Privacy

What Abstract does with the documents you upload, and with the people named inside them.

Effective 26 August 2026 · previous versions in the repository history

The people this affects are mostly not our users. A commercial lease names tenants, occupants, guarantors and landlord representatives, with home addresses, payment obligations and personal guaranties. They never signed up for anything. That shapes everything below: our customer decides what happens to that data, and we act on their instructions and no one else's.

1. Which of us is responsible for what

In data-protection terms, for the contents of an uploaded lease:

For our customers' own account data — the people who sign in — we are the controller, and section 4 covers that.

If you are named in a lease someone abstracted and you want it removed, the organization that uploaded it is the right place to start; they control it. If you cannot reach them, write to us and we will help — see section 6.

2. What is in a lease abstract

WhatWhere it comes fromWhy we hold it
The original PDFUploaded by the customerSo every extracted figure can be checked against its source page
Names of tenants, occupants, guarantors, landlord representativesExtracted from the documentThey are the terms of the lease
Addresses, contact details, signature blocksExtracted from the documentSame
Rent, obligations, personal guaranties, datesExtracted from the documentThe product
Verbatim quotations from the leaseExtractedCitations. Every number traces to the words it came from — without them the abstract is unverifiable
Corrections a reviewer makesOur customer, or our operator at their requestProvenance: what was changed, by whom, when

3. Who else sees it

Named individually at /subprocessors.html, which is dated and versioned. In summary:

We do not train models on customer documents and we do not permit our AI provider to. What that claim rests on, and what still needs confirming in writing, is recorded in docs/ai-provider-diligence.md — including the parts that are not yet closed out.

There is no analytics provider, no error-reporting service, no CDN and no advertising pixel anywhere in Abstract.

4. Our own staff

Abstract has an internal review console used to check extraction quality. It can read customer documents, and we would rather describe it than let you discover it:

5. How long we keep things

WhatHow longWhy
Lease abstracts and their citationsWhile the account is activeThe product
Original PDFs3 years, then deletedThe abstract does not need the source forever
PDFs with no matching abstractRemoved on the next daily sweepAn orphaned file is a confidential document nothing points at
Handoff tokensExpire on a timer, then deletedThey are credentials
Rendered notification emails30 daysDebugging, not archiving
Webhook delivery logsTrimmed per endpoint. Response bodies never storedDebugging
Account and billing recordsAccount life; billing 7 yearsTax and accounting obligations

These are enforced by a daily job, not by intention. Deleted data persists in backups until those expire on their normal cycle and is never restored to recover deleted records — that is the accurate position and we will not claim otherwise.

6. Rights, and how to use them

If you are a customer: export and deletion are in the product. Ask us and we will act within 45 days, usually far sooner.

If you are named in someone's lease: ask the organization that uploaded it — they control it and they can delete it. If you do not know who that is, or they will not respond, write to privacy@abstract.local. We will identify the controller and pass your request to them, and tell you we have done it. We will not delete a customer's records on a third party's instruction without the controller's involvement, because it is not our data to delete — but we will not leave you with nowhere to go either.

Two ways to reach us: the address above, or from inside your account under Settings. We acknowledge within 10 business days.

If we say no, we will say why and how to appeal. Most US state privacy laws require an appeal route; we would rather have one than argue about whether it applies.

7. Security

TLS everywhere. Passwords hashed with PBKDF2-HMAC-SHA256 and per-user salts. API keys are 256-bit, stored as SHA-256 hashes, sent in a header only, and never shown again after creation. Every customer-facing query carries an organization predicate enforced in the query itself. Outbound webhooks are checked against private, loopback, link-local and cloud-metadata address ranges before we connect, and redirects are refused. Response bodies from those requests are never stored or returned.

No system is perfectly secure. If something goes wrong, our procedure and timelines are in docs/breach-response.md, and our contractual commitment to customers is 48 hours.

8. Where processing happens

The United States. If you are established somewhere that restricts transfers, ask us — a DPA with an appropriate transfer mechanism is available.

9. Changes

Material changes are notified to account holders by email before they take effect, and the date above is updated. Subprocessor changes get 30 days' notice — see /subprocessors.html.

Contact

privacy@abstract.local

[DECISION NEEDED: replace with a real monitored address, and add the legal entity name and postal address — several state laws require a physical address in a privacy notice.]