BoardClerk — Privacy Policy

Effective date: July 23, 2026 (Beta)

1. Who we are and scope

This policy explains how BoardClerk ("we", "us") handles information when community association boards use our service at boardclerk.io. It covers board members who create accounts ("users") and information about homeowners that Associations process through the service ("association records"). For association records, we act as a service provider processing data on the Association's instructions; the Association is responsible for its lawful basis to use homeowner information for association business.

2. Information we collect

Account information: name, email, password/authentication data, role, Association name and state.

Association records you provide: governing documents; correspondence routed to your service inbox address (sender, content, attachments); meeting audio you upload and its transcripts and minutes; homeowner names and mailing addresses you add for association mail; violation records you create; documents generated by the service.

Payment information: handled by Stripe; we store subscription status, plan, and billing metadata — we never see or store full card numbers.

Usage and technical data: log data, feature usage counts, token/processing usage for plan limits, device and browser information, and cookies necessary for sign-in and session security. We do not use advertising cookies or sell data. We do not use third-party analytics that profile you across sites.

3. How we use information

To provide the service: storing and searching your documents, generating AI answers and drafts, transcribing meetings, maintaining compliance calendars, printing and mailing letters you approve, sending service email (magic links, digests, receipts), enforcing plan limits, and providing support. To protect the service: security, fraud and abuse prevention, and audit logging. To improve the service: aggregated, de-identified statistics only. To communicate: service announcements and, with your consent, product updates.

AI processing: content you submit is processed by our AI providers (Anthropic, OpenAI) and transcription provider (Deepgram) via their APIs to generate the requested output. Under our API terms with these providers, your content is not used to train their models.

We never sell personal information, and we never use association records for advertising.

4. Who can see what — including our own access

Within your workspace, access follows board roles set by your Association. Homeowners do not have accounts and cannot access the workspace.

Our administrative access is two-level by design. Level 1 (operations): we can see account/subscription status and usage counts — never the content of your documents, email, or minutes. Level 2 (support): content access is possible only in an explicit support session, requires a recorded reason, and every content view is logged. These access logs are retained and auditable. We will make support-access history visible to workspace admins in-product.

5. Sharing and subprocessors

We share information only with service providers that help us run BoardClerk, under contracts limiting their use to providing the service:

ProviderPurpose
Vercelapplication hosting
Supabasedatabase, authentication, file storage
AnthropicAI text processing
OpenAIembeddings (document search)
Deepgrammeeting transcription
Stripepayments and billing
Lobprinting and mailing physical letters
Resendtransactional email

We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer (with notice). We will update this table when subprocessors change.

6. Retention — written to match how the product actually works

7. Security

Data is encrypted in transit (TLS) and at rest. Access within the application is isolated per workspace at the database level (row-level security). Payment credentials are held by Stripe, OAuth-style secrets are stored encrypted, and financial ledgers are append-only. No system is perfectly secure; we will notify affected Associations of a breach as required by law.

8. Your choices and rights

Board users can access, correct, export, or delete account data via the app or by emailing us. Associations control their association records: export is available in-product; deletion requests are honored per Section 6. Depending on your state (e.g., California), you may have additional rights — to know, delete, correct, and non-discrimination; we honor these requests regardless of threshold applicability. We do not sell or "share" personal information as defined by the CCPA.

Homeowners whose information appears in association records (e.g., mailing addresses, correspondence) should direct requests to their Association, which controls those records; we assist Associations in fulfilling them.

9. Children

The service is for adults conducting association business and is not directed to children under 18; we do not knowingly collect children's information.

10. International processing

Our infrastructure processes data in the United States. Our team may access systems (per Section 4's access model) from outside the United States. By using the service, Associations authorize this processing.

11. Changes

Material changes will be announced by email or in-app at least 14 days before taking effect. The current version always lives at boardclerk.io/privacy.

12. Contact

Privacy requests and questions: support@boardclerk.io