Privacy policy
How ReclaimDeposit handles personal information
Last updated: August 11, 2026
This policy explains what the service collects, why it is used, which providers receive it, how long it may be kept, and the choices available to users.
1. Information collected
Case and document information. Names, email address when supplied, current and rental addresses, landlord details, lease and move-out dates, rent and deposit amounts, deduction descriptions, documentation answers, files you choose to save in the private vault, and generated documents.
Optional extraction input. If you ask the service to read a lease or deduction statement, the selected file or pasted text is sent for automated extraction. Suggested fields and charges remain editable. Manual entry is available instead.
Account information. If you create an account, Supabase Authentication processes your email address, authentication credentials, session information, and account identifier. ReclaimDeposit does not store your raw account password in its application database.
Transaction and fulfillment information. Stripe payment session, product, amount, status, and limited attribution when consented; Lob mail job, postal addresses, letter PDF, status, and provider cost; Resend message and delivery status.
Technical and security data. IP-derived rate-limit information, request identifiers, browser and network information needed for security, Cloudflare Turnstile verification results, and minimal error diagnostics. The application is designed not to put raw case data or access tokens in logs.
Optional analytics. After consent, PostHog may receive page paths and named product events with limited campaign/referrer data. Form text, full URLs with query strings, autocaptured clicks, and session recordings are disabled by configuration.
2. Why information is used
- Calculate an informational deadline and issue analysis from user inputs.
- Extract editable facts or charges from a document when the user selects that option.
- Create, download, save, and—only when explicitly approved—mail a demand letter.
- Authenticate users, maintain case history, and support account-data deletion.
- Process payment, prevent duplicate fulfillment, reconcile provider callbacks, and answer billing or delivery questions.
- Prevent abuse, investigate failures, protect the service, and comply with applicable obligations.
- Measure product reliability and flow completion when optional analytics is allowed.
3. Providers and disclosures
Information is disclosed to service providers only for their operational role: Supabase for authentication, database, and storage; Stripe for payment; Lob for requested physical mail; Resend for requested and transactional email; Cloudflare Turnstile for abuse checks; and PostHog for consented analytics. Their privacy terms also apply.
Optional document extraction. When you select this feature, OpenRouter routes the file contents or extracted text to an eligible model provider. Each request requires zero-data-retention routing; if no eligible endpoint is available, extraction fails instead of using an endpoint that does not meet that requirement. OpenRouter's privacy policy and the selected model provider's terms also apply.
Information may also be disclosed when reasonably necessary to comply with law, respond to valid legal process, protect users or the service, investigate abuse, or complete a merger, financing, acquisition, or sale subject to appropriate notice and protections.
ReclaimDeposit does not sell personal information or use it for targeted advertising.
4. Retention
Anonymous saved drafts and resume links expire after 30 days and are deleted by scheduled maintenance. Browser case and guest-access data uses session storage, which is normally removed when the browser session ends.
A document submitted only for optional extraction is processed in memory and is not added to the saved case or private vault. Facts or charges you accept into the form can become part of the case if you later save or submit it. Extraction requests use the zero-data-retention routing described above.
Signed-in case records and private vault documents remain until the user deletes them or the account, subject to backups, dispute handling, fraud prevention, and legal retention requirements. Payment, refund, mail, and transaction records may be retained for accounting, compliance, and dispute purposes.
Webhook replay receipts are routinely removed after 45 days. Retention can be longer when required by law, an active dispute, security investigation, or reliable backup cycle.
5. Security
The service uses production HTTPS, application-level encryption for sensitive case fields, private storage controls, short-lived or session-scoped capabilities, access checks, bounded uploads, zero-data-retention routing for optional document extraction, signed provider webhooks, and rate limiting. No system is perfectly secure; these controls reduce risk but do not guarantee that loss, misuse, or unauthorized access cannot occur.
Do not submit information the form does not request. In particular, do not upload government IDs, full payment-card numbers, account passwords, or unrelated personal records.
6. Your choices and requests
- Use the public research tools without creating an account.
- Enter lease and deduction details manually instead of using optional document extraction.
- Decline optional analytics; Global Privacy Control and Do Not Track signals are treated as a denial.
- Ask to access, correct, or delete applicable personal information by contacting support.
- Signed-in users can use the account deletion control to remove application records, vault objects, and the authentication account.
Optional analytics: not chosen
Some records may be retained where necessary for payment reconciliation, fraud prevention, legal obligations, or resolving an active dispute. Identity verification may be required before fulfilling a privacy request.
7. Children, geography, and changes
The service is intended for adults and is not directed to children under 13. The service is operated for U.S. rental matters; providers may process information in the United States and other locations under their own safeguards.
This policy may change as the service or law changes. A new effective date will be posted here, and material changes may receive additional notice when appropriate.
Contact
For privacy questions or requests, email support@reclaimdeposit.com. Do not send sensitive documents until support confirms they are necessary and provides a suitable method.
See also the Trust & Security page and Terms of Service.