Privacy Policy
Effective date: February 11, 2026
The Short Version
We collect the information you give us (name, email, deal details) and some technical data (device type, analytics) to run the Service. We use AI to extract and score your deals, but we never sell your data, share it with advertisers, or use it for ad targeting. You own your data and can delete your account at any time from the Profile page or by emailing support@hauldin.com. That's the gist -- the rest of this page covers the details.
1. Information We Collect
Account Information
Your name, email address, and password. Passwords are hashed using bcrypt before storage and are never stored in plain text.
Profile Information
Profile photo (stored as base64, maximum 2MB) and social media handles you choose to provide (Instagram, Twitter, TikTok, Facebook, LinkedIn).
Deal Information
Brand names, deal amounts, deadlines, deliverables, contract terms, payment status, and checklist items you enter or that are extracted by AI from your submitted content.
Source Content
Text you paste from DMs, emails, or text messages, and screenshots you upload. Pasted text is encrypted at rest using AES-256-GCM encryption. Uploaded screenshots are processed for AI extraction and stored securely.
Contract Files
PDF documents you upload are stored in Supabase Storage with access controls that restrict access to the uploading user only.
Compliance Data
NIL Go disclosure status, submission timestamps, disclosure tracking information, and export history (platform, date, deal count).
Technical Data
IP address, device type, push notification tokens (Expo), and browser or app version. This information is collected automatically when you use the Service.
Analytics Data
Page views and feature usage events collected via Vercel Analytics. This data is anonymized and does not include personally identifiable information (PII).
Subscriber Data
If you subscribe to our mailing list, we collect your email address and the source of your signup (landing page, scorer tool, or blog).
2. How We Collect Information
- --Directly from you -- when you create an account, fill out your profile, enter deal information, or subscribe to our mailing list
- --From content you paste or upload -- when you submit text from brand messages or upload screenshots for AI extraction
- --Automatically -- analytics events, device information, and IP address are collected automatically when you use the Service
3. How We Use Your Information
- --Service operation -- to provide, maintain, and improve the platform
- --AI processing -- to extract deal details from text and images and to score deals across six factors
- --Push notifications -- to send deadline reminders, deal status updates, and NIL Go compliance alerts
- --Compliance export -- to format your deal data for disclosure to platforms such as Opendorse, INFLCR, and NIL Go
- --Analytics -- to understand feature usage and improve the Service using anonymized, aggregated data
- --Marketing emails -- to send NIL tips and product updates to subscribers who have opted in
- --Support -- to respond to your questions and troubleshoot issues
- --Legal compliance -- to meet legal obligations, enforce our terms, and protect the rights and safety of our users
4. AI & Automated Processing
When you paste text or upload a screenshot, the content is sent to the Anthropic Claude API for processing. The AI extracts structured deal details (brand name, amount, deliverables, deadline) from unstructured messages. Deals are also scored across six weighted factors: Payment Fairness, Deliverable Clarity, Timeline Realism, VBP Risk, Red Flags, and RoC Risk.
All AI-generated results are fully editable. You can modify any extracted field or override any score. No fully automated decisions with material effect are made without your review and action.
Per Anthropic's data usage policy, inputs sent to the Claude API are not used to train their models.
5. Third-Party Services
We use the following third-party services to operate the platform. Each service processes only the data necessary for its purpose:
Supabase
Database hosting and file storage. Data is stored in the US West (us-west-2) region. Supabase provides the PostgreSQL database and storage infrastructure.
Vercel
Web hosting, serverless function execution, and anonymized analytics. Vercel hosts the web application and processes API requests.
Anthropic
AI processing via the Claude API. Text and image content is sent to Anthropic for deal extraction and scoring. Anthropic does not use API inputs for model training.
Expo
Push notification delivery for the mobile app. Expo routes notifications through Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM).
Apple & Google
App distribution via the App Store (iOS) and Google Play Store (Android). These platforms may collect additional data as described in their respective privacy policies.
6. Data Security
We take the security of your data seriously and implement multiple layers of protection:
- --Encryption at rest -- source content (pasted text from DMs/emails) is encrypted using AES-256-GCM before storage
- --Password hashing -- passwords are hashed with bcrypt and never stored in plain text
- --Row-Level Security -- database access controls ensure users can only access their own data
- --HTTPS/TLS -- all data in transit is encrypted via TLS
- --Security headers -- HSTS, X-Frame-Options, Content-Type-Options, XSS Protection, and restrictive Referrer and Permissions policies
- --Rate limiting -- sliding-window rate limits protect against abuse on login, signup, AI processing, and public tool endpoints
- --Signed URLs -- file access uses signed URLs with 24-hour expiry
- --JWT security -- mobile authentication tokens are invalidated when passwords are changed
7. Data Sharing -- What We Don't Do
We do not sell your personal information. We do not share your data with advertisers. We do not use your data for ad targeting. We do not provide your data to data brokers.
The only third parties that receive your data are the service providers listed in Section 5 above, and only to the extent necessary to operate the Service. We do not share your deal data, personal information, or usage patterns with any other party unless required by law.
8. Data Retention & Deletion
Active accounts
Data is retained for as long as your account is active.
Deleted accounts
Account data is permanently deleted within 30 days of account deletion.
Backups
Database backups containing deleted account data are purged within 90 days.
Email subscribers
Subscriber data is removed within 30 days of unsubscribing.
Analytics
Anonymized, aggregated analytics data may be retained indefinitely.
To delete your account, visit the Profile page in the app or email support@hauldin.com.
9. Your Privacy Rights
All Users
Regardless of where you live, you have the right to access your data, correct inaccurate information, delete your account and data, export your deal data, and opt out of marketing communications at any time.
California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect and how it is used, the right to request deletion, the right to opt out of the sale of personal information (we do not sell your data), and the right to limit the use of sensitive personal information.
Virginia, Colorado, Connecticut, Utah, Montana & Oregon Residents
Residents of these states have similar rights under their respective state privacy laws, including the rights to access, correct, delete, and obtain a portable copy of personal data, as well as the right to opt out of targeted advertising and profiling. We do not engage in targeted advertising or sell personal data.
Exercising Your Rights
To exercise any of these rights, contact us at privacy@hauldin.com. We will respond to verified requests within 45 days. We will not discriminate against you for exercising your privacy rights.
10. Children's Privacy
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information promptly. Users between the ages of 13 and 17 may use the Service only with verifiable parental or guardian consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact us at privacy@hauldin.com.
11. Cookies & Local Storage
We use minimal cookies and local storage, limited to what is necessary for the Service to function:
- --Authentication session cookie -- essential for keeping you logged in (strictly necessary, not optional)
- --Theme preference -- stored in localStorage to remember your light/dark mode choice
- --Onboarding flag -- stored in localStorage to track whether you have completed the onboarding flow
- --Vercel Analytics -- anonymized, privacy-friendly analytics with no PII tracking
We do not use third-party tracking cookies, advertising cookies, or cross-site tracking of any kind.
12. Do Not Sell My Personal Information
HAUL'D does not sell your personal information as defined under the California Consumer Privacy Act (CCPA) or any other applicable state privacy law. We have never sold personal information, and we have no plans to do so. If this ever changes, we will provide you with an opt-out mechanism before any sale of personal information occurs and will update this policy accordingly.
13. Changes to This Policy
For material changes to this Privacy Policy, we will provide at least 30 days' notice via the email address associated with your account before the changes take effect. Non-material changes (such as formatting corrections or clarifications) may be made without prior notice. The "Effective date" at the top of this page will always reflect the date of the most recent version. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact
For privacy-related inquiries, data requests, or to exercise your privacy rights, contact us at privacy@hauldin.com.
For general support, contact us at support@hauldin.com.