Cubre Data Processing Addendum (version 2026-09-14)

This version has been superseded. It was published 2026-09-14 and replaced for new acceptances on 2026-09-22. It is kept so anyone who accepted it can read exactly what they agreed to. The current version is the Data Processing Addendum. Every version is listed in the version index.

Version 2026-09-14. This Addendum is part of the Application Terms of Service. Where it conflicts with those Terms on the handling of personal information, this Addendum controls.

1. Roles

You are the controller of the personal information you put into Cubre. We are your processor: we process it on your documented instructions, which are these Terms, this Addendum, and your use of the application’s features.

We are the controller of the account information we hold about you and your Authorized Users — names, work email addresses, login records — which is covered by our Privacy Policy rather than by this Addendum.

If we ever believe an instruction from you violates applicable data-protection law, we will tell you.

2. What we process, and for whom

Purpose. To provide the application to you, and for nothing else.

Duration. For as long as your account is active, plus the periods in §7.

Categories of data subject: your customers (property owners and their household or business contacts), your Authorized Users, and people your customers identify to you.

Categories of personal information:

Category Examples
Identity and contact Name, business name, email address, phone number
Property and location Service address, property characteristics, coordinates
Commercial Estimates, invoices, payments and balances, job history, scheduled dates
Bank account (yours, if you link one) Institution name, account type, last four digits, and balances read through Stripe Financial Connections — read-only; we never hold your bank login
Content you upload Photographs of properties, documents, notes, form responses
Signature Electronic signatures, the signer’s name and email, IP address, timestamp, audit trail
Communications Emails and text messages sent through Cubre, delivery status, opt-out records

We do not knowingly process special-category or sensitive personal information, and the application is not designed to hold it. Do not put it in.

We do not use your personal information to train machine-learning models, and we require the same of our subprocessors.

3. Security

We maintain technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; per-tenant isolation enforced at the query layer; role-based access control with per-capability permissions; optional and enforceable two-factor authentication; encrypted storage of third-party credentials; audit logging of access to and changes of records; and least-privilege access for the small number of personnel who can reach production.

People with access are bound by confidentiality obligations that survive their engagement.

4. Subprocessors

You authorize the subprocessors below. Each is bound by a written agreement with data-protection terms no less protective than this Addendum, and we remain responsible to you for their performance.

Subprocessor What it processes Why Location
Fly.io All data in transit and in compute Application hosting United States (Dallas)
Neon All database records Managed PostgreSQL United States
Cloudflare R2 Files, photographs, documents, backups Object storage United States
Stripe Payment and payout data; your identity data for verification; if you link a bank, bank account identifiers (institution, last four, account type) and balances via Stripe Financial Connections Payment processing; bank linking United States
Resend Recipient address and message content Outbound email United States
Twilio Recipient number and message content Outbound and inbound SMS United States
Sentry Diagnostic data, which may incidentally include personal information in an error payload Error monitoring United States
Anthropic Content you submit to an AI-assisted feature — see below AI-assisted features United States

What goes to the AI provider, specifically

Some features send content to Anthropic to produce a result. This is the disclosure a generic policy would leave out, so it is stated precisely:

  • Importing a spreadsheet. To suggest how your columns map onto Cubre’s fields, we send the column headers and up to five example values per column. If you are importing a customer list, those example values are real names, addresses, or phone numbers.
  • Reading an uploaded document. To extract line items or measurements, we send the uploaded file itself, the whole PDF or image, including any names, addresses, signatures or photos it contains, not just its extracted text.
  • Matching, suggesting and proofreading. Item names, descriptions and the text you are writing.

This content is not used to train Anthropic’s models. If you would rather it were not sent at all, tell us at support@cubre.app and we will disable AI-assisted features for your account; the rest of the application is unaffected.

Changes

We will give you at least thirty (30) days’ notice before adding or replacing a subprocessor that processes personal information. If you reasonably object on data-protection grounds within that period, tell us: we will work with you in good faith, and if we cannot resolve it you may terminate the affected part of the service without penalty under Terms §16.2.

5. Your customers’ requests about their data

If a person asks us directly to access, correct, delete, or port personal information we hold for you, we will not act on it ourselves. We will pass it to you promptly, because you are the controller and the relationship is yours.

We will give you reasonable assistance — the tools in the application, and our help where the tools are not enough — so you can respond within your legal deadline.

6. Security incidents

We will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal information we process for you.

The notice will describe what we know: the nature of the incident, the categories and approximate number of records, the likely consequences, and what we are doing about it.

Colorado law (C.R.S. § 6-1-716) requires notice to affected residents within thirty (30) days in defined circumstances. That notice is yours to give, because you hold the relationship with those people; we will give you what you need to give it.

7. Return and deletion

On termination, §16.4 of the Terms governs:

  • You can export at any time while your account is active, including while suspended.
  • If we terminate, your data stays available for export for thirty (30) days, then is deleted.
  • If you delete your workspace, deletion is immediate and irreversible.

The exception, stated plainly because it is a real conflict. We retain some records after deletion where the law requires it:

  • Messaging-consent and opt-out records. Proof that someone consented, or asked to stop, is the evidence that defends a TCPA or CAN-SPAM claim — and a record of an opt-out is what makes the opt-out effective. We keep these for five (5) years, then delete them.
  • Financial records — what was invoiced, paid, refunded, and disputed — for the period tax and payment-network rules require.
  • Disconnected bank accounts keep their last balance and chart mapping — the numbers your books were opened from — until the workspace is deleted, at which point we also revoke the link at Stripe.

These are kept for that purpose only, are not used for anything else, and are not returned to active use.

8. Audit

On reasonable written request, no more than once a year (or after a security incident affecting you), we will provide the information reasonably necessary to show we are meeting this Addendum. Where a third-party audit report or certification is available, providing it satisfies this section.

9. International transfers

We process personal information in the United States. If you are subject to a law requiring a transfer mechanism, contact us and we will put an appropriate one in place.

10. General

This Addendum takes effect when you accept the Terms and ends when we have deleted or returned the personal information under §7. It may be executed as a standalone agreement at your request, with identical effect.

Questions: support@cubre.app