Privacy Policy
Last updated: September 2026
This Privacy Policy explains what data Attestly collects, why, and how it's handled. Attestly is built for compliance-sensitive customers, so we try to collect and retain no more than the service actually needs.
1. What we collect
Account information: your email address, and organization name/membership.
Content you provide: AI system descriptions, imported trace/event data, generated documentation, and edits or approvals you make.
Billing information: handled entirely by Paddle.com, our payment processor — Attestly does not receive or store your payment card details.
Basic usage data: standard web server logs and error logs needed to operate and secure the service.
2. How we use it
We use your data to operate the service: authenticating you, storing your organization's AI systems and traces, mapping evidence to compliance requirements, generating draft documentation, and sending service-related email (sign-in codes, team invitations).
3. Third-party subprocessors
Attestly relies on a small number of third-party providers to operate:
- Supabase — database, authentication, and file storage.
- Google (Gemini API) — processes trace evidence you've linked to a documentation section in order to draft that section's text.
- Resend — delivers transactional email (sign-in codes, team invitations).
- Paddle.com — processes payments and acts as Merchant of Record for subscriptions.
- Vercel — hosts the application.
Each provider only receives the data necessary to perform its function. We do not sell your data to anyone, including these providers, for their own independent use.
4. Data retention
We retain your account and organization data for as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.
5. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data. Contact us at support@attestly.online to exercise these rights.
6. Security
We use industry-standard measures including encrypted connections (HTTPS), row-level database access controls, and least-privilege service credentials. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to or stored by the service.
7. Changes
We may update this policy from time to time. Material changes will be reflected by updating the date above.
8. Contact
Questions about this policy can be sent to support@attestly.online.