Last updated: July 27, 2026
This Privacy Policy explains how Just OK Assets, LLC, a limited liability company organized under the laws of Oklahoma ("we," "us," "our"), handles information in connection with the NoteHarbor service (the "Service").
NoteHarbor is business-to-business software sold to lenders, note holders, and property owners in the United States. It is not a consumer product, and it is not offered to individuals for personal, family, or household purposes.
This policy is a general commercial template prepared for NoteHarbor and is subject to review by qualified counsel. It is a description of our practices, not legal advice to you.
1. The two hats we wear
Read this section first. It determines which parts of this policy apply to you.
1.1 We are a service provider (processor) for Customer Data. Our customers are businesses. They load information about their borrowers, tenants, lenders, vendors, and properties into the Service ("Customer Data"). For that information, the customer is the controller — it decides what to collect, why, and for how long. We act as a service provider / processor: we handle Customer Data to run the Service for that customer, and we do not use it for our own purposes.
If you are a borrower or tenant whose information appears in NoteHarbor, your relationship is with the business that services your loan or manages your property, not with us. Direct your privacy questions and requests to that business. We will support them in responding, but we cannot act on their data without their instruction.
1.2 We are a controller for account data. For information about our own customers and their users — registration details, billing records, support conversations, and how the Service is used — we act as a controller and this policy describes our practices directly.
2. Which privacy laws drive this
Much of the information in the Service is nonpublic personal information about individuals obtained in connection with a financial product or service. The Gramm-Leach-Bliley Act (GLBA) and its Safeguards Rule are therefore the dominant privacy and data-security regime for the Service, and our customers are generally the "financial institutions" with the primary GLBA obligations. We handle Customer Data as their service provider and support their GLBA program.
State consumer privacy laws may also apply to some information. Many of them exempt information already regulated under GLBA, and most exclude business-to-business and employment contexts; the analysis depends on the customer, so each customer must assess its own obligations.
We do not offer the Service in the European Economic Area, the United Kingdom, or Switzerland, and we make no GDPR or UK GDPR representations. We have not appointed an EU or UK representative.
3. Information in the Service
3.1 Customer Data (we are the processor)
Our customers may load, and the Service may store:
| Category | Examples |
|---|---|
| Identity and contact | Borrower, tenant, lender, vendor, and investor names; entity names; mailing addresses; phone numbers; email addresses |
| Loan and account records | Loan terms, balances, payment history, allocations, late fees, suspense balances, escrow ledgers, insurance and tax records, payoff figures |
| Property records | Addresses, parcel and legal descriptions, valuations, county tax-account data |
| Financial attributes | Where the customer chooses to record them: credit score, stated income, bank name and last four digits of an account number |
| Government identifiers | Taxpayer identification numbers (SSN, ITIN, EIN) where the customer records them for tax-form preparation — see Section 6 |
| Documents | Files the customer uploads, such as notes, deeds, statements, insurance policies, and correspondence |
| Case records | Foreclosure and bankruptcy timelines, notes, and correspondence the customer records |
We do not receive or store full payment card numbers or full bank account numbers.
3.2 Account and usage data (we are the controller)
- Registration: name, business email, organization name, role, and the identifiers our authentication provider assigns.
- Billing: plan, subscription status, and the identifiers our payment processor assigns. Card details go to the payment processor, never to us.
- Support and feedback: the content of support requests, feature requests, and in-app assistant conversations.
- Consent records: which legal documents a user accepted, the version, the timestamp, and the IP address and browser user-agent captured at the moment of acceptance — kept as proof of consent.
- Technical and security logs: IP address, user agent, timestamps, request outcomes, and rate-limiting counters.
- Audit records: who changed what, and when, inside a customer's account.
- Marketing-site traffic measurement: on our public marketing pages only — the page visited, the first page of the visit, the host name of the site that referred the visit (for example
google.com), any campaign tags or advertising click identifiers in the link (for examplegclid,fbclid), and a random identifier stored in a cookie so that a browser's repeat visits are recognized as the same visitor. This tells us which channels bring people to us. It does not run inside the signed-in Service, the borrower portal, or the resident portal. Our own records of this hold no name, no email address, no IP address, and no user agent; where Google Analytics is enabled it separately collects what is described in Section 7. See Section 11.
4. How we use information
We use information to:
- provide, operate, secure, and support the Service;
- authenticate users and enforce roles, permissions, and plan capacity;
- process payments and manage subscriptions;
- generate the documents, statements, forms, and reports our customers ask for;
- detect, investigate, and prevent abuse, fraud, and security incidents;
- maintain audit trails and consent records;
- communicate about service, security, billing, and account matters (these are transactional and cannot be opted out of while the account is open);
- send marketing email only where the recipient opted in (see Section 10);
- measure which channels bring visitors to our public marketing pages, and which of those visits become customers (see Section 11); and
- comply with law and enforce our agreements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use Customer Data for our own marketing, and we do not use it to train generative AI models. Any statistics we derive about how the Service is used are aggregated and de-identified so that they do not identify any customer, user, borrower, or tenant.
5. AI-assisted features and what they transmit
Some features send content to our AI Sub-processor for processing. Read this section carefully before using them.
5.1 AI never computes money and never decides anything. All amortization, allocation, escrow, payoff, and tax computation is done by deterministic calculation engines. AI summarizes, explains, extracts, classifies, and drafts. Its output is informational, must be reviewed, and is not tax or legal advice.
5.2 What each feature sends.
| Feature | What is transmitted |
|---|---|
| In-app assistant | Your question, recent conversation, help-center content, and limited page context. Identifiers such as emails, tokens, and identification-number patterns are redacted before the request is sent, and the loan context passed to it is restricted to an allowlist of fields that excludes taxpayer identification numbers, dates of birth, income, and bank details |
| Help-center and tax questions | The question you type and the reference content being cited |
| Risk scoring | Loan financial attributes and payment performance, plus the credit score and stated income where the customer recorded them. It does not send names or taxpayer identification numbers |
| County record retrieval | Text from the public county web page the customer points us at |
| Document and statement import (PDF, Word, text) | Text extracted from the file, passed through an identifier scrub before the request is sent — see 5.3. The file itself is never transmitted |
5.3 How document import handles your uploads. When a user invokes AI-assisted import, we do not send the uploaded file. We extract its text layer on our own servers, pass every character of that text through a single redaction step, and send only the redacted text. The redaction targets taxpayer-identification shapes (labelled, dashed, spaced, and bare nine-digit runs, including non-Latin digit forms) along with emails, tokens, and card-shaped numbers, while deliberately preserving balances, rates, and dates so the import can do its job.
Be aware of the limit: redaction is pattern-based, so we cannot promise it catches every identifier that could appear in an arbitrary document. It is a strong filter, not a guarantee. Review what you upload.
5.4 Stored taxpayer identification numbers are never sent to AI. Taxpayer identification numbers held in encrypted form in the Service are decrypted only at the specific tax-form and credit-file-export endpoints listed in Section 6. No AI code path decrypts or receives a stored taxpayer identification number.
5.5 No training. We send content to our AI Sub-processor under commercial API terms that do not permit the provider to train models on it, and we do not train models on it ourselves.
6. Taxpayer identification numbers
Because the Service prepares tax forms, it can store taxpayer identification numbers. We treat them as the most sensitive data in the system:
- Encrypted at rest with AES-256-GCM using a dedicated encryption key that is separate from every other application secret.
- Only the last four digits are stored in readable form, and only the last four are displayed anywhere in the interface.
- Decryption happens only at a short, fixed list of endpoints — the tax-form generators (Forms 1098, 1099-INT, 1099-A, 1099-C, and 1099-NEC) and the Metro 2 credit-file export. Nothing else in the application decrypts them.
- Every decryption is written to the audit log with the actor, the time, and the reason. The decrypted value itself is never logged.
- Each of those endpoints is restricted to privileged roles, and the full number appears only on the payer/IRS copy of the form itself.
- No AI path can decrypt one.
The same encryption is applied to the servicer login credentials a customer may store for an underlying "subject-to" loan, and revealing one is likewise audited.
7. Sub-processors
We use these third parties to run the Service. Each receives only what it needs for its function.
| Sub-processor | Function | What it can receive |
|---|---|---|
| Vercel | Application hosting and content delivery | All traffic to the Service in transit; request logs |
| Supabase | Managed Postgres database and private file storage | All Customer Data and account data at rest, including uploaded documents |
| Clerk | Authentication, user and organization management, multi-factor authentication | User names, email addresses, credentials, session and device metadata |
| Stripe | Subscription billing and payment processing | Billing contact details and payment card data, which Stripe collects directly on its own hosted pages |
| Anthropic | AI-assisted features | Only the content described in Section 5, and only when a user invokes an AI feature |
| Resend | Transactional email delivery | Recipient email address and the contents of the message being sent |
| Upstash / Vercel KV | Rate limiting, where configured | Rate-limit counters keyed to an organization identifier or IP address |
| Google Maps Platform | Address autocomplete, where enabled | The partial address text a user types into an address field |
| ClickUp | Internal support and feature-request tracking, where enabled | The subject and body of support requests and feature requests |
| Google Analytics | Traffic measurement on our public marketing pages, where enabled | Page addresses on our marketing site (stripped of any query string other than campaign tags), the page title, the name of the page-level event (for example "landing page viewed"), the origin of the referring site, its own cookie identifier, and the device, browser, approximate location and IP address that Google Analytics collects itself. It is not loaded inside the signed-in Service, the borrower portal, the resident portal, or the sign-in and sign-up pages, and it never receives Customer Data. |
We may add or change Sub-processors as the Service evolves; we will update this list. If you need advance notice of Sub-processor changes, ask us at justokassets@gmail.com.
The Service can also fetch a public county tax record from a URL a customer supplies. That is an outbound request to a public website; it sends no Customer Data.
We do not use advertising networks, session-replay tools, data brokers, or cross-site trackers, and we do not sell or share personal information for advertising. We do measure traffic to our public marketing pages, with our own first-party counter and — where enabled — Google Analytics. No analytics of any kind runs inside the signed-in Service, so no analytics provider can observe a customer working with borrower, tenant, or loan records. See Section 11.
8. Security
We describe below the controls we actually operate. We claim no security certification, accreditation, or third-party audit attestation — not SOC 2, not ISO 27001, not a PCI attestation. Payment card security rests with Stripe, which collects card data directly on its own hosted pages so that our systems never receive a card number.
- Encryption in transit. All traffic is served over HTTPS, with HTTP Strict Transport Security in production.
- Encryption at rest. Taxpayer identification numbers and stored servicer credentials are encrypted by the application with AES-256-GCM under a dedicated key (Section 6). The database and the private document bucket are encrypted at rest by our infrastructure providers.
- Tenant isolation. NoteHarbor is multi-tenant. Isolation is enforced in application code: every data query is scoped to the requesting user's organization through a single, central tenant-context function, and file access is validated against the owning record before a document is served. Documents live in a private bucket with no public URLs.
- Access control. Access is role-based. Sensitive surfaces — billing, team administration, audit logs, tax-form and credit-file generation — are restricted to privileged roles. Audit-log visibility defaults to Owners and Administrators, and an Owner can extend or restrict it per user.
- Multi-factor authentication. MFA is available through our authentication provider, and an account can be configured to require it for privileged roles before sensitive surfaces open. It is not enabled by default; enabling it is the customer's decision.
- Audit logging. Record changes across loans, payments, escrow, insurance, tax accounts, and case files are logged with the actor, timestamp, before-and-after values, and a required explanatory note.
- Borrower and tenant portal. Portal links carry a signed, time-limited token rather than a password. Anyone holding a valid link can view that borrower's or tenant's own information until the token expires, so treat portal links as sensitive and send them only to the intended recipient.
- Rate limiting and abuse controls on authentication and sensitive endpoints.
- HTTP security headers, including frame-denial, MIME-sniffing protection, a referrer policy, a restrictive permissions policy, and an enforcing Content Security Policy built per request with a fresh nonce.
- Least-privilege secrets. Credentials are held as server-side environment variables and never shipped to the browser.
No system is perfectly secure. We cannot guarantee that unauthorized access will never occur. If we learn of a security incident affecting Customer Data, we will notify the affected customer without undue delay and provide the information it needs to meet its own notification obligations. Because we are the processor, notice to the individuals affected is generally the customer's to give.
9. Retention and deletion
Be direct about this, because we are:
- We retain Customer Data for as long as the customer's account exists, and we do not currently operate an automated retention or purge schedule. Data a customer enters stays until it or the account is deleted.
- Cancelling a subscription or closing an organization deactivates the account; by itself it does not erase the data.
- To have data deleted, ask us. Email justokassets@gmail.com from an account owner's address. We will delete or de-identify the requested data within a commercially reasonable time, except where we must keep it to comply with law, resolve a dispute, or enforce our agreements. Where a customer's own regulatory retention rules require otherwise, tell us and we will not delete.
- Backups. Our infrastructure provider takes routine backups. Deleted data can persist in backups until those backups cycle out in the ordinary course.
- Records we keep as controller. Billing records, consent records, security logs, and audit entries are retained for as long as we need them for legal, accounting, and evidentiary purposes, even after an account closes.
- Marketing-site traffic records. The visit records described in Section 11 hold no name, email address, IP address or user agent, and are keyed by a random identifier rather than by you. The cookie carrying that identifier expires 90 days after your last visit. The records themselves are retained until we delete them — we do not currently operate an automated purge for them. Where a visit resulted in an organization, we keep that organization's originating channel — the source, medium, campaign, referring host name and landing page — for as long as the account record exists.
Export the data you need before you close an account. See Section 10 of the Terms of Service.
10. Your choices
10.1 Access and correction. Customers and their users can view and correct most account and Customer Data directly in the Service.
10.2 Export. The Service provides export features for reports, accounting journals, document archives, and tax packets. If you need something the export features do not cover, contact us.
10.3 Deletion. See Section 9.
10.4 Marketing email. Marketing email is optional and separate from the required agreements. It is never pre-checked at signup, we send it only to people who affirmatively opt in, and you can withdraw consent at any time in Settings → Your agreements or by using the unsubscribe link in any marketing message. Withdrawal is honored regardless of your account or billing status. See the Marketing Emails document. Service, security, billing, and legal notices are not marketing and continue while your account is open.
10.5 Borrowers and tenants. If you are a borrower or tenant, direct requests to the business that services your loan or manages your property. See Section 1.1.
10.6 Marketing-site analytics. Opt out with one click — turn off analytics for this browser — or by turning on Do Not Track or Global Privacy Control in your browser. Any of these stops both our first-party counter and Google Analytics before anything is loaded or recorded. The setting is stored in this browser only, so repeat it on each device. See Section 11.
10.7 Requests to us. Email justokassets@gmail.com. We may need to verify your identity and your authority over the account before acting, and we will not discriminate against you for making a request.
11. Cookies and tracking
Inside the Service (everything behind sign-in, plus the borrower and resident portals), cookies and similar storage are strictly necessary — keeping you signed in, maintaining your session and active organization, and protecting against abuse. Our authentication provider sets session cookies for that purpose. No analytics, advertising, or session-replay technology of any kind runs there.
On our public marketing pages — the home page, pricing, about, contact, comparison pages, calculators, help center, legal documents, and the sign-in and sign-up pages — we measure traffic so we know which channels bring people to us:
- Our own first-party counter. One cookie holding a random identifier — nothing derived from you — so that a browser's repeat visits are recognized as the same visitor. We store the page visited, the first page of the visit, the host name of the referring site, and any campaign tags or advertising click identifiers in the link. We do not store your IP address, your user agent, the full address of the referring page, or the query string of the page you landed on. If you later create an organization, we attach that visit's channel to the organization so we know where our customers come from.
- Google Analytics, where enabled. Standard page measurement, and only on the pages listed above other than sign-in and sign-up — those two are excluded specifically so that no sign-in parameter can ever reach it. Everywhere it does run, we replace the address it reports with one stripped of every query parameter except campaign tags, and reduce the referring address to its origin. Google Analytics sets its own cookies, which last up to two years. See Section 7 for what Google itself collects.
We honor your choice. If your browser sends a Do Not Track or Global Privacy Control signal, we load nothing and record nothing — no first-party counter, no Google Analytics. You can also opt out on this device with one click: turn off analytics for this browser (and turn it back on if you change your mind). We do not use cross-site trackers or advertising networks, and we do not track you across other websites.
12. International transfers
The Service and its Sub-processors are operated principally in the United States. Do not use the Service to process information about individuals in jurisdictions whose transfer rules you have not satisfied. See Section 2.
13. Children
The Service is not directed to children, and we do not knowingly collect information directly from anyone under 18. If a customer's records happen to include information about a minor (for example, a minor named on a title), it reaches us only as Customer Data under the customer's control.
14. Changes to this policy
We may update this policy. We will post the updated version at /legal/privacy with a new version identifier and, for material changes, give at least thirty (30) days' notice to the email address on the account before the change takes effect. Material changes may require you to re-accept.
15. Contact
Privacy questions, requests, or security reports:
Just OK Assets, LLC 3030 Northwest Expressway, Ste 200B, Oklahoma City, OK 73112, USA