HoldRescue emblemHoldRescue

Privacy Policy

Effective 2026-01-01 (Edit before launch).

1. What we collect

Account data: your email address and a password hash (we never store your plaintext password).

Case data: the answers you give in the intake, the business/contact details you enter, your case timeline entries, and the letters generated from them. This is necessary to provide the service — it is the content of your documents.

Billing data: your Stripe customer ID, subscription status, and purchase state. Card details are handled entirely by Stripe and never reach our servers.

Usage data: standard server logs (IP address, request time) used for security and rate limiting.

2. How we use it

To provide the service: generate your diagnosis, letters, and case tracking. To process payments and enforce plan limits. To secure accounts (rate limiting, session management). We do not sell your data, and we do not use your case content to advertise to you.

3. Legal bases (EEA/UK users)

Performance of contract (providing the service), legitimate interests (security, abuse prevention), and consent where required. You may request access, correction, export, or deletion of your personal data at any time via the contact below.

4. Sharing

We share only what is necessary: Stripe (payment processing), our database and hosting providers (infrastructure), and — when you choose to send them — the letters you generate, which you send yourself. We do not contact platforms or regulators on your behalf.

We may disclose information if required by law or to protect our rights.

5. Retention

Case data is retained while your account is active so your case history remains usable. You can delete individual cases; deleting your account deletes your personal data within 30 days, except where retention is legally required.

6. Security

Passwords are hashed with bcrypt; sessions use signed, httpOnly cookies; data is stored in an access-controlled database. No system is perfectly secure — please use a unique password.

7. Cookies

We use one essential cookie: your session cookie (httpOnly, SameSite=Lax, 7 days). No advertising or tracking cookies are used.

8. Contact

HoldRescue Inc. (Edit before launch) — support@holdrescue.example.com (Edit before launch). Entity address and contact details are placeholders marked "Edit before launch" until launch.