Live card checkout is closed on this deployment and nobody has been charged. This page is drafted from facts that have been checked against the running product. The register at the end of this page lists 9 facts the founder has not supplied, across all three staged documents. This document's own clauses need 5 of them, each marked PENDING where its value belongs, and none of them is written here. Each one blocks live checkout on its own: resolving all but one still leaves checkout closed.
Resolving them is not the same as being ready. A software check can prove that no blank is left, but it cannot read the document or know whether it is lawful where a customer lives, and it is not legal advice. The real gate is Ali's sign-off on the finished text.
Privacy
What stays in your browser, what leaves it and when, what is recorded, and what is deleted. Everything below describes what the product does today.
Staged 2026-09-11. Version 0.1-staged.
What this document is
A draft, not in force, published while the facts a data controller must state are still open. The data handling it describes is not a draft: it is the running product's, read from the source, and a gate checks the main parts of it on every run. Where this page and /trust describe the same path, they are meant to agree.
Who is responsible for this data
The entity responsible is PENDINGLegal seller. What is the exact legal name of the entity that sells Underwrite subscriptions, or is it you personally as a sole proprietor?
It operates from PENDINGOperating country. Which country does that seller operate from?, and written notice reaches it at PENDINGBusiness mailing address. What is the full business mailing address where written notice reaches that seller?
Privacy questions are answered at PENDINGSupport contact. Which address or channel is the official support contact for a paying subscriber, and is it ali@getunderwrite.com or something else?. Today the only address in the product is ali@getunderwrite.com, which reaches the founder directly.
What stays in your browser
Underwrite has no server-side deal store and no accounts. A deal you work on lives in the page, and a deal you save lives in your browser's local storage on your own machine. Delete one from the library, or clear the site's browser data, and it is gone from this browser. A share link you sent and a file you exported are copies outside it, and deleting here does not reach them.
Three random identifiers are also kept in browser storage so usage can be counted without knowing who anybody is: one for the browser, one for the tab's session, and one for the work item being underwritten. They are minted with the browser's own random number generator. None of them is derived from your property, your document, your numbers, or a hash of any of them. Clearing site data severs them from anything recorded before.
Underwrite sets no cookies. There is no advertising identifier, no session replay, no keystroke capture and no third-party analytics script anywhere in the product.
What leaves your browser, and when
Four paths carry deal material out, and every one of them is something you press: parsing a document, asking for AI review, asking for an AI summary, and creating a share link or a memo link. A link carries the deal's inputs in the URL itself; it does not carry the source quotes, which stay in the session that made them. Anyone holding the link can open that deal, and opening it sends the whole URL, deal included, to Underwrite's server, which serves the page and keeps no copy. The request line exists in the hosting platform's access log, which this product does not control and does not promise to delete.
A pasted document or a small PDF travels inside the parse request. A larger PDF is staged from your browser into private blob storage under a short-lived token scoped to PDFs and to one folder, read back by the server, and deleted the moment the parse settles, on success and on every failure path. An Excel workbook never travels as a file: it is opened in your browser and only its cell text, normalized and capped in size, is sent.
Two forms reach the founder through a form service: what you type in them and the email address you give go to that service and land in his inbox. Type nothing there you would not put in an email.
Confidential Mode is one switch on the desk that turns off the four paths in the first paragraph, the feedback question the desk asks after an export, and the usage events below. It does not govern the contact form on the marketing pages, which sends only what you type into it. What it turns off is listed exactly at /trust.
Usage events
When you use the desk, the browser may send a small event so the founder can see whether the product is being used. An event carries a name from a fixed allowlist, the moment it happened, the three random identifiers above, a random delivery identifier so a retried send is one record rather than two, an actor class that separates the founder's own testing and facilitated demonstrations from a stranger's use, the build and environment the server stamps on it, and a few operational properties whose keys and values are allowlisted per event.
What an event cannot carry, because the schema has no place for it: document text, rent rolls, addresses, deal names, filenames, financial values, source quotes, memo contents, IP addresses, user agents, keystrokes or page contents. The schema has no free-text field. A field path is accepted only if it is one of the engine's own input paths, and a property value only if it is one the engine knows. Anything else is refused outright with an error, not quietly dropped.
Events are stored as one small JSON object each in a private blob store, readable only with the server's own token. In Confidential Mode no event is sent at all, and the server neither knows nor needs to know why an event did not arrive.
Deletion
Deleting usage events is a pass somebody runs, not a timer or a background job. The window the pass uses is 90 days: a day older than that is deleted when the pass runs. Each run writes a receipt saying what it deleted and when. Until a pass has run, the events are still there.
The same pass removes staged uploads that were abandoned, meaning a document staged for a parse that never started because the tab closed. It deletes under the usage-event folder and the staging folder and nowhere else, and it refuses to touch billing records.
If the blob store is unavailable, the event is not recorded at all. What is left behind is one diagnostic line in the hosting platform's log naming the event and nothing else: no identifiers, in a log this product does not control and therefore does not promise to delete. An event that was never delivered, or failed to store, is activity nobody observed, not evidence that nothing happened.
Subscription records
If checkout is ever opened and you subscribe, the card is entered on Stripe's own hosted page. Underwrite never sees a card number. What it keeps is a customer identifier, the email address you gave Stripe, the plan, the subscription status, the last invoice outcome, and the identifiers of the Stripe events already applied, so the same event arriving twice is recorded once.
That is a business record with a different purpose from usage measurement, and it deliberately does not inherit the usage-event window: a payment record is kept for as long as the business needs it. It is never joined to browser activity by inference, and the funnel report counts paying subscribers from this ledger rather than from anything a browser did.
Who else touches it
Four providers are in the path: Anthropic runs the AI calls, the hosting platform serves the site and holds the private blob store, Stripe would take a payment, and a form service delivers the two contact forms. The AI calls run under Anthropic's commercial API terms, which do not use the input for training; Underwrite itself trains nothing.
No promise is made here about what any provider keeps, or for how long. Underwrite has no signed data processing agreement with any of them. An institution that requires a data processing agreement should run sensitive deals in Confidential Mode or by hand until that paperwork exists.
Your choices and rights
What you can do today without asking anyone: use Confidential Mode, which stops the desk and the memo page sending anything about your deal; delete any saved deal from the library; clear the site's browser data, which removes every deal and severs the three identifiers; and not press the buttons that send a document. Because there is no server-side deal store, there is no copy of your deal to request and nobody at Underwrite can pull one up.
Which statutory privacy rights apply to you depends on where you are, and the customer jurisdictions are PENDINGCustomer jurisdictions. Which countries or states may subscribers be in, and are any of them excluded?
Until that is settled, this page does not claim to satisfy any particular privacy regime and does not list rights under one. A request to remove a subscription record is answered at the support contact above.
Everything this document is still missing
The register below is the whole set across the three staged documents. Each entry blocks live checkout on its own in the payment code.
- PENDINGLegal seller. What is the exact legal name of the entity that sells Underwrite subscriptions, or is it you personally as a sole proprietor?
- PENDINGOperating state or province. Which state or province does that seller operate from?
- PENDINGOperating country. Which country does that seller operate from?
- PENDINGBusiness mailing address. What is the full business mailing address where written notice reaches that seller?
- PENDINGSupport contact. Which address or channel is the official support contact for a paying subscriber, and is it ali@getunderwrite.com or something else?
- PENDINGCustomer jurisdictions. Which countries or states may subscribers be in, and are any of them excluded?
- PENDINGTax treatment. Is the subscription price tax inclusive or tax exclusive, and who remits any sales tax or VAT?
- PENDINGRefund policy. What is the approved refund policy, stated in one sentence a customer can rely on?
- PENDINGWhat the subscription buys. Does the monthly subscription buy defined founder support, or paid software access, and what exactly is promised in either case?