In short
- You sign in with a one-time email link, so there are no passwords to store or leak.
- Your data is stored in Supabase with row-level security, so you can only access your own firm's.
- We do not use your client data to train AI models, and we do not sell your data.
Services that handle your data
If your practice keeps a written information security plan, these are the third parties that handle EngageDraft data. EngageDraft does not make compliance determinations for your practice.
| Service | Used for | Handles |
|---|---|---|
| Supabase | Database and sign-in | Account, engagement and signed-letter data |
| Vercel | Hosting | Serves the website and application |
| Resend | Email delivery | Login links and signing invitations |
| Anthropic (Claude API) | AI letter drafting | Text entered in the intake form |
| DocuSeal | E-signature | The letter PDF and the client's name and email |
| Stripe | Payments | Subscription payment details |
Storage and access
Your data is stored in Supabase, a managed Postgres database hosted on AWS infrastructure.
Login emails go through Resend, which does not store or have access to your engagement data.
The site is served over HTTPS only, and browsers are told to refuse unencrypted connections. Pages cannot be embedded in other sites.
AI processing
Text from the intake form is sent to Anthropic's Claude API to draft the letter. We understand it is processed transiently and is not used to train Anthropic's models.
E-signature and payments
Signing is handled through DocuSeal. Your client signs from a link sent to their email, with no account needed. Signed PDFs are stored and downloadable from your dashboard.
Stripe handles payment details. EngageDraft never stores full card numbers.
Retention and deletion
We keep your data while your account is active. Ask us to delete it and it is removed from active systems within 30 days, with backups purged within 90 days.