DossierMap legal
Privacy Policy
This policy explains what information DossierMap collects, how it is used, when it is shared, and what choices users have. It is written for the DossierMap website, account creation flow, and workspace.
Short version
DossierMap processes faculty promotion materials to help the signed-in user map evidence to promotion criteria. DossierMap does not sell uploaded dossier materials and does not use them to train DossierMap-owned AI models. Uploaded documents, extracted text, generated outputs, review decisions, and activity records should be treated as private faculty workspace data.
Information we collect
- Account information. Email address, login state, invite status, access tier, credit balance, and related account identifiers.
- Dossier workspace content. Documents you upload, project names, selected criteria, generated evidence maps, gap reports, matrix exports, review decisions, manual evidence, and download activity.
- Payment and billing records. Checkout status, purchase tier, credit grants, webhook event identifiers, and payment metadata supplied by Stripe. DossierMap does not store full card numbers.
- Operational data. Security logs, session cookies, CSRF tokens, API usage estimates, worker health, error details, and privacy-safe aggregate metrics needed to operate and improve the service.
- Communications. Messages you send about access, support, privacy, refunds, or product feedback.
How we use information
- Authenticate users and protect private faculty workspaces.
- Run PDF preflight checks, evidence extraction, AI-assisted citation proposal, deterministic verification, gap reporting, and draft matrix export.
- Track credits, process payments, prevent duplicate billing, and provide purchase support.
- Maintain security, debug errors, monitor service health, and prevent misuse.
- Improve DossierMap using privacy-safe aggregate usage patterns that do not expose uploaded dossier text, file names, citations, line references, or generated matrix contents.
- Comply with law, enforce terms, and respond to valid legal requests.
AI model providers
DossierMap may send extracted dossier text, criteria rows, citation context, and related prompt data to the configured AI model provider only as needed to perform evidence matching or analysis. Local deterministic and fixture modes do not make external AI provider calls.
The deployed provider may vary by environment. Current provider integrations include Anthropic and retained OpenAI comparison providers. Provider processing, retention, and training practices are governed by the provider terms and data policies for the API account used by DossierMap.
DossierMap does not intentionally opt uploaded dossier materials into AI model training. If a separate institutional agreement changes the provider, retention, or processing terms, that agreement controls for the covered users.
Provider references: Anthropic data retention, Anthropic model training, and OpenAI API data usage.
How information is shared
- Service providers. DossierMap may use hosting, authentication, AI model, payment, logging, storage, backup, and support vendors that process data for the service.
- Payment processor. Stripe processes checkout and payment information under its own privacy disclosures.
- Legal and safety needs. Information may be disclosed when required by law, to protect rights and security, or to investigate misuse.
- Business changes. Information may be transferred as part of a merger, acquisition, financing, or sale of assets, subject to this policy or a successor policy.
- With consent. Information may be shared when you ask or authorize DossierMap to share it.
DossierMap does not sell uploaded dossier content.
Retention and deletion
DossierMap retains uploaded documents, generated artifacts, account records, billing records, and activity events only as long as needed to provide the workspace, preserve review continuity, maintain security, meet legal or billing obligations, and support configured retention policies.
Uploaded documents can be deleted or soft-deleted through workspace and admin controls when available. Soft-deleted upload records may be purged according to the configured retention policy. Local development data and demo data may be reset or deleted at any time.
Before production use with real faculty dossiers, DossierMap should be deployed with production authentication, private storage, encryption, backup, restore-drill confirmation, and retention controls appropriate for the institution or customer.
Security
DossierMap uses technical and organizational safeguards such as private workspace sessions, CSRF protection, public/private asset boundaries, production readiness checks, private storage gates, application-level encryption for encrypted-local private storage, and operational views that avoid exposing dossier text to admins. No internet service can guarantee perfect security.
Your choices
- Do not upload materials you are not authorized to submit for analysis.
- Contact DossierMap to request access, correction, deletion, or export of account-linked data where feasible.
- Use logout controls to end the browser session on shared devices.
- Consult your faculty affairs office, institution, or privacy officer before uploading confidential or institution-regulated materials.
Children
DossierMap is intended for adult faculty, administrators, mentors, and authorized institutional users. It is not directed to children under 13.
Changes
DossierMap may update this policy as the service, providers, legal requirements, or production controls change. Material changes will be reflected by updating the effective date and, when appropriate, providing additional notice.
Questions or requests?
Submit privacy and account requests through the DossierMap contact page. Requests go into the DossierMap admin workflow for follow-up.