Legal

Privacy Policy

Effective and last updated: September 21, 2026

This Policy describes what information moves through ProcessGround, what is stored, which service providers help process it, and the choices available to account holders. It is intended to make the document-processing workflow transparent rather than imply that all processing happens only on our own servers.

Section 1

Scope and operator

This Privacy Policy explains how Cinder Coach LLC, a Colorado limited liability company, collects, uses, discloses, retains, and protects information when operating ProcessGround. It applies to our website, authenticated application, diagram-generation services, billing features, and related support communications.

For account, billing, website, and service-operations data, Cinder Coach LLC determines the purposes and means of processing. When a business user submits documents containing another person's information, that user is responsible for having authority to process it, and we process it only to provide the requested service.

Section 2

Account and identity information

Clerk provides authentication for ProcessGround. We receive and store your Clerk user identifier, primary email address, name if provided, account timestamps, and whether and when current legal documents were accepted. Clerk processes session tokens, verification codes, authentication events, and essential cookies needed to keep you signed in and protect your account.

We do not offer social login, password storage, or phone authentication for the MVP when the Clerk application is configured as intended. Clerk may retain additional authentication and security information under its own privacy documentation.

Section 3

Uploaded documents and generated files

Customer Content can include a process name, process documentation in DOCX, PDF, or TXT format, optional risk and control information in XLSX or CSV format, and the structured process model generated from those materials.

Uploaded file contents and generated Draw.io, Visio, and workbook files are processed in server memory for the request and returned to your browser. ProcessGround does not intentionally persist those file contents or generated files in its Neon application database or provide a diagram-history repository. You are responsible for storing downloaded output you want to keep.

To provide reproducible reruns, we retain an encrypted normalized analysis for up to 30 days for the account that created it. This normalized record can include extracted flows, steps, roles, phases, source references, mappings, findings, and a semantic fingerprint, but not the original uploaded files or generated download files. It is isolated by account and cannot be reused by another customer.

We store limited, content-free generation metadata described below. Process names, uploaded filenames, extracted text, evidence snippets, model responses, and generated file contents are not intentionally stored in generation-event or diagnostic records.

Section 4

OpenAI processing

To extract process structure, map supplied risks and controls, and verify the proposed flow, we transmit process document content and relevant structured risk/control data to the OpenAI API. PDFs may be transmitted in their original digital form; other supported formats are parsed into a structured or text representation before transmission.

We use OpenAI's Responses API with structured outputs and store:false. Model identifiers are fixed by the versioned ProcessGround quality profile and recorded in content-free cost telemetry. OpenAI states that API data is not used to train its models unless the API customer explicitly opts in. Under OpenAI's default controls, abuse-monitoring logs may contain prompts, responses, and related content for up to 30 days, unless law requires longer retention. We have not promised Zero Data Retention and users should assume this default vendor retention applies. Review the currentOpenAI data controls.

Cinder Coach LLC does not use Customer Content to train a proprietary model, sell it, or build advertising profiles. We may use aggregated or deidentified operational measurements, such as token cost, duration, and success rates, to operate and improve the service.

Section 5

Billing, purchase, and subscription information

Stripe hosts checkout and billing management. We receive and store limited information such as your Stripe customer, Checkout, payment, and subscription identifiers; billing email, name, and address; selected price; Starter purchase and expiration dates; subscription status and billing periods; cancellation status; and quantity. If you choose to cancel Professional, you may optionally provide a cancellation reason and short comment. ProcessGround sends that feedback to Stripe with the subscription update and does not copy it into the application database. Stripe may provide receipts and collect a billing address.

ProcessGround does not receive or store complete payment-card numbers or card security codes. Stripe processes payment credentials, fraud signals, invoices, and transaction records under its own privacy terms.

Section 6

Usage and operational metadata

Neon Postgres stores the information needed to operate account limits and billing, including:

  • plan, Starter expiration or billing-period key, generation limit, used count, and remaining allowance;
  • successful-generation timestamp, analysis mode, package status, file types, and non-identifying size buckets;
  • whether optional risk/control data was supplied, without storing its filename or contents;
  • OpenAI model and processing stage, input and output token counts, cached tokens, estimated cost, and duration;
  • account-to-Stripe linkage and subscription state; and
  • version, cryptographic document hash, consent type, plan, price, Stripe Checkout Session, and timestamp of legal or commercial acceptance.

Source and generated files are not intentionally persisted in the ProcessGround application database. We do not intentionally store generated diagram markup or downloaded files in operational tables. Encrypted normalized analyses are stored separately for up to 30 days as described above; application logs do not intentionally contain prompts, extracted text, risk/control rows, or model responses.

Section 7

Technical information, logs, and cookies

Vercel, Clerk, Stripe, OpenAI, Sentry, and related infrastructure may automatically process IP address, browser and device information, timestamps, request paths, response status, security events, and similar technical data to deliver, secure, troubleshoot, and prevent abuse of their services. We do not intentionally place document contents in application logs.

Sentry provides operational error and performance monitoring. ProcessGround configures Sentry to receive redacted error reports and a limited sample of performance traces, such as route, runtime or browser type, response status, stack trace, and timing. We disable session replay, Sentry logs, request and response bodies, cookies, HTTP headers, URL query parameters, stack-frame variables, AI prompts and responses, and database query values. Uploaded files, extracted document text, risk/control rows, and generated files are not intentionally sent to Sentry.

Vercel Web Analytics provides anonymous, aggregate measurement of page views, referral sources, campaign parameters, device and browser categories, approximate location, and content-free product-funnel events such as checkout started or confirmed. It does not use third-party cookies or create a profile that ProcessGround can use to identify an individual visitor across websites. We do not send names, email addresses, Clerk or Stripe identifiers, uploaded content, process names, filenames, prompts, model responses, or generated files in analytics page paths or custom-event properties.

Clerk uses cookies and browser storage that are necessary for authentication and session security. The site also requests font styles from Fontshare, which receives ordinary network-request information. We do not use advertising cookies, behavioral advertising pixels, or ad-platform tracking tags. If that changes, we will update this Policy and provide any legally required choices before deployment.

Section 8

How we use information

We use information to:

  • authenticate users and maintain account security;
  • parse documents and generate requested process-flow files;
  • map risks and controls only when a user supplies that data;
  • measure usage, enforce Starter and Professional allowances, and restore approved credits;
  • provide public sample downloads without processing personal documents;
  • create one-time or subscription checkout sessions, synchronize purchases, provide billing management, and understand optional cancellation feedback;
  • measure aggregate page visits, referral sources, campaign performance, and content-free conversion events;
  • operate, test, troubleshoot, secure, and improve reliability and cost efficiency;
  • respond to support, legal, and privacy requests;
  • detect fraud, abuse, prohibited content, and violations of our Terms; and
  • comply with law, enforce agreements, and establish or defend legal claims.

We do not use Customer Content for unrelated marketing or model training.

Section 9

How we disclose information

We disclose information only as reasonably necessary to:

  • Clerk for identity, authentication, email verification, and session management;
  • Neon for encrypted Postgres hosting of account, usage, billing, acceptance, and telemetry records;
  • OpenAI for request-time document analysis, structured extraction, mapping, and verification;
  • Stripe for checkout, subscription billing, cancellation feedback, fraud prevention, receipts, and the customer portal;
  • Vercel for application hosting, delivery, request processing, infrastructure logs, and anonymous aggregate web analytics;
  • Sentry for redacted application-error reporting and sampled performance monitoring;
  • Fontshare for delivery of the website's font stylesheet;
  • professional advisers under confidentiality obligations;
  • government, regulators, courts, or other parties when legally required or necessary to protect rights and safety; or
  • a buyer or successor during a merger, financing, reorganization, or sale, subject to appropriate safeguards.

ProcessGround does not automatically send generated files to Draw.io, Lucidchart, or Microsoft. Those companies receive a file only when you choose to open, upload, or import it into their products.

Section 10

No sale or targeted advertising

We do not sell personal data for money or other valuable consideration, share it for cross-context behavioral advertising, or process it for targeted advertising. We do not use personal data to make decisions that produce legal or similarly significant effects through automated profiling. Because we do not conduct these activities, there is currently no sale or targeted-advertising opt-out mechanism beyond contacting us with questions.

Section 11

Retention

We apply the following retention approach:

  • uploaded file contents and generated files are not intentionally persisted in the application database;
  • encrypted normalized analyses are retained for up to 30 days to support reproducible, no-charge exact reruns;
  • generation metadata and associated AI cost telemetry are retained for up to 24 months;
  • account profiles, legal acceptances, and usage counters are retained while the account remains active;
  • billing and transaction records may be retained for up to 7 years after the customer relationship ends;
  • support and privacy communications are generally retained for up to 24 months after resolution unless needed longer for a dispute or legal duty; and
  • service providers retain information under their own policies, account settings, and legal obligations, including OpenAI's default abuse-monitoring period described above, Sentry's configured event-retention period, and Vercel's analytics retention for the applicable plan.

We may retain information longer when required by law, needed to resolve a dispute, protect security, enforce agreements, or preserve a legal claim. Where practical, we delete or deidentify information when the applicable purpose expires.

Section 12

Account deletion

You can request permanent deletion from the authenticated account page. Deletion immediately cancels an active Stripe subscription without a prorated refund, removes the Clerk identity, and deletes the app profile, usage counters, legal-acceptance records that are not legally required, encrypted canonical analyses, generation metadata, and associated OpenAI cost telemetry.

We retain only billing and transaction records, including Starter purchase and subscription records, reasonably needed for tax, accounting, fraud, chargeback, and legal obligations, and unlink them from the deleted application account where practical. Deleting an account does not remove files you previously downloaded or files you independently uploaded to third-party diagram tools.

Section 13

Security

We use reasonable administrative, technical, and organizational safeguards appropriate to an early-stage SaaS product, including managed authentication, encrypted HTTPS transport, TLS-protected database connections, restricted production secrets, authenticated routes, webhook signature verification, and data minimization.

No online service can guarantee absolute security. You are responsible for controlling access to your email, device, downloaded files, and destination diagram accounts. Contact us promptly if you suspect unauthorized access involving ProcessGround.

Section 14

Your privacy choices and rights

Depending on where you live and subject to legal exceptions, you may request access to, correction of, deletion of, or a portable copy of personal data we control. You may also ask about our processing or appeal the denial of a privacy request.

Submit a request to kevin@processground.com. Use the subject “Privacy Request” or “Privacy Appeal” and describe the right you want to exercise. We will verify your identity using information associated with your account and respond within the period required by applicable law. Authorized agents may be required to provide signed authority and confirm the consumer's identity. We will not discriminate against you for exercising applicable rights.

You can update certain profile details through Clerk, manage billing through Stripe, cancel renewal through the account page, and permanently delete the account through the deletion control.

Section 15

US state privacy notices

Residents of states with comprehensive privacy laws may have rights to know or access categories and specific pieces of personal data, correct inaccuracies, delete data, obtain portability, and opt out of certain sales, targeted advertising, sharing, or significant automated profiling. We honor applicable rights even when a statutory threshold or exception must first be evaluated.

The categories collected are identifiers, customer records, commercial/subscription information, internet or network activity, professional process content, and inferences produced to generate a requested diagram. We do not sell these categories or use them for targeted advertising. Colorado residents can review theColorado Attorney General's privacy guidance.

Section 16

Children

ProcessGround is a professional service and is not directed to children under 18. We do not knowingly create accounts for children or permit users to submit children's personal data. If you believe a child's information was submitted, contact us so we can investigate and delete it as appropriate.

Section 17

United States processing

ProcessGround is operated from the United States and uses service providers that may process information in the United States and other locations. If you access the service from outside the United States, your information may be transferred to jurisdictions with different data-protection laws. The MVP is not specifically marketed as an EU, UK, or regulated-sector service and does not currently offer a customer data-processing addendum.

Section 18

Changes to this Policy

We may update this Policy when the product, vendors, data practices, or law changes. We will post the revised Policy and update the effective date. For material changes, we will provide additional notice through the service or account email and may require renewed acceptance before continued generation or new purchases.

Section 19

Contact and appeals

ProcessGround is owned and operated by Cinder Coach LLC, a Colorado limited liability company. Send privacy questions, requests, complaints, or appeals to kevin@processground.com. We do not publish a street address for the MVP; email is the designated legal and privacy contact method.