Privacy, in plain terms
Facts stay in your browser
Your case, document index, correspondence records, original documents and edits are stored in this browser. There are no customer accounts or server-held case records. This deterministic edition sends no facts or document text to OpenAI or any other model.
To authorize document creation, the browser sends our server an opaque random case ID, a signed access token and the product identifier. Our server returns fixed correspondence wording, and your browser combines it with the facts you recorded. Names, account references, narrative and other case facts never leave for this step. No identifier restoration through an external service is needed.
Payments are separate from case details
When purchases are available, new checkout uses PayU. Payer name, email, phone and an opaque case ID reach our server to prepare the payment. The signed hosted checkout sends PayU the payer contact, transaction reference, amount, product name, return addresses and a hash. It does not send your case ID, account number, case narrative or documents.
The return callback is checked against its original signed description and does not itself grant access. Our server separately verifies payment capture and the amount against the signed purchase. Verification logs contain payment references, claimed status, verification result, stage/reason and time; they do not contain case facts. This describes our application code, not separate hosting or PayU practices.
The case ID is hashed in the signed access token. It is not a fingerprint derived from your account number or other case facts. Access is tied to this pack and separates test from production payments. The fixed access window is 90 days from checkout preparation. It does not renew on refresh or verification.
Recovery and unencrypted backups
Before leaving for PayU, this browser stores a pending purchase with a case snapshot and the details needed to verify it. Verified access is saved before that pending record is cleared. Recovery requires that browser data; there is no automatic recovery on another browser or device.
Download your case file to continue a correspondence case later. Opening it reads the file locally and does not upload it. It is an unencrypted JSON backup containing account/reference numbers, recorded facts, correspondence, edits and saved access. Local archives have the same privacy limits. Anyone with access to the device or backup can read them. Clearing site data or private browsing can lose work. We cannot retrieve, restore, delete or resend a case we do not hold.
Limited technical counting
We count a few actions, such as saving a case, viewing checkout and copying or downloading correspondence. Optional feedback sends only the answer you select from a fixed list. These event messages contain no customer/session identifier, account number, exact amount, free-text answer, contact information or document content. They do not update your case or request support.
Our event endpoint writes only allowed event names to application logs; older event names may include a broad category. Reports count actions, not unique people or individual journeys. Hosting systems may separately keep technical request logs under their own retention settings. There is no session recording or third-party analytics service.
Read the full terms, disclaimer and refund policy for review responsibilities, support and liability terms.