Privacy Policy

Last updated: July 27, 2026

What we collect

Account details (name, email, phone, brokerage info), the documents and client records you create, uploaded form templates, signature records (including signer name, contact, IP address, and consent timestamps — kept as the audit trail), and conversation transcripts with the assistant (web, SMS, and voice) used to carry out your requests.

How we use it

To run the service: filling and delivering your documents, remembering your clients for you, routing calls and texts to your account, and securing the platform. We do not sell your data, and we don’t use your documents to advertise to anyone.

Service providers

We rely on a small set of processors to operate: Supabase (database & file storage), Vercel (hosting), OpenAI (AI processing of your instructions and documents), Vapi (voice calls), Twilio (calls & SMS), Resend (email), and Stripe (subscription billing and payments). Each receives only what it needs to do its job — Stripe, for example, handles your payment details directly; we never see or store your full card number.

Retention & deletion

Your data stays until you delete it. Removing a document, client, or form deletes that record; deleting your account in Settings removes your account and its data from production systems, with residual copies in backups expiring on a rolling basis.

Security

Data is encrypted in transit and at rest, access is scoped per-account with row-level security, document links use signed unguessable tokens, and webhooks are signature-verified.

Contact

Privacy questions: documents@pheme.deals.

Privacy Policy — Pheme