Version 2.0 · Last updated: August 22, 2026
This policy applies worldwide and is designed to satisfy the privacy laws of all fifty U.S. states, the District of Columbia, and the other jurisdictions listed in Section 12.
Compliance Technologies ("Compliance Technologies", "4eye", "we", "us") is an independent organization operating as part of the non-profit initiative OpenVerdict Inc., doing business as 4eye.me, and residing in the State of New York. We operate the ComplaintAI service at 4eye.me and app.4eye.me. We are the controller (and, where applicable, the "business" under the California Consumer Privacy Act) for personal information we collect about our own users. Where a business customer, such as a property management company or landlord, uploads personal information about its tenants, that business customer is the controller (the "business") and we process that information only on its documented instructions as a service provider / processor (Section 10).
We help consumers prepare, file, and track complaints with government agencies, including the Consumer Financial Protection Bureau (CFPB), the Federal Trade Commission (FTC), state Attorneys General, and other regulators. Separately, we provide business tools for property management companies and landlords to receive, manage, and respond to complaints. Because both functions involve sensitive records, this policy is written to be specific rather than generic.
| Category | Examples | Why | Shared with |
|---|---|---|---|
| Account data | Email address (magic-link sign-in) | Create and secure your account | Our authentication and email-delivery providers |
| Profile data | Name, mailing address, phone, date of birth | Required by agency complaint forms | The agency you file with; AI processors during drafting |
| Sensitive identifiers (optional) | Social Security Number (only for certain CFPB categories); identity-verification data | Agency form requirements; identity verification | Encrypted at the application layer before storage; never sold |
| Evidence documents | Bank statements, receipts, letters, screenshots, call logs you upload | Extract facts and draft your complaint | AI processors (Azure OpenAI, Mistral OCR on Azure, Anthropic Claude) |
| Complaint content | Drafts, filed narratives, confirmation numbers, agency status history | Provide the service and track outcomes | The agency you file with |
| Agency credentials (optional) | CFPB portal email/password and MFA codes; optional Gmail app password used solely to read MFA emails | File and poll status on your behalf | Encrypted at rest; used only against those portals |
| Business account data | Organization name, verification documents, license key, team members, properties, units, leases, tenant complaints | Provide the enterprise portal | Stored for your organization; tenant data controlled by you (Section 10) |
| Payment metadata | Payer ID, subscription ID, transaction amount, credit ledger entries | Billing and audit | PayPal (we never see card or bank numbers) |
| Usage analytics | IP address, request timestamps, referer, country, path, utm parameters | Security, fraud prevention, service improvement | Kept internally; no advertising cookies, no Google Analytics |
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not build advertising profiles. We have never done either.
Consumers.
Business customers (property management companies and landlords).
We deliberately do not publish details about our infrastructure, storage layout, or security architecture; those details are maintained internally on a need-to-know basis because the service handles regulatory correspondence and other categories of non-public information. Because we run no third-party ad tech, there is nothing to which a Global Privacy Control signal could apply beyond what we already do not do; we honor GPC as a "do not sell or share" instruction regardless.
We use personal information to:
We do not use personal information for automated decisions that produce legal or similarly significant effects about you. Filing always requires a human click: the AI drafts, you approve.
Legal bases (EEA/UK users): performance of a contract (providing the service), legitimate interests (security, fraud prevention, product improvement), consent (optional features such as portal credentials or SSN entry), compliance with legal obligations (records tied to filings), and substantial public interest / legal claims where relevant to complaint correspondence.
Document analysis and drafting use three classes of AI models:
Each provider operates under commercial terms that prohibit training on our inputs. Every dollar amount, date, reference code, and account number in a generated document must trace back to extracted facts; anything unverifiable is flagged and corrected or surfaced for review before filing is allowed. You remain the final reviewer, and nothing is submitted to any agency until you explicitly approve it.
We share personal information only as follows:
| Recipient | What | Why |
|---|---|---|
| Government agencies (CFPB, FTC, state AGs, OCC, SEC, BBB) | Your complaint narrative, required identifying fields, and exhibits | You approved the filing |
| Managed database / authentication / storage provider | Account, application, and file data | Database, authentication, and file hosting |
| Frontend hosting provider | Web traffic and request logs | Serving the web application |
| Backend cloud host | Application workloads and encrypted records | Running the service |
| AI model providers (OCR, extraction, drafting) | Evidence content during processing | AI processing (no training on your content) |
| PayPal | Transaction metadata | Payments |
| Email delivery provider | Email address and message content | Transactional email delivery |
| DNS / TLS / inbound-email infrastructure provider | Routing of agency MFA emails you direct to us | Infrastructure and email routing |
| Identity verification partner | Identity-verification flows where applicable | Verification |
| Law enforcement / legal process | What a valid subpoena or court order compels | Legal compliance; we notify you when permitted |
We keep this list at the category level on purpose: we do not publish the specific vendors or architecture behind each category. A detailed sub-processor list is available to business customers under their Data Processing Agreement.
A filed complaint becomes part of the receiving agency's records and may be published in anonymized form under that agency's rules (for example, the CFPB's public consumer complaint database). Once filed, submission cannot be undone by us.
We do not disclose detailed security architecture publicly. No system is perfectly secure; Section 13 explains breach notification.
Regardless of where you live in the United States, you may email legal@4eye.me to access, correct, export, or delete your personal information, or to withdraw consent for optional features. We verify requests by contacting you at your account email and respond within 30 days (45 days where a state law allows an extension).
California (CCPA/CPRA). California residents have the right to:
Other states. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island (each with a comprehensive privacy law in effect as of January 2026), together with residents of any other state, receive at minimum: confirmation of processing, access, correction, deletion, portability, the ability to opt out of targeted advertising, sale, or profiling (all of which we do not engage in), and appeal of any denied request by replying to our decision email. Maryland residents additionally receive the strictest processing limits available anywhere in this policy: we collect only what is reasonably necessary for the services you request.
Authorized agents may submit requests with written permission. Parents and guardians may exercise rights on behalf of children under 16.
When a property management company or landlord uploads tenant information, that customer determines the purposes and means of processing and remains responsible for having a lawful basis (such as performing the lease or a legitimate business need) under laws like the Fair Credit Reporting Act when applicable, state landlord-tenant statutes, and local housing rules. We process tenant data strictly to deliver the portal: intake, routing, response drafting, statements, and support.
The service is intended for adults 18 and older. We do not knowingly collect personal information from children under 13 (COPPA, 16 C.F.R. Part 312) or maintain accounts for anyone under 18. If a child has provided us personal information, contact us and we will delete it promptly.
We serve users worldwide from infrastructure in the United States. For transfers out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses (Module Two/Three as applicable) plus supplementary technical measures; UK transfers use the UK Addendum. Transfers from Canada occur under PIPEDA's accountability principle with comparable safeguards, from Brazil under LGPD Article 33 mechanisms (including SCCs), and from Australia under APP 8 with comparable protection commitments. EEA/UK users may lodge a complaint with their supervisory authority (or the ICO in the UK); we will provide our SCC-executed DPA on request.
Your EEA/UK rights include access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent, exercisable at legal@4eye.me.
If we determine that personal information was subject to a breach of security, we will notify affected individuals without unreasonable delay as required by every U.S. state's breach-notification statute (as New York residents under Gen. Bus. Law § 899-aa and elsewhere), HHS-style timelines do not apply, but where GDPR/UK GDPR applies we will notify the competent supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in risk, and we will keep a written incident log.
When we make a material change to this policy or to the Terms of Service, we will automatically notify every registered account holder by email at least 14 days before the change takes effect, summarizing what changed, and we display a notice banner inside the app. Non-material edits (clarifications, typo fixes) update the version line at the top without individual notice. If a change affects an active paid subscription in a way you do not accept, you may cancel before the effective date without penalty.
Version history: v1.0 (May 31, 2026, initial publication); v2.0 (August 22, 2026, dual-audience rewrite covering business customers, payment-consent flow, U.S. state and international rights).
Privacy questions, data requests, appeals, and security reports: legal@4eye.me. We correspond by email only and do not publish a postal address.