Skip to the privacy policy
Deal42
Home Privacy Terms Providers Support
Log in
Privacy
  1. Overview
  2. Information processed
  3. How information is used
  4. Providers and AI
  5. Connected sources
  6. Google API data
  7. Browser storage
  8. Retention and requests
  9. Contact

Effective September 19, 2026

Privacy Policy

A plain-language summary of how the free Deal42 tool handles information.

1. Overview

Deal42 is a free tool for reviewing deal information. The public website and the signed-in tool are separate. Google Drive, Dropbox, Airtable, and Notion remain separate services controlled by their users. Google Meet also remains a separate service if its default-off transcript connector is separately enabled for a user.

2. Information Deal42 processes

  • Account information: email address, sign-in identifiers, session and security information.
  • Deal content: files, records, notes, and other material you upload or choose to import.
  • Tool activity: jobs, results, usage limits, source references, and basic audit events.
  • Connected-service information: connection status and, for Airtable, Notion, or a separately enabled Google Meet connection, encrypted authorization data while connected.
  • Support information: messages and attachments you choose to send to support.

3. How information is used

Deal42 uses information to:

  • sign users in and keep accounts secure;
  • run the deal-review features a user requests;
  • save deal history and results;
  • prevent abuse, troubleshoot problems, and maintain the tool; and
  • answer support and data requests.

Deal42 does not run advertising or sell personal information.

4. Providers and AI processing

Deal42 uses Cloudflare for delivery, security, Workers, and private file storage; Supabase for authentication and application data; and Render for background processing. See the Providers page for the simple list.

When you run an analysis, relevant deal content may be sent to OpenAI or Anthropic to generate the requested output. Deal42 does not send content to an AI provider merely because you visit the public website.

5. Connected sources

  • Google Drive: Deal42 uses Google Picker and the drive.file permission for a file you deliberately select. It reads the connected account label and the selected file’s identifier, name, type, size, and revision details needed to validate and import that file. Deal42 does not list your whole Drive or edit, upload, or delete files in Google Drive.
  • Google Meet (default-off): if the connector is separately enabled and you connect it, Deal42 uses read-only Google authorization to show eligible ended meetings. Deal42 reads a transcript only after you explicitly select and confirm it.
  • Dropbox: Deal42 receives only the file you select for the requested import.
  • Airtable and Notion: Deal42 can keep an encrypted connection while you choose to stay connected.
  • Writeback: importing content does not authorize source edits. You can request an Airtable writeback in one action, or explicitly enable automatic writeback for an Airtable connection in Connections. Automatic writeback is off by default and fills empty mapped fields after a successful analysis while the Control Center is open; pending writes can resume in the same browser. Airtable writeback preserves existing values and verifies the saved values. Notion writeback requires a separate preview and confirmation.

Disconnecting or revoking a source stops future access but does not by itself remove a copy already imported into Deal42.

6. Google API data

Google Drive

Access and use. When you connect Google Drive, the browser requests only https://www.googleapis.com/auth/drive.file. Deal42 uses the resulting short-lived authorization to show the connected Google account, open Google Picker, validate the one PDF you select, and download that PDF for the deal review you request.

Token handling and storage. The Google Drive access token is kept only in memory in the current browser tab. It is not written to browser storage, Supabase, Cloudflare R2, logs, or a processing job, and Deal42 does not request or store a Google refresh token. After an import, Deal42 keeps one private copy of the selected PDF and the source reference, job, result, and audit information needed to provide the requested Deal42 features. Deal42 does not store a copy of your whole Google Drive.

Processing and sharing. The imported copy and related application records are handled by the services described on the Providers page: Cloudflare stores the private file, Supabase stores application records, Render runs the requested analysis, and relevant deal content may be sent to OpenAI or Anthropic only when you request an AI analysis. Deal42 does not use Google user data for advertising, sell it, use it to determine creditworthiness, or use it for an unrelated purpose.

Disconnect and deletion. Disconnecting clears the in-tab Google authorization and asks Google to revoke it. Revoking Deal42 in your Google Account also stops future access. Neither action deletes a PDF or result already imported into Deal42. To request removal of Deal42-held Google Drive content and related records, email support@deal42.ai from the address linked to your Deal42 account and identify the file or deal.

Google Meet transcripts (default-off)

Availability, access, and use. The Google Meet transcript connector is default-off. If it is separately enabled for your account and you choose to connect it, Deal42 requests exactly openid and https://www.googleapis.com/auth/meetings.space.readonly. The openid scope confirms which Google account is connected. The read-only Meet scope lets Deal42 list eligible ended conference records and read the transcript, participant and speaker attribution, and meeting and transcript timing needed to show and verify a transcript you can access. It does not let Deal42 create, join, record, edit, or delete Google meetings or Google Meet content.

Credential handling. Unlike the Google Drive Picker flow above, Google Meet is a saved server-side connection. Google Meet access and refresh credentials are encrypted before they are stored in Deal42’s tenant-bound connection store. Deal42 uses them only on the server for the connected user’s read-only requests. Raw credentials are not placed in browser storage or exposed in the user interface.

Import, storage, and AI processing. Connecting a Google Meet account does not by itself import, freeze, or analyze a meeting. Only after you explicitly select and confirm an eligible ended transcript may Deal42 verify it and create a private, tenant-bound immutable snapshot for the deal you selected. Cloudflare stores the private snapshot and Supabase stores related connection, source, and audit records. Relevant transcript content may be sent to OpenAI or Anthropic only when you separately request an AI analysis; it is not sent merely because you connect Google Meet or view available meetings.

Disconnect, revocation, and deletion. Disconnecting Google Meet removes Deal42’s saved connection credentials and stops future reads through that connection. Revoking Deal42 in your Google Account also stops future access. Neither action by itself deletes a transcript snapshot or result already imported into Deal42. To request removal of Deal42-held Google Meet content and related records, email support@deal42.ai from the address linked to your Deal42 account and identify the meeting or deal.

Deal42’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Browser storage

The website stores a theme preference. The signed-in tool uses browser storage and necessary session data for authentication, preferences, and bounded recovery of interrupted work. Deal42 does not currently use advertising, replay, or third-party product-analytics tools.

8. Retention and data requests

Deal42 keeps information needed to operate the tool, protect accounts, and preserve requested deal-review history. The tool does not currently offer self-service account deletion or a self-service export.

To ask about access, correction, export, account closure, or removal of Deal42-held content, email support@deal42.ai from the address linked to your account. Deal42 may need to verify your identity and the requested scope before acting.

9. Contact and changes

Questions about this policy can be sent to support@deal42.ai. Updates will be posted on this page with a revised effective date.

Deal42 — evidence-backed deal review.
Home Privacy Terms Providers Support

Effective September 19, 2026