Privacy Policy
Last updated: August 2026
1. What We Collect
When you create an account, we collect your name, email address, and a hashed password. When you use our service, we collect usage data including the templates you upload, documents you generate, and your API activity. We also collect billing details through Stripe -- we never store full card numbers on our servers.
Uploaded template files and generated documents are stored in secure S3-compatible object storage. Documents are automatically deleted after their expiry window (which depends on your plan).
2. How We Use Your Data
We use your data to provide, maintain, and improve the BulkRender service. This includes processing document generation requests, sending transactional emails (confirmations, alerts, invoices), and enforcing plan limits. We do not sell your data to third parties.
Aggregate, anonymised analytics help us understand how the product is used so we can make it better.
3. Third-Party Services and Subprocessors
We share data with the following subprocessors only to the extent necessary to operate the service:
- Stripe -- payment processing. Card data goes directly to Stripe and never touches our servers.
- HubSpot -- CRM. We sync your organisation name, email, and plan to help us manage our customer relationships. This data is only used internally.
- PostHog -- product analytics. Session and usage events are collected to understand feature adoption. No personally identifiable content from your documents is sent to PostHog.
- Railway object storage (S3-compatible) -- your uploaded templates and generated documents are stored in encrypted object storage hosted on Railway.
- Resend -- transactional email delivery (invitations, verification codes, document delivery, receipts). Recipient email addresses and message content pass through Resend to reach your inbox.
- AI providers (OpenAI, Anthropic, Google) -- power the optional AI template generator. When you use it, the description you type is sent to the configured provider to produce the template. Your generated documents and their data are never sent to AI providers.
4. AI Assistant Connections
You can connect BulkRender to AI assistants such as Claude through OAuth. When you approve a connection, the assistant can act on your account within the permissions you approved: viewing templates, generating documents (which uses your credits), and, if granted, managing templates. We record which app you connected, when, and the permissions granted. The AI assistant provider processes the prompts you write and the tool results returned to it under its own privacy policy. You can disconnect any app at any time from Settings, Integrations, which immediately revokes its access tokens.
5. Data Retention
Generated documents are automatically deleted after their plan-defined expiry window. You can also delete documents manually at any time from the dashboard. Account data is retained while your account is active. You can delete your own account at any time from Settings, Profile. If you are the last active member of your organization, deleting your account closes the organization: every credential is revoked immediately, your subscription is canceled, and all of the organization's data is automatically and permanently deleted 30 days later, except where retention is required by law (for example, invoicing records). Contact us at the address below within that window if you need to restore a closed organization.
6. Your Rights
You have the following rights over the personal data we hold about you:
- Access and correction -- request a copy of your data and correct anything that is inaccurate.
- Deletion -- delete your account and data at any time (see Data Retention above).
- Data portability -- request a copy of your personal data in a machine-readable format.
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
7. Security
All data is transmitted over HTTPS. Passwords are hashed before storage. API keys are encrypted at rest. Access to production systems is restricted to authorised personnel only.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by email or via a notice in the dashboard. Continued use of the service after the effective date constitutes acceptance of the updated policy.
9. Contact
Questions about this policy? Email us at support@bulkrender.com.