Privacy Policy
Last updated: September 2026
1. What we collect
Account details (name, email, role); the workspaces and projects you set up; the record you create in them (baselines, changes, decisions, the maintenance log); evidence and photos you upload; notes you save; the workspace’s time zone and, where you set one, its pinned location for attendance; messages you send to support; and the basic operational logs needed to run the service securely. If you enrol a phone for WhatsApp, we store that phone number. Attendance check-in stores a name, company, check-in and check-out times, and a location status (see “Location at check-in”). Payments are processed by Stripe; Draft never holds card numbers.
2. How we use it
To provide the service; to send transactional messages (sign-in codes, decision and membership notifications, and the due-date and digest emails you can switch off in Settings); and, in de-identified, aggregated form only, to improve the product. Draft AI reads what you write to draft and structure it, and reads a saved note to propose an action you may apply; it never prices, approves, attributes, or predicts; a person decides. Draft does not sell your data.
3. Subprocessors
Draft relies on a small set of vendors to operate: DigitalOcean (hosting), Supabase (database), Resend (email), Twilio (WhatsApp messaging), Stripe (payments), and Anthropic (the provider powering Draft AI). These are disclosed subprocessors and process data on Draft’s behalf.
4. Data ownership and retention
The account that holds a workspace owns its record; Draft is custodian. Records stay in live custody for as long as the account exists; a lapsed or cancelled subscription never locks them. Export is always available. If an account is abandoned, we provide notice and a grace window (export still available) before any deletion, never a silent delete, and after deletion Draft retains only the de-identified aggregate. Support correspondence is part of Draft’s operational records and is retained separately, including after an account is closed.
5. Your rights
You can access and export your record at any time, and you can delete your account from Settings; deletion follows the notice and grace window above, with export available throughout.
6. Location at check-in
When someone checks in or out at the site, the page asks the browser’s own permission prompt for the device’s location and compares it to the workspace’s pinned location. Only the outcome is kept: a status (verified, out of range, or unavailable) and a distance in metres. Raw coordinates are discarded immediately and never stored. There is no movement tracking and no background collection, and declining the prompt never blocks a check-in.
7. Cookies
Draft sets only first-party, functional cookies: the signed session cookie that keeps you signed in; a short-lived sign-in cookie that carries your email for a few minutes while your one-time code arrives; two cookies remembering your current workspace and project; and two attendance conveniences: one that lets the check-in page greet a returning contractor by name, and one that remembers a walk-up visitor’s name and company on their own phone (kept for around 180 days). Your theme choice and a dismissed banner are kept in your browser’s own storage, not in a cookie. No advertising, analytics, or cross-site tracking cookies, ever.
8. Calendar feeds
If you add a workspace’s maintenance schedule to a calendar app, the feed address carries a secret for that workspace. Anyone holding the address can read the schedule (item names, notes and due dates) until an account admin regenerates the secret, which disconnects every calendar that used the old one.
9. Jurisdiction
Draft is operated by Kepler Insights LLC under the laws of the State of Florida, United States, and is intended for use outside the EU. EU data-protection (GDPR) coverage is not yet in place; the service is not marketed to EU users.
10. Contact
Privacy questions: [email protected].