Back to home

Privacy Policy

DeliverFirm

Last updated: June 2026

Effective date: June 2026

Who We Are

DeliverFirm ("we", "us", "our") is operated as an independent software product accessible at deliverfirm.com. DeliverFirm is a scope-creep analysis tool that helps freelancers identify whether client requests fall within their agreed project scope.

If you have questions about this policy, contact us at: deliverfirm@gmail.com

What Information We Collect

2.1 Information you provide directly

Account information: Your email address and password when you create an account.

Profile information: Your name, freelance pricing model, and hourly rate or unit rate (used to calculate your ROI dashboard figures).

Scope documents: The project scope text or contract you paste or upload per project. This is the core content the app analyses.

Client messages: The client messages you paste into the scope checker for analysis.

Client records: Names and email addresses of clients you add to the Clients section.

Change orders: Details of change orders you create, including descriptions and pricing.

Uploaded files: PDF, PNG, or JPG files you upload to extract scope text from.

2.2 Information collected automatically

Usage data: Pages visited, features used, and actions taken within the app (used to improve the product).

Authentication tokens: Session data to keep you logged in securely.

Payment information: We do not store your card details. Stripe, our payment processor, handles all payment data directly. We receive only a Stripe customer ID and subscription status.

How We Use Your Information

We use your information solely to operate and improve DeliverFirm. Specifically:

  • To provide the scope analysis service - your scope documents and client messages are sent to the Claude API (operated by Anthropic) for classification and reply generation.
  • To store your projects, checks, and history so you can access them across sessions.
  • To calculate and display your ROI dashboard figures.
  • To process your subscription via Stripe.
  • To send transactional emails (account confirmation, password reset, subscription receipts) via Resend.
  • To improve the product based on aggregate, anonymised usage patterns.

We do not sell your data. We do not use your data for advertising. We do not use your scope documents or client messages to train AI models.

How Your Data Is Processed by AI

DeliverFirm uses the Claude API, operated by Anthropic (anthropic.com), to analyse scope documents and client messages and generate verdicts and reply drafts.

When you submit a scope check or use the Scope Improver:

  • Your scope text and client message are transmitted to Anthropic's API over an encrypted connection.
  • Anthropic's data usage policies apply to data processed through their API. As of the date of this policy, Anthropic states that API inputs and outputs are not used to train their models by default. You can review Anthropic's privacy policy at anthropic.com/privacy.
  • We do not store the raw API responses beyond what is needed to display and save your results.

Important: Do not paste content that you are prohibited from sharing with third parties under a non-disclosure agreement or other confidentiality obligation without first confirming that doing so is permitted under that agreement.

Data Storage and Security

  • All user data is stored in Supabase, a managed database platform with encryption at rest and in transit.
  • Uploaded files are stored in a private Supabase storage bucket. Files are not publicly accessible.
  • Access to your data is restricted by Row Level Security - you can only access data belonging to your own account.
  • We use HTTPS for all data transmission.
  • Passwords are hashed and never stored in plain text.
  • We do not have access to your Stripe payment card details at any point.

While we take reasonable steps to protect your data, no internet transmission or storage system is 100% secure. We encourage you to use a strong, unique password for your account.

Data Retention

  • Active accounts: We retain your data for as long as your account is active.
  • Deleted projects: Projects you move to Trash are soft-deleted and can be restored. Permanently deleted projects are removed from our database within 30 days.
  • Closed accounts: If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (for example, Stripe transaction records).
  • Uploaded files: Files you upload are retained until you delete the associated project or your account.

Sharing Your Information

We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

We share data only with the following service providers, strictly to operate DeliverFirm:

  • Anthropic (Claude API) - AI scope analysis and reply generation - anthropic.com/privacy
  • Supabase - Database, authentication, and file storage - supabase.com/privacy
  • Stripe - Payment processing and subscription management - stripe.com/privacy
  • Resend - Transactional emails - resend.com/privacy
  • Vercel / Cloudflare - Hosting and content delivery - vercel.com/legal/privacy-policy

We may disclose your information if required to do so by law, or to protect the rights, property, or safety of DeliverFirm, our users, or the public.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to certain types of processing.

To exercise any of these rights, contact us at deliverfirm@gmail.com. We will respond within 30 days.

If you are located in the European Economic Area or United Kingdom, you have rights under GDPR/UK GDPR. If you are located in California, you have rights under the CCPA.

Cookies

DeliverFirm uses only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

Children's Privacy

DeliverFirm is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, contact us at deliverfirm@gmail.com and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a notice in the app before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent version.

Continued use of DeliverFirm after changes take effect constitutes acceptance of the updated policy.

Contact

For any privacy-related questions, requests, or complaints:

Email: deliverfirm@gmail.com

Website: deliverfirm.com