Sub-processors

Last updated: September 23, 2026

To provide LetterScript, we share limited data with the third-party service providers (“sub-processors”) listed below. Each one processes only what it needs to perform its function. This list supplements our Privacy Policy; if our sub-processors change, we will update this page.

Sub-processorPurposeData involvedRegion
Amazon Web Services (AWS)Cloud hosting, encrypted document storage, database, and job queuesAll application data, encrypted at rest and in transitUnited States
Amazon BedrockAI processing — OCR, field extraction, classification, and chat over your documentsDocument contents and chat messages (not used to train AI models)United States
Amazon SESEmail delivery and inbound per-transaction mailboxesSender/recipient email addresses, message contents, and attachmentsUnited States
ResendTransactional email delivery (invites, reminders, notifications)Recipient email address and message contentsUnited States
StripeBilling and paymentsName, email, and billing details (card data is handled by Stripe; we never store it)United States
CloudflareBot protection (Turnstile) on sign-in and public formsA challenge token and your IP addressGlobal
PostHogProduct analytics and (masked) session replay to diagnose and fix issuesAn opaque user identifier and product-usage events; session recordings mask all text and inputs, and never include document contentsUnited States
SentryApplication error monitoringError diagnostics (stack traces, page URL, browser info); configured not to send personal data or document contentsUnited States
Google / Microsoft / AppleSign-in (OAuth)Email, name, and account identifierUnited States
TermlyAuthoring and hosting the source text of our legal policiesNone about you — our server fetches the policy text; Termly is not loaded in your browserUnited States
Follow Up BossCRM sync — only if you choose to connect itContact details you sync (names, emails, phone numbers, addresses)United States
CalendlyMeeting scheduling — only if you choose to connect itInvitee names, email addresses, and meeting detailsUnited States
Google / Microsoft CalendarCalendar sync of transaction deadlines and meetings — only if you choose to connect itCalendar event titles, times, and attendeesUnited States
SignWellDocument e-signature — only if you send a document for signatureDocument contents and signer names and email addressesUnited States
Anthropic (Claude)Reads the transactions you approve — only if you connect the LetterScript connector in ClaudeAnswers to the requests the assistant makes: transaction record values, deadlines, point-of-sale requirements, document titles, and cited excerpts of document text. Your account email address and whether it is verified, only if the assistant asks for it and you approve that on our approval screenUnited States
OpenAI (ChatGPT)Reads the transactions you approve — only if you connect the LetterScript connector in ChatGPTAnswers to the requests the assistant makes: transaction record values, deadlines, point-of-sale requirements, document titles, and cited excerpts of document text. When it requests it and you approve that on our approval screen, your account email address and whether it is verifiedUnited States

Connecting an AI assistant

LetterScript publishes a connector that lets an AI assistant you already use — Claude, ChatGPT, or another — read transactions on your behalf. It is off unless you turn it on. No data reaches an assistant provider until you connect it and approve specific transactions on our approval screen, and you can end that access at any time from Settings → Integrations → Connected apps, which refuses the assistant’s next call.

What the assistant can receive. From the transactions you approved, and no others: property address and parcel number, transaction record values (prices, dates, party names, roles and companies), derived deadlines, point-of-sale requirements for the parcel, document titles, and short cited excerpts of document text. The connector is read-only — it cannot send email, change a date, upload or delete a document, or move money.

Your account email address, if the assistant asks for it. An assistant may also ask which LetterScript account it is connected to. The most it can receive is a stable account identifier (a random ID, not your name) and — only if our approval screen listed Your email address and you approved — the email address you sign in with and whether we have verified it. Approval covers everything the assistant asked for, so an assistant that asks for your email address receives it only if you approve the whole request; declining means it receives nothing. We report an address as verified only after you have proven you control it: by signing in with Google, by signing in with Apple when Apple confirms the address, by completing a password reset, or by entering, on the approval screen, a code we emailed you. A password sign-up is not verified until one of those happens, and a Microsoft sign-in never counts as proof. Nothing else about your account — name, phone number, or workspace — is returned this way, and it stops when you disconnect the assistant or turn off AI assistant access for the workspace. Like any contact detail, your address can still appear inside a document excerpt a search returns.

What never leaves. Taxpayer identification numbers and wire or banking instructions are removed server-side before any result is returned. Whole documents are never readable and no download link is ever produced. Party phone numbers and email addresses are not in the party roster or the transaction record; they can still appear inside a document excerpt, because excerpt text is redacted for taxpayer identifiers and banking instructions, not for contact details.

What we record.For security and support, our service logs record every request made to the connector — each call an assistant makes, and each request it makes to sign in — with the time, the network address it came from, and the software identifier it sent (its user agent). For a call that returns an answer, they also record the tool name, which connection made it, the assistant’s host, the transaction it concerned (if any), and how much was returned. A search that runs over a transaction’s documents is recorded instead in the audit ledger of the workspace that owns the transaction, shown in that workspace’s Audit log: the time, who ran it, the tool name, the assistant’s host, the transaction, how much was returned, and what it cost. Approving or disconnecting an assistant is recorded in your workspace’s audit ledger too. Network addresses are not written to the audit ledger. We do not log your conversation, document text, or the text of your question — a search’s ledger entry keeps only a one-way hash of it. The ledger is tamper-evident and append-only, so entries are kept for as long as the workspace exists. Separately, when an assistant asks which account it is connected to, our service logs record the time, which connection asked, and the assistant’s host — never the email address itself. Those requests are not written to the audit ledger or recorded against a transaction.

After it leaves us. What the assistant provider does with data once it reaches them is governed by their terms, not ours — including whether it may be used to improve their models, which on some consumer plans depends on a setting in your account with that provider. Their current policies are the authority: Anthropic and OpenAI. LetterScript is not affiliated with, endorsed by, or partnered with either company.

We never use your documents to train AI models, and neither do the providers that process them for us. The one exception is the one you create yourself: if you connect an AI assistant, what that provider does with the data it receives is governed by its own terms, as described above. Some integrations only receive data if you explicitly connect them. Questions about how your data is handled? Reach us through our contact page.