Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains what information Cannpliance (“we,” “us”), a product of Elevated States Consulting, LLC, collects when you use cannpliance.com and our compliance tools, and what we do with it. We minimize what we keep where it counts: we never store the labels, PDFs, or Certificates of Analysis (COAs) you upload. We do store the reports you generate — in your account, so you can revisit, unlock, and download them — and you can delete them at any time (see “Your reports and storage” below).
Information we collect
- Account information — handled by our authentication provider, Clerk: your email address, any name or profile details you provide, and (optionally) your company name and business type.
- Usage metadata — for each analysis: which tool was used, how many and which states were checked, token/processing counts, an estimated cost, and a timestamp. Used for rate limits, billing, and product analytics.
- Report contents — the reports you generate (findings, regulatory citations, pass/warning/fail counts, and any brand or product name shown on your label). Stored in your account so you can access them later; you can delete any report at any time (see “Your reports and storage”).
- Payment information — when paid plans are available, payments are processed by a third-party payment processor. We do not receive or store your full card number.
- Support communications — if you contact us, we keep your message and contact details to respond.
Your uploads — never stored
The packaging images, PDFs, or COAs you upload exist only transiently in server memory for the duration of the analysis request, and are discarded when it completes. They are never written to any database, object store, or log that we control.
Your reports and storage
The report we generate — its findings, citations, pass/warning/fail counts, and any brand or product name read from your label — is stored in your account so you can revisit it, unlock a full report later, and download it. This is what lets your reports appear in your account history.
- Delete anytime. You can delete any stored report from your account, which removes it from our database.
How your uploads are processed
To analyze your product, your uploaded content is sent to Anthropic’s Claude API for processing. We do not permit use of your content for model training. To make multi-state analyses fast and affordable, we use Anthropic’s prompt caching, which means portions of a request may reside briefly in Anthropic’s cache for a short time-to-live window before expiring. Anthropic acts as our data processor: under its commercial terms, API inputs and outputs are not used to train its models and are retained only as needed to provide the service and for limited safety monitoring.
Why we minimize what we keep
We never keep your source files — only the report generated from them, which you can delete at any time. Minimizing what we retain limits what could be exposed, subpoenaed, or misused — we can’t leak what we don’t keep.
Cookies & analytics
We use strictly necessary cookies for authentication and session management. If and when we enable product analytics or additional cookies, we will present a consent banner and update this policy accordingly. We do not track you across third-party websites; because there is no industry-standard for browser “Do Not Track” signals, we do not currently respond to them.
Data retention
We retain account information for as long as your account is active, and usage metadata as long as needed for billing, security, and analytics. Stored reports are retained until you delete them or close your account. We never retain your uploaded source files. You may request deletion of your account and associated data (see “Your choices”).
Service providers (subprocessors)
- Clerk — authentication and account management
- Neon — managed PostgreSQL database (accounts, billing, and stored reports)
- Anthropic — AI processing of your analysis requests
- Vercel — application hosting
- Payment processor — a third-party service for payment processing (when paid plans are live)
- Resend — transactional email delivery
Your choices & rights
Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To exercise these rights, contact us at support@cannpliance.com. We will respond as required by applicable law, including the GDPR and CCPA where they apply.
Children
Cannpliance is a business tool intended for adults; it is not directed to children and we do not knowingly collect information from anyone under 18.
Where we operate
Cannpliance is intended for businesses in the United States. We do not target the service to, or knowingly offer it to, users in the European Union or EEA, and we do not process personal data under the GDPR.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, additional notice.
Contact
Questions about this policy: support@cannpliance.com · Elevated States Consulting, LLC.