Effective August 31, 2026
In effect, and still early
Hull is a free beta run by one person, and this document has not yet been reviewed by a lawyer. It is in effect and it does bind both of us — this notice is here so you know how young it is, not to suggest you can ignore it. Expect it to be revised; material changes will be announced before they apply to you.
Hull is an AI finance operations tool for small ecommerce businesses. It connects to the accounting and commerce platforms you already use, reads the bills and records you give it, and answers questions about your costs and margins.
The service is operated by Clayton Allen, an individual. For anything in this policy, contact us at clayton@hull.tools.
This policy covers the Hull application. It does not cover QuickBooks, Shopify, or any other service you connect — those remain governed by their own privacy policies and your agreements with them.
Everything below is data you give us or that we retrieve on your instruction. We do not buy data about you, and we do not track you across other websites.
Account and sign-in
Your name, email address, and a hashed password (we never store the password itself). If you sign in through a third-party provider, we store the access tokens that provider issues us. We also record your profile image URL if you set one, and whether your email has been verified.
Session and technical
When you sign in we store a session token, the IP address, and the browser user-agent string of the session, plus timestamps. This is how sessions expire and how you can tell an unfamiliar sign-in from your own.
Your company workspace
The company name, legal name, timezone, and the people you invite, along with their email addresses and roles.
Data from accounts you connect
When you connect QuickBooks or Shopify, we read business records from them: bills, vendors, items, chart of accounts, expenses, bill payments, orders and order lines, payouts, and balance transactions. Connections are read-only — Hull never writes to your accounting platform or your store.
Documents you upload
Supplier bills, invoices, bills of materials, rate cards, and loan documents. We store the file itself along with its filename, file type, size, a SHA-256 checksum, page count, and which user uploaded it. These documents routinely contain business information, and can contain personal information where your suppliers put it there — a contact name on an invoice, for example.
What we derive
The line items, cost classifications, product mappings, cost layers, allocation rules, projections, debt facilities, certifications, and trade classifications that Hull builds from the above.
Operational records
An audit log of significant actions — who did what, when, the old and new value, whether AI suggested it, and whether a human approved it. AI usage metering (token counts, which model ran, an estimated cost). And error diagnostics through our monitoring provider, sampled, to find and fix faults.
To run the service: read and classify your documents, sync your connected accounts, compute costs and margins, produce forecasts, and answer your questions. To operate accounts, memberships, and permissions. To keep the service secure and diagnose faults. To communicate with you about the service.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.We do not use your business data to advertise to you, and we do not use one customer's data to serve another.
AI is central to how Hull works, so it is worth being specific about what that means.
What is sent to an AI model
When Hull reads a document, classifies a cost, suggests a product mapping, drafts a message to a supplier, or answers a question in the assistant, the relevant content is sent to a third-party AI provider for processing. That can include the contents of documents you upload and the business records in your workspace that are relevant to the request.
Which providers
Our default provider is Anthropic (Claude models). We also support Google's Gemini models, which are disabled by default and can be enabled per feature. We use paid API tiers under terms that do not permit the provider to train its models on the content we submit.
AI never has the last word
AI output is always a draft that a person approves. Extracted bills sit in a review queue; nothing becomes a final record in your workspace without someone explicitly approving it. Every figure Hull shows you names the document or record it came from, and where it cannot answer from real data it says so rather than estimating.
Scope
An AI request is scoped to the single company workspace you are working in. It cannot read another customer's data, and it cannot read another workspace of your own that you are not currently in.
Automated decisions
Hull does not use AI to make decisions that produce legal or similarly significant effects about any individual. It classifies business costs and drafts records for human approval.
We use the following providers to run the service. Each processes data only to provide their service to us.
| Provider | What they do |
|---|---|
| Vercel | Application hosting and serverless compute |
| Neon | Managed PostgreSQL database |
| Cloudflare R2 | Storage for documents you upload |
| Anthropic | AI processing (default provider) |
| Google (Gemini API) | AI processing — optional, disabled by default |
| Nango | Custody of the OAuth credentials for your connected accounts |
| Sentry | Error and performance monitoring |
| Inngest | Background job orchestration (syncs, document processing) |
| Resend | Transactional email (invitations, notifications) |
| Intuit (QuickBooks) · Shopify | Sources you connect; we read from them, never write |
Data is encrypted in transit and at rest. Each company's data is isolated, and every read and write in the application is scoped to a single company. Uploaded documents are stored privately and served only through short-lived signed links to signed-in members of the company that owns them — they are never publicly accessible.
Access within a company is role-based, credentials for your connected accounts are held by a specialist provider rather than in our own database, and significant actions are recorded in an audit log.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay.
We keep your data for as long as your account is active. When you delete a company, every record and document belonging to it is permanently removed. When you delete your account, your identity records are removed, and any company where you were the last remaining member is deleted with you.
Deleted data may persist in encrypted backups for up to 30 days before those backups age out. Aggregate, de-identified operational metrics that cannot be linked back to you may be retained.
You can access and correct most of your data directly in the app. You can delete your company or your account at any time from Settings → Members. You can disconnect any connected account at any time from Settings → Connections.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use it, to request deletion or correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information, so there is nothing to opt out of. To make any other request, email clayton@hull.tools. We will verify your request against your account before acting on it.
Hullis a business tool. Where we process business records that contain another person's information — a contact name on a supplier invoice, for instance — we act on your instructions as your service provider, and you remain responsible for having the right to give us that data.
Hull is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
If we make a material change — a new category of data, a new AI provider, a new purpose — we will update the effective date above and notify account owners by email before it takes effect.
Questions, requests, or complaints: clayton@hull.tools.