Privacy Policy

Last updated June 2026

Draft — to be reviewed by counsel before launch.

What this covers

This policy explains what Shingle collects when you use the app and the web dashboard, why we collect it, and what happens to it. Shingle is a roof-inspection reporting tool: the data flowing through it is your account details, your company branding, and the photos and addresses of the properties you inspect.

What we collect

Account details— your email address, your name if you add it, and your team members' emails when you invite them.

Company branding — company name, license number, phone, address, and logo, used to brand your reports.

Inspection data — the photos you upload and the property addresses, customer names, and claim details you enter for each inspection.

We do not collect payment card numbers — billing runs entirely through Stripe.

How we use it

One purpose: generating your inspection reports. Photos are analyzed to draft damage tags and narratives, and your branding is placed on the PDFs you export. Your data is never sold, never mined for advertising or marketing, and never used to train third-party AI models.

Sub-processors

A short list of services touch your data, each for one job:

  • Anthropic — analyzes inspection photos to draft damage tags and report narratives.
  • Stripe — billing and payment processing.
  • Resend — transactional email (verification, password resets, report shares).
  • Twilio — support phone and messaging.

Retention

We keep your data until you delete it. Delete an inspection and its photos and reports go with it; delete your account and everything goes. Expired report share links stop working automatically.

Your rights

You can export or delete your data at any time — inspections and reports can be deleted in-app, and you can ask support for a full export or full account deletion. We don't make you jump through hoops.

Cookies and sessions

We set a session cookie to keep you signed in and an optional trusted-device cookie if you ask us to remember a device for two-factor sign-in. No advertising or cross-site tracking cookies.

Security

Passwords are hashed, sessions can be reviewed and revoked from your security settings, and two-factor authentication and passkeys are available to every account. Report share links are signed and expire.

Changes to this policy

If this policy changes in a way that matters, we'll email the account owner before the change takes effect.

Contact

Questions or requests: support@shingle.app.