Collector Audit Collector Audit Back to home

Privacy Policy

Last updated · July 22, 2026

The short version

We collect what we need to help you document collector interactions and mail letters, and nothing else. We do not sell your personal information. Sensitive content — call notes, SMS transcripts, uploaded photos, audio, and PDFs — is stored under strict access controls and only you can see it.

What we collect

  • Account data: name, email, password hash, sign-in events.
  • Profile data: phone number and mailing address (street, city, state, ZIP) so we can populate letter return addresses.
  • Collector data: the names, addresses, and notes about debt collectors you choose to track.
  • Communications you log: the date, type, direction, notes/transcripts, and any files you upload (photos, PDFs, audio recordings).
  • Letters: the draft and final content of letters you create or send.
  • Payment data: handled by Stripe. We store the receipt metadata (amount, status, last 4 of card) but never the card number itself.
  • Technical data: standard server logs and error reports for security and reliability.
  • Usage data: which pages and features you use and general session activity, collected via product analytics. This is tied to your account once you sign in; before that it's anonymous.

How we use it

  • To run the service and show you your own audit.
  • To process payments and send receipts.
  • To print and mail letters you have approved.
  • To prevent abuse and comply with the law.
  • To understand how the app is used and improve it.

Who we share it with

We share data only with the processors that make the service work:

  • Lob, Inc. — our certified-mail provider. When you send a letter, we transmit your name and return address, the recipient's name and address, and the letter contents so Lob can print and mail it. Lob retains records under its own privacy policy.
  • Stripe, Inc. — payment processing.
  • Supabase — managed Postgres database, authentication, and encrypted object storage on our behalf.
  • Cloudflare — application hosting and edge runtime.
  • Amplitude, Inc. — product analytics. We share which pages and features you use so we can understand how the app is used and improve it. Once you sign in, this is tied to your account identifier and email; before that it's anonymous. Amplitude acts as our service provider for this purpose; see Amplitude's privacy policy for how they handle data on our behalf.
  • Law enforcement or regulators — only when required by valid legal process.

We do not sell or rent your personal data.

Sensitive content (calls, SMS, photos, recordings)

Notes, transcripts, and uploaded evidence files are stored in an access-controlled bucket and protected by row-level security: only your account can list or read them. Files are served through short-lived signed URLs that expire after a few minutes. We never use uploaded evidence to train AI models or share it with marketing partners.

Data retention

  • Active account data and evidence: kept for as long as your account is open.
  • Letter records: kept for as long as your account is open so you can produce a paper trail later.
  • Mailed-letter copies held by Lob: retained per Lob's policy (currently 7 years for certified mail records). Deleting your account removes the link in our database; Lob's own records are subject to their retention schedule.
  • Stripe receipts: retained per Stripe's policy for tax/dispute purposes.

Your rights

You can:

  • See and edit your profile and collectors in Settings.
  • Delete your account at any time from Settings → "Delete account." This removes your profile, collectors, communications, evidence files, letters, and purchase records from our database, attempts to cancel any in-flight letters with Lob, and deletes all uploaded files from storage. Lob, Stripe, and other processors retain records as described above.
  • Request an export of your data, or ask us a question about how your data is used, by emailing privacy@collectoraudit.com.
  • Residents of California, Colorado, Virginia, and other states with comprehensive privacy laws can also request the categories of personal information we collect and opt out of sharing — email the address above and we will respond within the statutory window.

Security

Connections are encrypted in transit (TLS). Data is encrypted at rest by our managed database and object storage providers. Access is gated by row-level security and short-lived signed URLs. No system is perfect, so if you suspect a breach contact us immediately at security@collectoraudit.com.

Children

Collector Audit is not directed to anyone under 18. We do not knowingly collect data from minors.

Changes

When this policy changes materially we will notify you in-product or by email at least seven days before the change takes effect.