Privacy
What Abstract does with the documents you upload, and with the people named inside them.
Effective 26 August 2026 · previous versions in the repository history
1. Which of us is responsible for what
In data-protection terms, for the contents of an uploaded lease:
- Our customer is the controller. They decide what to upload, why, and how long to keep it.
- Abstract is the processor. We extract, store and return it on their documented instructions, and we do nothing else with it.
For our customers' own account data — the people who sign in — we are the controller, and section 4 covers that.
If you are named in a lease someone abstracted and you want it removed, the organization that uploaded it is the right place to start; they control it. If you cannot reach them, write to us and we will help — see section 6.
2. What is in a lease abstract
| What | Where it comes from | Why we hold it |
|---|---|---|
| The original PDF | Uploaded by the customer | So every extracted figure can be checked against its source page |
| Names of tenants, occupants, guarantors, landlord representatives | Extracted from the document | They are the terms of the lease |
| Addresses, contact details, signature blocks | Extracted from the document | Same |
| Rent, obligations, personal guaranties, dates | Extracted from the document | The product |
| Verbatim quotations from the lease | Extracted | Citations. Every number traces to the words it came from — without them the abstract is unverifiable |
| Corrections a reviewer makes | Our customer, or our operator at their request | Provenance: what was changed, by whom, when |
3. Who else sees it
Named individually at /subprocessors.html, which is dated and versioned. In summary:
- Anthropic — receives the full text of each lease for extraction. This is the only subprocessor that sees document contents.
- Our hosting provider — holds the database and the PDF files at rest.
- Stripe — billing only. Never lease contents.
- An email provider — deadline notifications: recipient, lease name, obligation and date.
- Any webhook the customer configures — a destination they choose, for events they select.
We do not train models on customer documents and we do not permit
our AI provider to. What that claim rests on, and what still needs
confirming in writing, is recorded in
docs/ai-provider-diligence.md — including the parts that are not
yet closed out.
There is no analytics provider, no error-reporting service, no CDN and no advertising pixel anywhere in Abstract.
4. Our own staff
Abstract has an internal review console used to check extraction quality. It can read customer documents, and we would rather describe it than let you discover it:
- It requires an explicit operator flag set by hand on an account, and a connection from the machine itself. Both, not either.
- Every operator access to a lease or a PDF is logged — who, which lease, which organization, when.
- It is the only place in Abstract that crosses between organizations, and it does so deliberately and visibly rather than because a query forgot a predicate.
5. How long we keep things
| What | How long | Why |
|---|---|---|
| Lease abstracts and their citations | While the account is active | The product |
| Original PDFs | 3 years, then deleted | The abstract does not need the source forever |
| PDFs with no matching abstract | Removed on the next daily sweep | An orphaned file is a confidential document nothing points at |
| Handoff tokens | Expire on a timer, then deleted | They are credentials |
| Rendered notification emails | 30 days | Debugging, not archiving |
| Webhook delivery logs | Trimmed per endpoint. Response bodies never stored | Debugging |
| Account and billing records | Account life; billing 7 years | Tax and accounting obligations |
These are enforced by a daily job, not by intention. Deleted data persists in backups until those expire on their normal cycle and is never restored to recover deleted records — that is the accurate position and we will not claim otherwise.
6. Rights, and how to use them
If you are a customer: export and deletion are in the product. Ask us and we will act within 45 days, usually far sooner.
If you are named in someone's lease: ask the organization that uploaded it — they control it and they can delete it. If you do not know who that is, or they will not respond, write to privacy@abstract.local. We will identify the controller and pass your request to them, and tell you we have done it. We will not delete a customer's records on a third party's instruction without the controller's involvement, because it is not our data to delete — but we will not leave you with nowhere to go either.
Two ways to reach us: the address above, or from inside your account under Settings. We acknowledge within 10 business days.
If we say no, we will say why and how to appeal. Most US state privacy laws require an appeal route; we would rather have one than argue about whether it applies.
7. Security
TLS everywhere. Passwords hashed with PBKDF2-HMAC-SHA256 and per-user salts. API keys are 256-bit, stored as SHA-256 hashes, sent in a header only, and never shown again after creation. Every customer-facing query carries an organization predicate enforced in the query itself. Outbound webhooks are checked against private, loopback, link-local and cloud-metadata address ranges before we connect, and redirects are refused. Response bodies from those requests are never stored or returned.
No system is perfectly secure. If something goes wrong, our procedure and
timelines are in docs/breach-response.md, and our contractual
commitment to customers is 48 hours.
8. Where processing happens
The United States. If you are established somewhere that restricts transfers, ask us — a DPA with an appropriate transfer mechanism is available.
9. Changes
Material changes are notified to account holders by email before they take effect, and the date above is updated. Subprocessor changes get 30 days' notice — see /subprocessors.html.
Contact
[DECISION NEEDED: replace with a real monitored address, and add the legal entity name and postal address — several state laws require a physical address in a privacy notice.]