Privacy

Effective: August 22, 2026

Documents you upload

Uploaded files, including work-order PDFs and the order-history export you may import as your material price book, are processed entirely in memory on our server and handed straight back to you. The file itself is never written to disk, and neither is the workbook we build from it. We do not index your documents, we do not review them, and we never sell them or use them to build anything for anybody else. Once the response is sent, that document is gone from our systems. Our multipart parser is configured to keep upload parts in memory rather than spooling them to a temporary file.

Some narrower things are kept, and they are named here rather than left to be discovered further down. A few facts about a job reach our server logs, listed in full under “Cookies and analytics” at the end of this page. A work order you build through the review screen leaves one audit row, listed field by field under “What we do store”. And if you sign in, the jobs you save and your price book are kept on purpose, because keeping them is what puts your work on your other devices; the same section says what they hold, and both come back out again whenever you want them gone.

Your material prices

If you import an order history, what we read from it (item names, the price you paid, and the supplier) is returned to your browser and kept in your own device's local storage. If you are signed in to an account, a copy is also saved to your account so the same price book is there on your other devices. That copy stays on our server until you delete it. If you are not signed in, it is sent to us only at the moment you build a workbook and is discarded as soon as that workbook is built. We never sell it and never use it to build any kind of shared or aggregate pricing data. The one place it goes is the account database described under “What we do store” below. It is your purchasing history and your negotiated pricing. Signed in, the button on the home page reads “Remove it from this device and my account”, and that is what one click does: this device's copy and the account's copy both go. Signed out, it reads “Remove it from this device” and there is no other copy to remove.

Automatic reading of unrecognized formats (important)

For a work order whose layout we recognize, including Invitation Homes, the entire process happens on our own server and the document text never leaves it.

If your work order is in a layout we don't yet recognize, we can read it automatically. That sends the text of that document to Anthropic (the maker of the Claude AI model), which processes it under its commercial terms and is contractually barred from training its models on it.

This never happens unless you ask for it, per upload. We only ask once we have actually failed to recognize a layout, so the question is always about a specific document you have just uploaded rather than a preference set in advance. The box is unticked every time, and your answer is not remembered. The next work order asks again, even if it is the same layout from the same company. If you don't tick it, that work order is declined and nothing is transmitted; we would rather refuse a conversion than send a document you did not intend to send.

Why we are careful about this: a work order belongs to the property owner who issued it, not to the contractor who received it. Your agreement with that owner, not us, decides whether you may share it with a service provider. That is your call to make, which is why we ask rather than assume. If your agreement does not allow it, switch automatic reading off for your whole account under Your account and no upload can transmit, whatever gets ticked on a form.

Your order history is handled differently and more carefully. If our own reader can’t work out which column is which, we ask the same service to identify the columns. We send it only your file’s column headings and a description of each column’s shape (“this column holds money”, “this one holds dates”). The cell values are stripped out before the request is built, so no item, SKU, supplier or price you paid is transmitted. We do not send documents anywhere else, and recognized formats are never transmitted off our server. If you would rather no document ever leave our server, use only the supported formats listed on the home page, or ask us to add yours.

What we do store

License records: your license key, Stripe customer and subscription identifiers, subscription status, usage counts, which company’s work orders you told us you convert, and whether you have automatic reading switched on.

Two other things live in that same database, and neither is a licence field. When a work order we did not recognize is built through the review screen, we write one audit row for it: a one-way digest of the file name rather than the name itself, how many line items you approved, what those items added up to, what the document printed as its total, whether those two figures agreed, and whether you ticked the box saying you knew they did not. That row is the evidence behind Section 3 of the User Agreement, which is the whole reason it exists. We keep it for three years and then it is deleted. Section 17 of that agreement gives you one year to bring a claim, which is shorter, but that year runs from the day a claim arises rather than the day we built the workbook, and a claim brought by the property owner whose document it was is not under that section at all. Three years is Colorado’s own limit for a contract claim and it is the outer edge of when this row can still be the thing that answers one. Separately, if you answer the “what stopped you” question when a trial runs out, the reason you pick and anything you type in the box are stored on your licence record, and they go when that record goes.

If you create an account and sign in, we also store the jobs you save: the property address, the line items, your rates, and the costs and hours you enter as you work. That is what makes a job open on the truck and the office computer both. Your email address is held for sign-in.

You can take your data with you at any time, from your account page: Export downloads your price book and every job you have saved, as one file. It does not include your licence and billing record; email us and we will send you that. If the file ever has to stop short of your whole account we say so on screen rather than hand you a partial one quietly.

Delete, on the same page, removes every job in your account and your whole price book, straight away and for good, and closes the account itself: your sign-in email address goes with it. One thing holds it open, and that is a paid subscription that is still running, because your subscription record is attached to the account and removing it would leave your card being charged with nothing on our side to tie the charge to. Your jobs and your price book still go immediately in that case, and we say on screen that the sign-in stayed. Cancel the subscription and press the button again, or email hello@clevrdata.ai and we will do both, normally the same day, and tell you when it is done.

Deleting the account also removes the sign-in address and the live account records. To stop one person from repeatedly claiming the same promotional trial, we retain a keyed one-way digest made from the normalized email address. The marker becomes eligible for deletion after 24 months and is removed opportunistically when a later eligible operation runs cleanup. This is a cleanup threshold rather than a promise that every marker disappears at an exact time. We do not keep the email address in that marker, customers cannot access the marker, and it is used only to enforce the one-trial rule. Billing, tax, chargeback, and fraud records held by Stripe or required by law may remain for their applicable retention periods.

We also limit how many promotional trials can start from one network source in a day. For that check, the server makes a separate, domain-separated keyed HMAC from the trusted source IP address. The trial-control table stores only that pseudonymous digest, the UTC claim day, and an aggregate claim count. It does not store the raw IP address. Rows older than 31 days are eligible for deletion and are removed opportunistically when a later eligible operation runs the cleanup, so this is a cleanup threshold rather than a promise that every row disappears at an exact time. Basic server logs are separate and are described under “Local storage and operational monitoring” below.

Deleting is immediate in the database itself, and there is one lag behind it worth naming rather than leaving you to wonder. Supabase keeps a daily backup snapshot of that database for seven days, so rows you delete today sit inside those snapshots until the last one holding them rolls off. We do not read them and we do not restore from them to bring anything back, and once that last snapshot has aged out there is no copy of your jobs or your price book left with us. Section 12 of the User Agreement says the same thing.

The database behind your account is run by Supabase, which holds it for us under contract and uses it for nothing else. They are our subprocessor for your account data in the same way Anthropic is for a layout we do not recognize.

You can use SubCost without an account. Signed out, nothing in this section beyond the license record exists, and jobs never leave your device.

Payments

Payments are processed by Stripe. Your name, email, and payment details live with Stripe, not with us.

Local storage and operational monitoring

No advertising trackers. Your own browser's local storage holds your license key, any jobs you chose to "work on here" (including the costs and notes you type in the field), and your imported material price book. Signed out, that copy is the only one: it stays on your device and clearing it from the page it belongs to is the end of it. Signed in, it is a working copy of what is in your account, which is what makes a job open on the truck and in the office. Clearing your browser in that case empties the copy and leaves the account's, and signing in again brings it back. The controls described above, under “What we do store”, are the ones that remove it for good. Basic server logs (IP, timestamp, endpoint, status) exist for security and are rotated.

When you check the signup agreement, this browser briefly keeps the email address you entered with a timestamp so the acceptance can be attached to the account after email verification. That pending marker is removed when acceptance is recorded, when you sign out, or after 24 hours. It is never an authentication credential.

When operational error reporting is configured, Sentry receives technical error and performance information such as the route, request method, status, application release and environment, exception type, stack-frame locations, and timing. Before an event leaves SubCost we remove request bodies, query strings, cookies, user fields, IP-forwarding and referrer headers, credential headers, exception messages, source context, and local variables. Sentry is used to diagnose reliability and security problems, not to advertise to you or build a marketing profile.

Those logs are not empty of your work, and it would be easy and wrong to say they were. Five things off a job can appear in them. We log which company’s layout the work order was and how many line items it held. If it uses a trade name we have no phase for, we log that trade name, because a new one showing up is the first sign a company has changed its template. If the line items do not add up to the total printed on the document, we log both figures, and if the document prints no total at all we log what the items came to. And if the separate program that reads your file dies instead of answering, we log the first four kilobytes it printed on its way out: what kind of fault it was, and the file and line inside SubCost where it happened. We leave the fault's own message out on purpose, because a message about a spreadsheet can quote a cell of that spreadsheet. That is the entire list. The line items themselves never go in, nor the address, nor the file, and never your material price book. The one thing we cannot promise you is what a third-party reader library prints into that same four kilobytes as it dies; that is the one place a fragment of a file could reach a log.

Who holds any of this for us

We do not run all of this ourselves. The companies below run parts of it, and they are named here rather than left as “our subprocessors”, because a list you cannot read is not a disclosure. This is all of them, and what each one gets is what its own sentence says.

Anthropic gets the text of a work order, and only one in a layout we do not recognize, and only the ones you tick the box for. That is the transmission described under “Automatic reading of unrecognized formats” above; a layout we do recognize never leaves our server at all. The second path to Anthropic is a much narrower one and it stays narrow on purpose. When your imported order history has columns our own reader cannot work out, we send the column headings and a description of each column’s shape, and the cell values are stripped out before the request is built, so no item, SKU, supplier or price you paid goes with them.

Supabase runs the database behind your account and the sign-in service in front of it. That means the jobs you save, so the property address, the line items, your rates, and the costs and hours you type in the field; the copy of your price book that puts it on your other devices; and the email address you sign in with. Your subscription record is kept there as well, which is your license key, the Stripe identifiers and whether the subscription is running, so with an account that record exists in two places and this is one of them. It is the same database described under “What we do store”, and Supabase holds it for us under contract and uses it for nothing else.

Railway runs the machine this site is on and the disk attached to it. The license records described under “What we do store” sit on that disk: your license key, the Stripe identifiers, your counts and credits, whether automatic reading is switched on, the audit row for a work order you built through the review screen, and anything you typed in the box when a trial ran out. Your license key and the Stripe identifiers are also on the subscription record in Supabase described just above, and those two are the whole of where that pair is kept. The server logs described just above are on the same machine. Your uploaded work order and your material prices pass through that machine in memory while a workbook is being built, and neither one is written to its disk. Renting a machine is not the same as handing somebody your work, and Railway is not given yours to use.

An administrator can request a backup of the license ledger. That operation creates a plaintext snapshot in the container's temporary directory while it is opened for streaming. On the production Linux container its directory entry is removed as soon as the stream is opened. Failed attempts are deleted, and startup cleanup removes a snapshot left by an unexpected process stop. This temporary snapshot contains license and Stripe subscription identifiers, not uploaded work-order files.

Stripe takes the payment. Your name, your email address and your card details go to Stripe when you subscribe, they stay with Stripe, and we never see the card number. Stripe also uses what it collects to run its own payments and fraud checking, the way every card processor does, and its privacy notice covers that side of it.

Resend carries the email we send you. When your payment succeeds we email you your license key, so your email address and that key both pass through Resend on the way to your inbox. Signing in works the same way: the link or the code that gets you into your account is sent through Resend too, which is your address and a live credential in one message. We send no marketing through it and there is no mailing list here to be on.

Sentry receives the scrubbed operational error and performance data described above when monitoring is enabled. There are no advertising trackers or marketing analytics, and no fonts, scripts or images are loaded from an unnamed third-party server.

Data requests

Want your license record deleted, want a copy of your records, or have any privacy question? Email hello@clevrdata.ai.

← Back