted file. If your organization requires a particular recovery time, recovery point or deletion schedule, discuss it with us before relying on it.
Report a service or security concern for help with access problems, missing files or a suspected vulnerability.
Request review materials
Contact the Privacy Requests team with your company name, the materials you need, and any review deadline. Do not send requester records or identity documents. We can explain current availability; a request does not imply that a document or commitment is already approved.
Questions to settle before using sensitive data
- Which contractual documents does your organization require?
- Who may access cases and approve disclosures?
- What retention and recovery requirements apply to your organization?
- Does your organization require a particular processing location?