PullPermits.ai

Legal

Privacy Policy

Effective 2026-07-12 · Version 0.1-fable · Questions: hello@pullpermits.ai

1. Who We Are and What This Covers

This policy is published by PullPermits LLC, a Georgia limited liability company ("PullPermits"). It covers both of our sites: pullpermits.ai (the marketing site) and app.pullpermits.ai (the product). It applies to customers, visitors, and waitlist subscribers. Questions and requests: hello@pullpermits.ai. Effective date: 2026-07-12.

These capitalized terms mean the same thing here as in our other documents:

  • "Platform" means the PullPermits software service operated by PullPermits LLC at pullpermits.ai and app.pullpermits.ai, including its AI-assisted drafting and filing automation.
  • "Contractor" (or "you") means the licensed Georgia contractor — or the business entity holding the license-qualifying relationship — that holds the account.
  • "Jurisdiction" means a city or county permit office the Platform supports.
  • "Filing" means one permit application prepared and submitted (or to be submitted) to a Jurisdiction through the Platform.
  • "Approve & File" means the in-product step where the Contractor reviews the drafted application, affirms that the facts in it are true and accurate, and authorizes the Platform to submit it to the Jurisdiction.
  • "Authorization" means the Limited Agency & Permit-Filing Authorization the Contractor signs at onboarding (including its Exhibit A, Portal Account & Credential Access Consent).
  • "Portal Account" means the Contractor's own account on a Jurisdiction's online permitting portal.

2. Data We Collect

  • Identity documents — your Georgia license card, driver's license, and business license (images or PDFs), uploaded at onboarding and stored encrypted at rest in a private vault.
  • OCR-extracted fields — names, license numbers and classes, and expiry dates read from those documents. Extraction happens server-side.
  • EIN — your business's federal employer identification number.
  • Contact data — business name, your name, email, phone.
  • Payment data — Stripe payment tokens only. We never see or store card numbers; cards are entered directly with Stripe.
  • Portal credentials — when collected, credentials for your Portal Accounts are stored encrypted, used only as consented to in the Authorization's Exhibit A, and never written to logs.
  • Filing artifacts — the applications we draft and submit, the signed Authorization, and screenshots of portal sessions. These are our record of what was filed.
  • Audit logs — who did what, when: document uploads and reads, your Approve & File approvals, payment events, and system actions.
  • Waitlist emails — the email address you give us on the marketing site.

Job-site data (third-party personal data)

To prepare a Filing you give us job facts: the job address, a description of the work, and often the property owner's or customer's name. That is personal data about third parties — your customers, not you. By supplying it, you warrant that you may share it with us for permitting. We process job-site data only to prepare and file the permit (and to keep the resulting filing records). We never use it for marketing.

3. How We Use Data

We use the data above to: provide the service; draft and file permits; verify licenses against the Georgia Secretary of State; bill you; support you; secure and audit the Platform; and comply with the law.

We do not sell personal data. We do not share personal data for third-party advertising.

4. Who Processes It for Us

VendorPurposeData touched
AnthropicDocument OCR and application drafting (API; Anthropic does not train on our API data under its commercial terms)Identity documents, job facts, draft applications
StripePaymentsName, email, payment tokens
SupabaseDatabase, auth, and file storageAccount data, encrypted documents, filing records
VercelHosting and cookieless analyticsRequest and usage data
Twilio (when live)SMS status updatesPhone number, message content
ResendEmailEmail address, message content
SignWell (when live)E-signature of the AuthorizationSigner name and email, the signed document
Browserbase (when live)Portal automation sessionsFiling data entered into portals, session recordings and screenshots
Google Workspace, Instantly, OutscraperBusiness outreach operations — marketing side only, never customer filing dataBusiness contact information

Each vendor publishes its own subprocessor list; our internal register tracks the data-processing agreements.

Separately: Jurisdictions receive what a permit application requires — your license details, job address, job facts, and owner/customer name as the application form demands. That is the product working as designed, not third-party sharing.

5. How Long We Keep It

This table is our retention schedule:

Data classKept forTrigger
Identity documents & OCR-extracted fields (incl. EIN)Account closure + 30 daysDeleted after the closure window
Portal credentialsUntil Authorization revocation, or account closure + 30 daysWhichever comes first
Job & filing records (drafted applications, portal screenshots, signed Authorization)7 yearsFrom the Filing — they document what was filed with a government office
Payment ledger & invoices7 yearsFrom issuance — financial records
Audit logs7 yearsFrom the logged event
Waitlist emailsUntil unsubscribe, or 24 months of inactivityWhichever comes first
Account & contact dataAccount closure + 30 daysExcept where it appears inside records retained above
Auth/session dataSupabase session lifetimeExpires with the session

You can also request deletion sooner — see section 8. Automated enforcement of this schedule is on the engineering roadmap; until then it is applied on request and at account closure.

6. Security

  • Identity documents and credentials are encrypted at rest (AES-256-GCM envelope encryption).
  • Data moves over TLS in transit.
  • Access to stored documents is audit-logged.
  • Service access follows least privilege.

No system is perfectly secure, but these are the controls actually in place — we describe them as they are.

7. Cookies & Analytics

  • pullpermits.ai uses Vercel Analytics, which is cookieless.
  • app.pullpermits.ai uses strictly-necessary auth cookies and localStorage to keep you signed in.
  • Neither site uses advertising or cross-site tracking cookies — which is why there is no cookie banner.

8. Your Rights

Email hello@pullpermits.ai to access, correct, or delete your data. We honor these requests for everyone, even where Georgia law mandates none. We don't currently offer California- or EU-specific rights processes because we serve Georgia businesses only.

One limit: we can't delete records that the law or a filed permit requires us to keep (see the retention table in section 5) — filing records document what was submitted to a government office.

9. If There's a Breach

If a data breach affects your unencrypted personal information, we will notify you without unreasonable delay, consistent with Georgia's breach-notification law (O.C.G.A. §10-1-910 et seq.) and our incident-response plan.

10. Children

The Platform is for business users 18 or older. We don't knowingly collect children's data.

11. Changes to This Policy

We'll post updates on this page and email account holders about material changes.

12. Change Log

VersionDateChange
0.12026-07-12Initial version.