Privacy Policy
The sections below are a first, AI-assisted draft, written only from facts already true and already documented elsewhere in this product — they have not been reviewed by a qualified lawyer, and none of this is legally in force yet.
What we collect
The client and policy information your own team enters into Redline — names, contact details, policy and renewal data, documents you upload, and the notes and communications you record — stored under your own brokerage's account, never mixed with any other brokerage's.
Account details for each person on your team — name, email, and a password, stored only as a one-way hash, never in a form anyone could read back out.
A security-relevant activity log — sign-ins, password changes, two-step verification changes, data exports — kept in a tamper-evident form so it can be independently verified. See our Security & trust page for exactly what that log covers and how it's checked.
How we use it
Data you and your team put into Redline is used for exactly one purpose: running Redline for your own brokerage. We don't sell client data, and we don't share it with third parties for marketing or any other purpose. This marketing site itself carries no tracking scripts and no third-party analytics, on the same principle.
Redline ships with its AI provider slot set to "none," and every AI-adjacent feature already works fully without one (server-filled templates, computed answers, real keyword/full-text search). If a provider is ever turned on, it answers or drafts using your own data for your own request, in the moment — never to train a shared model on it.
Where it's stored
Today, Redline's entire database lives in a single SQLite file on whichever machine runs it — there's no data spread across a dozen third-party services. That file, and every stored document, is encrypted at rest once a database encryption key is configured — mandatory for any real, production deployment. A signed-in owner can check this brokerage's own real, live encryption status any time from Settings → Security.
Your rights
You can access, correct, or delete the data your brokerage has entered into Redline at any time, from inside the product. You can also export everything — every client, policy, renewal, task, claim, communication, and stored document — as a single download, any time you want it, with no advance notice needed from us.
If your brokerage ever leaves Redline, that same export is still available to you, and you keep read-only access to look things up afterward. Your data is yours; we don't hold it hostage.
Data retention
Redline keeps a rolling window of encrypted nightly backups, tested by real periodic restores, as protection against data loss — see our Security & trust page for how those backups are verified.
Still open — not yet decided: Beyond that backup window, no fixed policy has actually been decided yet for how long client data is kept after a brokerage's account is closed, or exactly what continued "read-only access" means in practice over time. This is a real decision the product owner still needs to make, not yet a stated policy.
Contact
Questions about this privacy policy, or a request relating to your own data, can be sent to [email protected] — a real person reads every message.
Need something specific before the real version is ready? Get in touch.