Privacy Policy
Effective date: September 4, 2026
This explains what the service collects, where it is stored, and how it is handled. The short version: only data needed to operate the service is stored, data is never sold, and no advertising trackers are used.
1.What we collect
We collect only what the service needs to work:
- Your account email and password (the password is stored hashed by our auth provider, never in plain text).
- Your brand profile, which you enter: your name, title, individual and company NMLS numbers, state license line, company, phone, email, brand color, logo, and headshot.
- The loan scenarios you type into the tools (loan amounts, rates, terms, prices, and any borrower name you choose to enter). These are processed to render your documents but are saved in your browser, not in our database.
- Your theme preference and basic session state.
2.Where your data lives
Your account and brand profile are stored in our database (hosted on Supabase). Access is restricted so your data is tied to your account. The loan scenarios you build stay in your browser's local storage on your device; they are sent to our servers only to render a document and are not stored there.
Payments are handled entirely by Stripe. Your card number and payment details go directly to Stripe and never touch the service's servers. We store only a customer and subscription identifier so we know whether your plan is active.
3.Borrower data, handle with care
The scenarios you build may include a borrower's name. Any borrower information you enter stays in your browser on your device, is used only to render your documents, and is never shared with or sold to anyone. The service is a tool for you; we do not contact your borrowers and we are not the borrower's data controller. Enter only what you need, and follow your own obligations for handling client information.
Lead-capture submissions are delivered to the loan officer you configure, via email and/or their webhook, and a copy is stored in the service so the loan officer can retrieve the lead from their account even if a delivery attempt fails. Lead data is visible only to the loan officer who owns the intake link, and is never sold or shared with third parties. Borrowers also affirm consent to be contacted at submission. The exact consent text, version, time, and IP address are stored with the lead for compliance records.
4.Tracked artifact links
Tracked links are opt-in. Nothing is stored on our servers for a document unless you click "Create tracked link" yourself. When you do, we store the scenario figures, a snapshot of your brand, and an optional first name you enter for your own notification. We store only a first name, never a full name, an SSN, or a date of birth.
When a borrower opens or downloads a tracked link, we log only the kind of event and a timestamp. We do not collect an IP address, device, or browser information from that view, and we do not know who the borrower is beyond a first name you may have entered yourself.
Tracked links expire automatically after 30 days. You can revoke a link at any time, which shows anyone who opens it a message that the link has expired, or delete it permanently, which removes the stored scenario and brand snapshot along with its event history.
5.Lead Radar and public Reddit data
Account holders can choose public subreddits and keywords to watch. The service reads public posts that match those settings and stores the subreddit, post title and link, public username, short excerpt, match score, matched keywords, and a draft reply.
A summary email may be sent to the account holder. The service does not post, reply, message users, or send any account or borrower data to Reddit. Radar records remain until the account holder dismisses or deletes them, or until the account is deleted.
6.Local storage on your device
We use your browser's local storage to remember your theme choice, to keep your session so you stay signed in, and to save the scenario inputs you type into the tools so they are still there when you come back. For trial use before you create an account, a brand you enter may be cached locally on your device until you sign in. We do not use advertising or third-party tracking cookies.
7.Analytics
We keep lightweight, first-party usage analytics, anonymous counts of events such as a page view or a document download, to understand how the product is used and what to improve. These counts do not include your identity, your account, your borrowers, or your scenario data, and they are never shared with advertisers or third parties.
8.What we do not do
We do not sell your data. We do not share it with advertisers. We do not run ad-tracking pixels. Borrower information is used only to operate intake, delivery, storage, and document features requested by the account holder.
9.Sharing with service providers
We share data only with the providers that run the service on our behalf, our database host (Supabase), our payment processor (Stripe), our email delivery provider (Resend, which sends transactional email such as lead notifications), and Reddit as the source of public posts used by Lead Radar. Data is shared only as needed to operate the service or when required by law. Nothing is posted to Reddit.
10.Data retention and deletion
Account data is kept while the account is active. Lead submissions remain until the loan officer deletes them or the account is deleted. Account holders can request deletion of their account and data inside the app. Required billing or legal records may be retained.
11.Changes to this policy
If we change this policy, we will update the date at the top of this page. Material changes will be reflected here.
12.Contact
This service is operated by Lendcraft. Questions about this policy, requests for a copy of your data, and account or data deletion requests go to hello@lendcraft.app, or through support inside the app.
Borrowers: your details were submitted to a specific loan officer, and they control that record. Ask the loan officer who sent you the intake form to delete your submission. You can also write to the address above and we will pass the request on.