Privacy at Safestead

Privacy notice

What we collect, why we need it, who helps us operate Safestead, and the choices you have.

Effective 2 August 2026 · New Zealand

What this notice covers

This notice explains how Safestead handles personal information when you visit our website, create an account, use a Safestead workspace, use the Safestead browser extension, contact us, or choose to allow product analytics.

A business using Safestead controls the records it uploads and the people it invites. That business is responsible for telling its workers, customers, and other people how it uses their information. Safestead processes that workspace content to provide the service.

Information we collect

  • Account and workspace details: name, email address, organisation, role, plan, and account settings.
  • Customer content: forms, photographs, records, answers, approvals, attachments, and audit history that you or your organisation choose to store.
  • Billing details: subscription status and billing identifiers. Stripe processes payment-card details; Safestead does not store complete card numbers.
  • Support and communication: messages, feedback, and transactional email delivery information.
  • Security and reliability data: sign-in activity, internal identifiers, controlled error codes, device or browser information, and coarse performance measurements.
  • Browser-extension data: a locally stored pairing key and cached workspace identity; participant names and email addresses from an opened Gmail or Outlook conversation; visible Xero reconciliation details; and attachments, PDFs, page content, page screenshots, titles, and source URLs that you choose to file or capture.
  • Optional product analytics: page paths and selected product actions only after you choose “Allow analytics”. We do not send form answers, documents, names, email addresses, query strings, or session recordings to product analytics.
  • Optional referral attribution: when you open a customer referral link and allow analytics, we record an opaque referral code and anonymous journey ID. The referring workspace sees totals only, never your identity or workspace details.

How the browser extension uses data

The extension has one purpose: connect Safestead’s document workflow to the browser pages where you choose to use it. It does not read an entire mailbox or collect general browsing history.

  • Gmail and Outlook: when you open a conversation, the extension reads participant names and email addresses visible in that conversation and sends those identifiers to Safestead to find a customer in your current workspace. It does not send the message body. A selected email attachment is uploaded only after you choose a filing action.
  • Quick attach: the extension requests permitted Safestead documents and completed forms so you can attach one to an open reply. When no customer matches, customer-owned forms and documents are excluded.
  • Page and PDF capture: after you choose to create a draft form or file a PDF, the extension sends the selected PDF or up to 12 screenshots of the page, together with its title and an HTTPS source URL when available. Local folder paths are not sent.
  • Xero: on a bank-reconciliation page, the extension sends the visible transaction date, amount, and payee to Safestead to find receipt candidates. It can fill supported draft fields only after you approve a match and never submits or reconciles the transaction for you.
  • Connection: Chrome stores a Safestead pairing key, the selected Safestead address, and a cached workspace identity on the device. The pairing key is not exposed to Gmail, Outlook, Xero, or other page scripts. Disconnecting removes the local key; revoking the connection in Safestead stops it server-side.

Extension data is used only to provide or improve these user-facing Safestead features, keep them secure, and diagnose reliability. It is not sold, used for personalised advertising, credit decisions, or data brokerage, and it is not used to build a record of unrelated browsing.

Why we use it

  • Provide, secure, and support Safestead.
  • Turn submitted paper or digital forms into organised records.
  • Operate accounts, workspaces, permissions, integrations, subscriptions, and service messages.
  • Match an opened email or visible Xero bank line to records in the connected workspace and carry out extension actions that you choose.
  • Investigate failures and improve reliability without intentionally sending customer content to monitoring tools.
  • Understand which journeys work when a visitor or user has consented to privacy-safe product analytics.
  • Count anonymous referral outcomes so customers and Safestead can understand whether a relevant introduction helped.
  • Meet legal obligations and protect Safestead, our customers, and other people from misuse.

Service providers and locations

We use service providers only where needed to operate Safestead. They may process information for us under their own security and data protection commitments.

  • Supabase for authentication, database, and private file storage.
  • Vercel for web hosting and delivery.
  • Stripe for subscriptions and payment processing.
  • Resend or our configured mail provider for account and service emails.
  • Anthropic for assisted reading of image-only documents, receipts, handwriting, and blank forms.
  • OpenAI for Ask Safestead answers, and as a configured alternative or fallback for assisted document reading.
  • PostHog for optional product analytics. Safestead uses an EU-hosted project.
  • Sentry for error and performance monitoring. Safestead uses EU-hosted projects, with screenshots and session replay disabled.
  • Google, Microsoft, Xero, and other integrations only when a workspace chooses to connect them.

When assisted document reading is needed, the provider receives the relevant page image and limited document context. Ask Safestead sends OpenAI your question, recent Help conversation, signed-in role, device experience, a normalised screen path, and relevant published Help Centre excerpts. It does not automatically send workspace records or files.

Anthropic and OpenAI state that content sent through their commercial APIs is not used to train their general models by default. Safestead does not submit customer content as training data. Under standard API arrangements, request content may be retained for up to 30 days for safety and misuse monitoring, or longer where required by law.

Some providers or connected services may process information outside New Zealand. We assess providers and configure regional hosting where it is available and appropriate.

Analytics choice

Product analytics is off until you make a choice. Choosing “No thanks” does not affect Safestead. On the website, you can change your choice at any time using the Privacy choices link in the footer. In the field app, use Settings → Share product analytics.

We disable PostHog autocapture, heatmaps, and session recording. We send only explicit product events with controlled properties and page paths without query strings.

Retention

  • Customer records and account information are kept while the workspace is active and as reasonably needed to provide exports, meet legal obligations, resolve disputes, and complete deletion or backup cycles.
  • Privacy-safe product-event records are targeted for deletion after 25 months.
  • Consented referral visit and attribution records are targeted for deletion after 25 months.
  • Detailed operational-run records are targeted for deletion after 90 days.
  • Billing, audit, fraud-prevention, and legally required records may be kept for longer where necessary.

Security and sharing

We use access controls, private storage, encryption in transit, least-privilege service access, audit records, monitoring, and data scrubbing to protect information. No internet service can promise absolute security.

We do not sell personal information. We disclose it to the workspace and people authorised by that workspace, to the providers above, when a user asks us to share or export it, or where disclosure is required or permitted by law.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not allow people to read extension user data except with explicit consent for specific support, where necessary for security or legal compliance, or when data has been aggregated and anonymised for internal operations.

Your choices and rights

You may ask whether we hold personal information about you, request access to it, or ask us to correct information that is wrong, incomplete, or misleading. Workspace members can update some account details directly. Requests involving workspace content may need to be handled with the organisation that controls that workspace.

You may also decline optional analytics, disconnect optional integrations, or ask about account and workspace deletion. We may need to verify your identity before acting on a request.

Contact us

For a privacy question, access or correction request, or complaint, email accounts@paperrelay.app. Please do not send passwords, payment-card details, or customer documents by email.