← Back

Privacy Policy

Effective August 31, 2026

In effect, and still early

Hull is a free beta run by one person, and this document has not yet been reviewed by a lawyer. It is in effect and it does bind both of us — this notice is here so you know how young it is, not to suggest you can ignore it. Expect it to be revised; material changes will be announced before they apply to you.

Who we are

Hull is an AI finance operations tool for small ecommerce businesses. It connects to the accounting and commerce platforms you already use, reads the bills and records you give it, and answers questions about your costs and margins.

The service is operated by Clayton Allen, an individual. For anything in this policy, contact us at clayton@hull.tools.

This policy covers the Hull application. It does not cover QuickBooks, Shopify, or any other service you connect — those remain governed by their own privacy policies and your agreements with them.

What we collect

Everything below is data you give us or that we retrieve on your instruction. We do not buy data about you, and we do not track you across other websites.

Account and sign-in

Your name, email address, and a hashed password (we never store the password itself). If you sign in through a third-party provider, we store the access tokens that provider issues us. We also record your profile image URL if you set one, and whether your email has been verified.

Session and technical

When you sign in we store a session token, the IP address, and the browser user-agent string of the session, plus timestamps. This is how sessions expire and how you can tell an unfamiliar sign-in from your own.

Your company workspace

The company name, legal name, timezone, and the people you invite, along with their email addresses and roles.

Data from accounts you connect

When you connect QuickBooks or Shopify, we read business records from them: bills, vendors, items, chart of accounts, expenses, bill payments, orders and order lines, payouts, and balance transactions. Connections are read-onlyHull never writes to your accounting platform or your store.

Documents you upload

Supplier bills, invoices, bills of materials, rate cards, and loan documents. We store the file itself along with its filename, file type, size, a SHA-256 checksum, page count, and which user uploaded it. These documents routinely contain business information, and can contain personal information where your suppliers put it there — a contact name on an invoice, for example.

What we derive

The line items, cost classifications, product mappings, cost layers, allocation rules, projections, debt facilities, certifications, and trade classifications that Hull builds from the above.

Operational records

An audit log of significant actions — who did what, when, the old and new value, whether AI suggested it, and whether a human approved it. AI usage metering (token counts, which model ran, an estimated cost). And error diagnostics through our monitoring provider, sampled, to find and fix faults.

How we use it

To run the service: read and classify your documents, sync your connected accounts, compute costs and margins, produce forecasts, and answer your questions. To operate accounts, memberships, and permissions. To keep the service secure and diagnose faults. To communicate with you about the service.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.We do not use your business data to advertise to you, and we do not use one customer's data to serve another.

How we use AI

AI is central to how Hull works, so it is worth being specific about what that means.

What is sent to an AI model

When Hull reads a document, classifies a cost, suggests a product mapping, drafts a message to a supplier, or answers a question in the assistant, the relevant content is sent to a third-party AI provider for processing. That can include the contents of documents you upload and the business records in your workspace that are relevant to the request.

Which providers

Our default provider is Anthropic (Claude models). We also support Google's Gemini models, which are disabled by default and can be enabled per feature. We use paid API tiers under terms that do not permit the provider to train its models on the content we submit.

AI never has the last word

AI output is always a draft that a person approves. Extracted bills sit in a review queue; nothing becomes a final record in your workspace without someone explicitly approving it. Every figure Hull shows you names the document or record it came from, and where it cannot answer from real data it says so rather than estimating.

Scope

An AI request is scoped to the single company workspace you are working in. It cannot read another customer's data, and it cannot read another workspace of your own that you are not currently in.

Automated decisions

Hull does not use AI to make decisions that produce legal or similarly significant effects about any individual. It classifies business costs and drafts records for human approval.

Who else processes your data

We use the following providers to run the service. Each processes data only to provide their service to us.

ProviderWhat they do
VercelApplication hosting and serverless compute
NeonManaged PostgreSQL database
Cloudflare R2Storage for documents you upload
AnthropicAI processing (default provider)
Google (Gemini API)AI processing — optional, disabled by default
NangoCustody of the OAuth credentials for your connected accounts
SentryError and performance monitoring
InngestBackground job orchestration (syncs, document processing)
ResendTransactional email (invitations, notifications)
Intuit (QuickBooks) · ShopifySources you connect; we read from them, never write

How we protect it

Data is encrypted in transit and at rest. Each company's data is isolated, and every read and write in the application is scoped to a single company. Uploaded documents are stored privately and served only through short-lived signed links to signed-in members of the company that owns them — they are never publicly accessible.

Access within a company is role-based, credentials for your connected accounts are held by a specialist provider rather than in our own database, and significant actions are recorded in an audit log.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay.

How long we keep it

We keep your data for as long as your account is active. When you delete a company, every record and document belonging to it is permanently removed. When you delete your account, your identity records are removed, and any company where you were the last remaining member is deleted with you.

Deleted data may persist in encrypted backups for up to 30 days before those backups age out. Aggregate, de-identified operational metrics that cannot be linked back to you may be retained.

Your choices and rights

You can access and correct most of your data directly in the app. You can delete your company or your account at any time from Settings → Members. You can disconnect any connected account at any time from Settings → Connections.

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use it, to request deletion or correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information, so there is nothing to opt out of. To make any other request, email clayton@hull.tools. We will verify your request against your account before acting on it.

Hullis a business tool. Where we process business records that contain another person's information — a contact name on a supplier invoice, for instance — we act on your instructions as your service provider, and you remain responsible for having the right to give us that data.

Children

Hull is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

Changes to this policy

If we make a material change — a new category of data, a new AI provider, a new purpose — we will update the effective date above and notify account owners by email before it takes effect.

Contact

Questions, requests, or complaints: clayton@hull.tools.