Privacy Policy
Effective date: 2026-09-02
1. Who this policy covers, and who the data controller is
This policy covers the Compliant Always website, the free document check, the live conference demo at /conference-demo, the product itself, and the no-login manufacturer/counterparty request pages. The data controller is Lettuce Labs LLC, a Delaware limited liability company, the same contracting entity named in the Terms of Service.
2. The principle this policy is built on
Everything a customer uploads is private to their account by default. Everything. Documents, the facts and rules extracted from those documents, learned formats, and relationships to suppliers, manufacturers, or buyers are never shared with, shown to, or used to benefit any other customer's account. There is no "your document helps train the system for other customers" exception hiding in this policy, and no fine print that overrides this by default.
Three categories of information are handled differently, deliberately:
1. The rule content of a widely-distributed document an issuer publishes (for example, a supplier manual a retailer sends to every vendor). This kind of content may be added to a shared requirement library, but only when Compliant Always acquires its own copy directly from the issuer (a public posting, or a direct request to the issuer), and authors the shared rule entry from that copy. A customer's own upload of the same document is never itself the source used to populate the shared library, and never identifies that customer as the source to any other customer. 2. A customer's own documents: Certificates of Analysis, negotiated specifications, learned document formats, and anything else uploaded. Private, always, with no exception above. 3. The relationship graph: who a customer sells to, who supplies them, and any other counterparty relationship. This is treated as the customer's trade secret. It is never inferred, surfaced, or made visible across accounts, and is not used to build any cross-customer feature without a separate, explicit, opt-in policy (see Section 6).
Process learning is shared; content is not. The system's ability to read a supplier manual, a questionnaire, or a Certificate of Analysis layout may improve over time in ways that benefit every customer, but this happens without moving any customer's actual document, or facts extracted from it, into any shared store, and without any other customer being able to see, query, or infer the existence of a particular customer's document.
The only outward signal a private upload may ever produce is a non-identifying acquisition hint, for example an internal note that "a supplier manual for issuer X, version dated Y, appears to exist," routed only to Compliant Always's own first-party document-acquisition process, never to any other customer, and structured so it cannot be used to reconstruct who sells to, or buys from, whom. This hint generation defaults to off and is enabled only where it can be verified not to be identifying.
3. What is collected, and why
| Category | What | Why |
|---|---|---|
| Account details | Name, email address, company name, role | Operate your account, sign you in, and reach you about deadlines |
| Uploaded documents | Labels, Certificates of Analysis, specifications, and similar files you or your counterparties upload | This is the service: reading them, extracting facts, checking them against requirements, and keeping them ready to hand over |
| Extracted facts | Structured values read out of your documents (ingredient amounts, expiry dates, claims, and similar), with source and confidence recorded | Drives the requirement-matching engine and the readiness/status views |
| Usage data | Which pages and features are used, error rates, timing | Improves the product where it is actually used; describes usage of the product, never the contents of a document |
| Billing | Subscription status, invoice history, and the number of products your subscription is billed on | Charging the correct amount and showing you why. Card details are handled directly by our payment processor and never touch our own servers. The number is a count of products, not an inventory of what is in your documents |
| Counterparty-submitted documents | Documents a manufacturer, supplier, or other counterparty uploads through a no-login request link on your behalf | Fulfilling the document request you initiated; the link's use is logged for security, since it accepts uploads without authentication |
The conference demo (/conference-demo) is a no-login chat surface we run at trade events. It collects the messages you send, the files you upload, and, if you choose to leave them, an email address or WhatsApp number and your name and company. We use this to answer you during the demo and, if you leave contact details, to follow up and set up your account. Files you upload there are processed by the AI subprocessors named in Section 5, and nothing you send is used to train any model. Conversation records from the demo, including any contact details you leave, are kept the same way as our other sales lead records: they are retained until you ask us to delete them (Section 7), and they are never sold or shared for advertising (Section 4).
4. What is never done
- Your data is never sold, rented, or shared for advertising purposes.
- Underlying AI models are never trained on customer documents or the facts extracted from them.
- No customer document, extracted fact, or relationship is shared with, or made visible to, any other customer's account.
- No consumer health information is collected: this Service processes product-testing and compliance documents about products, not information about individual people's health.
5. Where your data lives, and who processes it (subprocessors)
All data is stored and processed in the United States. Database, file storage, and hosting all run in US regions; we do not currently operate infrastructure outside the US. The subprocessors below are the only third parties that process customer data. Each is bound by its own standard commercial terms of service and, at minimum, standard contractual confidentiality and security commitments; where a customer requires an executed copy of a specific subprocessor's data processing terms for their own compliance file, contact legal@compliantalways.com and we will provide what we hold.
| Subprocessor | Role | Notes |
|---|---|---|
| Vercel | Application hosting and file storage | Runs the application; stores uploaded documents in private, non-public blob storage |
| Neon | Managed database | Holds account data, extracted document values, and audit history |
| Clerk | Authentication | Sign-in, sessions, account identity |
| Stripe | Payment processing | Card details go directly to Stripe; never stored on our servers |
| Resend | Transactional email | Deadline warnings, receipts, counterparty document requests |
| OpenRouter (default) or Anthropic | Document reading and extraction, and the in-product assistant | Processes uploaded document content and extracted facts to read documents and answer questions about your account. The default provider is OpenRouter, which routes the request to one of several underlying model providers; Anthropic may be used instead. Customer content is not used to train any model, under either provider. |
This list is updated whenever a subprocessor is added, removed, or changed; material changes are notified as described in Section 10.
Security, stated as practices rather than as a claim. Access to customer data is scoped to the account it belongs to at the query layer, so a request made in one account cannot read another account's rows; uploaded files are held in private, non-public storage; sign-in and sessions are handled by the authentication subprocessor above, and card details never reach our servers. Consequential actions in the product are recorded in an append-only activity log attributed to the named person who took them. We do not claim certification under any security standard, and this policy does not describe an audited control set; it describes how the system is built.
If there is a breach. If we confirm a security incident affecting your data, we will notify the account holder by email without undue delay, describing what we know, what data was involved, and what we are doing about it, and we will do so whether or not any particular statute requires it of us. Where a law that applies to you or to us sets a shorter deadline or requires notice to a regulator or to individuals, we follow that requirement in addition (see Section 8 for the two regimes we have specifically flagged as not yet worked through).
6. Cross-account aggregate data
We may, in the future, compute aggregate patterns across accounts that do not reveal any single account's identity or relationships (for example, general response-time patterns for a category of counterparty). Today, none of this is enabled: per-account data is scoped to that account only. If and when any cross-account aggregate feature is introduced, it will be disclosed here and offered on an opt-in basis, never retrofitted silently into this policy.
7. Retention, export, and deletion
- Account data and uploaded documents: retained while the account exists. Cancelling a paid subscription does not delete anything: the account continues on the free first product and the data stays until deletion is requested.
- Free-check uploads (the no-signup document check): retained for 30 days after the check is run, so the results can be claimed into an account, and then deleted.
- Free-check reports: the report link expires and the uploaded files are deleted 30 days after the check is run. A minimal record of the run itself (the report's findings and the email address given to receive it, if one was given) is retained after that, until deletion is requested.
- After account deletion: removed from live systems within 30 days of the deletion request, or of a termination by us taking effect, with invoices retained only as long as tax law requires. Write to support@compliantalways.com to request deletion; export first if you need the records, since deletion is final.
- Backups: the managed database provider's point-in-time recovery is used for disaster recovery, not as a secondary archive; backup copies cycle out of retention within 35 days.
- Export is self-serve and unconditional on payment status: a complete copy of your data can be exported at any time, whether or not you pay us, including while your account is running only on the free first product, during and after a trial, for products you have made inactive, and after cancellation and before deletion. This is a contractual commitment (see the Terms of Service, §5 and §6) as well as a privacy commitment: export is never used as a retention lever.
- You may request access, correction, or deletion of your data by contacting support@compliantalways.com. Depending on where you are located, these rights may also be independently guaranteed by law (for example the EU/UK GDPR or the US state privacy laws such as the CCPA); such requests are honored regardless of which specific law applies, and honoring them is not a statement that any particular statute does or does not apply to your account.
- How we work out which privacy laws apply. Our working assumption is that a regime's applicability follows where the contracting customer account is domiciled and where we ourselves operate, rather than the incidental location of an individual named inside an uploaded document (for example, a laboratory analyst's name on a Certificate of Analysis). That is an operating assumption about which processes we build first. It is not a legal conclusion, and it never narrows a right the law actually gives you.
8. International regimes: a readiness note, not a compliance claim
We serve customers who trade internationally, and two regimes we expect to matter early are Thailand's Personal Data Protection Act (PDPA) and the Philippines' Data Privacy Act (DPA). This section states our position under those two statutes honestly rather than claiming a readiness we do not yet have.
This section is not a claim of current compliance with either regime. No PDPA- or Philippines-DPA-specific mechanisms (a local representative, cross-border transfer assessments, breach-notification timelines under those specific statutes, or data-subject-rights processes tailored to those laws) are in place today, and no customer or data subject connected to either jurisdiction is known to us today.
What we commit to now:
- Applicability. We treat PDPA and Philippines-DPA applicability as keyed to where the contracting customer account is domiciled, not the incidental location of individual data subjects named inside an uploaded document (for example, a person's name on a Certificate of Analysis), the same account-domicile assumption stated at the end of Section 7. It is an operating assumption, not a legal conclusion, and it never narrows a right either law actually gives you.
- Local representative / DPO. No local representative or data protection officer is currently appointed in Thailand or the Philippines, because no customer or operation currently engages either regime. Where either statute requires one, one will be appointed before that customer's account goes live.
- Cross-border transfer. This Service currently stores and processes data only in the United States (Section 5). Any Thai- or Philippine-connected data would therefore be transferred out of those jurisdictions to the US; the transfer mechanism each regime requires (consent, adequacy, or contractual clauses) will be put in place before we take on data that engages it.
- Breach notification. We already commit, as a baseline, to notifying affected account holders of a confirmed breach without undue delay (Section 5). Where PDPA or the Philippine DPA imposes a shorter or additional statute-specific notification requirement, we will follow it, on top of that baseline, once the regime applies.
- Data-subject rights. The access, correction, and deletion channel in Section 7 (support@compliantalways.com) is the same channel that handles a PDPA or Philippine-DPA request, and we will add any further process either statute requires once it applies.
This section will be substantively updated, not merely re-dated, before we take on a customer or data that brings either regime into scope.
9. Manufacturer and counterparty request pages
When a customer asks Compliant Always to request a document from their manufacturer or another counterparty, the recipient's email address and any document they upload are used only to fulfill that specific request. The recipient is never added to any marketing list. Because the request page accepts uploads without a login, visits to it are logged (including IP address) for security purposes. Request links expire 30 days after they are created.
10. Changes to this policy
Material changes will be notified to account holders by email before taking effect, with the effective date updated at the top of the published policy.
11. Contact
Privacy questions or data-subject requests: support@compliantalways.com. Legal notices specific to this policy: legal@compliantalways.com. Postal: Lettuce Labs LLC, c/o ZenBusiness Inc., 611 South Dupont Highway, Suite 102, Dover, DE 19901, United States, the same notice address given in the Terms of Service.