Surrenderless

JusticeChat intake

Home

Privacy Policy

Last updated: June 21, 2025

Overview

This Privacy Policy describes how Surrenderless Form Assistant ("Surrenderless," "we," "us") handles information when you use this web application. Surrenderless helps you organize consumer issues into structured cases, prepare drafts and checklists, and record filing-related activity. It does not file or submit complaints automatically to regulators, courts, or companies except where a clearly labeled, optional assisted workflow is enabled in your deployment.

Surrenderless does not provide legal advice, and we does not guarantee that any regulator, business, or third party will accept a complaint, filing, or dispute.

Information we collect

Account and authentication data. Sign-in is handled through Clerk. Clerk processes credentials and session information needed to authenticate you. We associate your activity in Surrenderless with your authenticated user identifier.

Case and intake data. When you use Consumer Justice features, we store case-related information you provide or generate in the product, such as intake answers, case labels, timelines, client state, payment-dispute draft fields, and related workflow status. Some information may also be mirrored temporarily in your browser session or local storage to resume work on your device.

Evidence metadata. The product lets you save proof notes as structured metadata (for example title, evidence type, optional date, and description). Surrenderless does not provide file upload storage for evidence attachments in the current product; you describe proof in text fields rather than uploading files through the app.

Filing and handling records. You may record manual filing activity, handling requests, packet approvals, and similar workflow events tied to your cases.

Automation and task logs. When you use assisted submission or form-analysis features, the service may store task logs, form field mappings, and related technical metadata needed to run or retry those workflows.

Technical and security data. We use rate limiting and related safeguards that may process request metadata (such as identifiers derived from your session or IP address) to protect the service.

How we use information

We use the information above to:

  • Provide sign-in, case persistence, and Consumer Justice workflow features;
  • Generate drafts, previews, action plans, and checklists from your case data;
  • Display your saved cases, evidence notes, filings, and timeline history when you are signed in;
  • Run optional assisted browser workflows you initiate, and record their results in task logs;
  • Protect the service through authentication checks, ownership validation, and rate limits;
  • Improve reliability and troubleshoot errors in server logs where configured.

We do not sell your personal information as part of the product behavior described in this repository.

AI processing

Surrenderless uses third-party AI services (OpenAI) for features such as conversational intake chat, optional AI-assisted submission draft text, field matching for assisted forms, and related decision assistance. When you use those features, relevant portions of your case context and prompts may be sent to the AI provider to generate responses.

AI output is used to assist drafting and workflow suggestions only. It is not legal advice and may be incomplete or inaccurate. You are responsible for reviewing anything you rely on before submitting it anywhere.

External submission assistance

Some workflows help you prepare or assist with submitting information on external websites. In practice deployments this may include:

  • Same-origin mock practice forms (for example mock FTC or BBB practice pages) used for training and testing workflows;
  • Optional real Better Business Bureau complaint autofill when explicitly enabled in the deployment configuration, which uses browser automation directed at the official BBB complaint URL;
  • Manual copy-and-paste preparation pages for many other destinations, where Surrenderless prepares text for you to submit yourself on third-party sites.

When assisted automation runs, form content derived from your case may be processed by browser automation infrastructure (local Playwright and/or a configured Browserless endpoint) and submitted only according to the workflow you start and the allowlisted destination URLs enforced by the service.

Third-party sites have their own privacy practices. Information you submit on external regulator, business, or payment-platform sites is governed by those sites' policies, not this one.

Service providers

Depending on how the application is deployed and which features you use, data may be processed by:

  • Clerk — authentication and session management;
  • Supabase — database storage for cases, evidence metadata, filings, profiles, and task logs accessed through server-side API routes;
  • OpenAI — AI-assisted intake, drafting, and form-matching features;
  • Browserless (when configured) — remote browser automation for assisted form workflows;
  • Upstash Redis (when configured) — rate limiting;
  • Stripe (when configured) — payment checkout sessions if billing features are enabled in the deployment.

These providers process data on our behalf only to deliver the features above. Their handling of data is also subject to their own terms and privacy policies.

Security

We use industry-standard web application practices available in this product, including authenticated API routes, case ownership checks, rate limiting on sensitive automation endpoints, and URL allowlisting for assisted external submission. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Deployments may additionally use deployment-level access controls (for example HTTP basic authentication when configured). You are responsible for safeguarding your account credentials and devices.

Retention and deletion

Case data is retained in the database while your account and cases remain active unless you take action available in the product. You can archive cases, which marks them with an archive timestamp and removes them from active case lists while retaining the stored record according to the deployment's database configuration.

You may delete individual evidence metadata records through the evidence management features. Broader deletion of all account-linked data may require actions through your authentication provider and database administration for the deployment; specific retention schedules are not defined in the application code.

Browser session and local storage mirrors on your device can be cleared by you through browser settings or by clearing site data.

Your choices

You choose what case information to enter. Many Consumer Justice features require sign-in. You can decline to use AI-assisted features where alternatives exist (for example deterministic draft previews). You can archive cases and manage evidence metadata within the product.

Changes to this policy

We may update this Privacy Policy as the product changes. The "Last updated" date at the top of this page will reflect the latest revision. Continued use after changes become effective constitutes acceptance of the updated policy.

Contact

For privacy questions about Surrenderless Form Assistant, contact us through the support or account contact options made available in your deployment or authentication provider account settings. This repository does not publish a dedicated legal mailing address or privacy inbox.