Privacy Policy

How HandleIt Docs uses information

Effective July 15, 2026. This policy describes the HandleIt Docs service operated by HandleIt Docs LLC.

Information collected

The service stores account email and password-derived authentication data; document answers, including the sender name, mailing address, callback phone number, and optional email used in the document signature block; generated drafts, edits, and export records; payment status and Stripe identifiers; product analytics events; generation cost and error metadata; document suggestions; support tickets; and email subscriptions. Stripe handles card details, which HandleIt Docs does not store.

How information is used

Information is used to authenticate accounts, verify email addresses, preserve short-lived guest workflow progress, generate and save drafts, confirm payments, enforce paid and promotional export access, provide support, prevent abuse, understand product usage, and operate the service.

AI processing

Document answers are sent to OpenAI’s API to generate a draft. OpenAI states that API inputs and outputs are not used to train its models by default. Its standard abuse-monitoring logs may retain some content for up to 30 days. HandleIt Docs does not use customer documents to train its own models.

Service providers

Cloudflare provides application hosting, database services, private export storage, DNS, inbound email forwarding, and aggregate web analytics. Microsoft Clarity provides optional behavior analytics such as masked session recordings, heatmaps, scroll behavior, and click diagnostics when analytics consent is allowed. Stripe provides payment processing. OpenAI processes document-generation requests. Resend provides transactional account, payment, and support-notification email. Discord receives private business-operations alerts containing aggregate usage statistics or limited event metadata such as a ticket reference, category, status, and subject. Discord alerts do not include account email addresses, ticket message bodies, private document text, passwords, card details, mailing addresses, or phone numbers.

Cookies and analytics

The service uses essential signed cookies to keep users signed in and, when guest-first workflows are enabled, to connect a short-lived anonymous workflow draft to the same browser. First-party product and marketing events may record an account or anonymous session identifier, normalized page path, sanitized referring origin or route, public document-workflow identifier, category, form step number, campaign labels, and product or revenue totals. Traffic may be classified as production, preview, owner/internal, test, health-check, likely human, or automated so business reports do not treat tests and known bots as customers. Analytics do not intentionally store document text, workflow narrative answers, names, addresses, account numbers, email addresses, passwords, reset tokens, export IDs, or payment identifiers.

Microsoft Clarity is supplementary behavior analytics and is not the source of truth for accounts, purchases, exports, or revenue. Clarity may observe clicks, scrolling, page visibility, browser diagnostics, and masked page structure. The project uses Strict masking, and sensitive application routes are also explicitly marked for masking. HandleIt Docs does not send names, email addresses, document text, form answers, support messages, or payment identifiers through Clarity custom events or tags.

Clarity analytics storage is denied by default until you choose Allow analytics. Advertising storage remains denied. Choosing Continue without analytics prevents the Clarity script from loading; you can reopen Analytics choices in the site footer at any time. An owner-only exclusion cookie also removes a browser from qualified business reporting and prevents Clarity initialization. HandleIt Docs does not use Clarity for targeted advertising and does not add advertising cookies through this integration.

Launch-offer integrity

If a launch offer is active, HandleIt Docs records verification status, a non-reversible normalized email hash, redemption status, document and export references, rate-limit outcomes, and a general risk category. These records enforce one redemption per eligible user and email, prevent duplicate or automated use, restore failed reservations, and keep promotional exports separate from payment revenue. IP or shared-network signals may support review but are not the sole reason for rejecting ordinary household, workplace, school, military, public-network, mobile-carrier, or privacy-VPN users.

Email choices

Checklist and optional marketing signups record the email address, consent time and statement, selected topic segment, source page, and campaign parameters. Optional marketing messages require consent and include an unsubscribe mechanism. Transactional account and payment messages are handled separately. Automated marketing email remains disabled until owner, domain, unsubscribe, and privacy readiness checks are approved.

Referrals

Referral links record visits, attributed signup, paid-purchase confirmation, reward status, and rejection reasons needed to prevent self-referrals or duplicate credit. Referral records do not expose or include private documents.

Retention and deletion

Unclaimed guest workflow drafts expire automatically after seven days. Account and document data is retained while an account is active so users can access saved history. A signed-in customer may delete the account from Account settings, which removes saved drafts, sessions, private exports, support tickets tied to the account email, and marketing subscriptions. Limited payment, promotion-integrity, fraud-prevention, or operational records may be retained where needed for reconciliation or legal obligations.

Security

The service uses signed sessions, authorization checks, private export storage, rate limits, password hashing, and Stripe webhook signature verification. No system can guarantee absolute security. See Security and Privacy for a plain-language overview.

Your choices

You may update or delete your account data and unsubscribe from marketing email. Additional rights may apply based on your location.

Contact

Privacy or data-deletion questions can be submitted through the support form or sent to privacy@handleitdocs.com. Requests are reviewed during normal business days.