Privacy policy
Effective 2026-09-20
What we keep, who can access it, and how you stay in control.
Lookover is operated by Webspin, LLC. This policy covers our website, mobile app and explanation service, including documents uploaded on our website or app or sent by email or text, questions and answers, the account page and family summaries. Our health data privacy notice provides additional information about health-related documents.
Information we collect
- Account and payment records: contact details, plan, subscription status, consent records and billing identifiers. Stripe, Apple or Google collects payment details for purchases made through its checkout; we receive the information needed to manage your subscription, not your complete card number.
- People on your account: names and contact details you or an account holder provide, invitations, confirmations, sharing preferences and access history.
- What you send: photos, documents, email content and attachments, texts, follow-up questions and corrections. These may contain financial, health or other sensitive information about you or others.
- What we produce: explanations, extracted names, amounts and dates, warning signs, reminders, summaries and account context used to interpret later submissions. These are computer-generated inferences and can be wrong.
- Support and technical records: help requests and replies, delivery status, processing records, security and access logs, and website request information such as IP address and browser details.
- The Lookover app, if you install it: the name and type of each phone or tablet you sign in on, an identifier the app creates for that installation, and, only if you turn notices on, the token your phone’s notification service issues. Photos you take in the app can be saved as encrypted drafts until you send them. Drafts are scoped to your sign-in and household and excluded from device backups. They are removed after successful submission or sign-out, or during cleanup after one day. Background uploads and opening originals also create temporary files in protected app storage; these are cleared after completion and during the next launch after an interruption. Notices contain a short generic sentence and never the contents of a document.
- Optional app diagnostics and usage: when crash reporting is configured, Sentry receives filtered technical error reports and connection metadata. We exclude document text, questions, email addresses and credentials from those reports. If you enable Help improve Lookover, we also collect limited interaction events, such as an upload starting or failing, linked to your account. You can turn usage events off in Your account.
- Apple or Google sign-in: if you choose one of these options, we receive the provider identifier and verified information it shares. Apple may supply a private relay email address. We keep an encrypted Apple token to revoke access when you remove that sign-in method or delete your sign-in; a pending revocation token is retained until the provider confirms the request.
We receive information from you, people participating in your account, and providers that handle payments, messages and service infrastructure. We do not connect to your bank or continuously read your inbox. Only send information you have the right to share, and cover unnecessary identifiers before taking a photo.
How we use it
We process information to explain what you send, answer follow-up questions, keep your record, send reminders and authorized summaries, administer subscriptions, provide support, prevent abuse and comply with legal obligations. Corrections and saved context help improve explanations for your account. Explanations inform your decisions; Lookover does not make legally significant decisions about your eligibility for credit, insurance, employment or healthcare.
We do not sell personal information, use it for targeted advertising, or share it for other companies’ marketing. We do not use your documents to train general-purpose models without a separate opt-in. Account-specific context and processing needed to answer you are different from training a general-purpose model.
Family sharing is a real privacy choice
Each sender chooses whether to share their documents, explanations and extracted details with each named person. Getting explanations and family sharing are separate choices. Reply SHARE from your registered phone or email to see the people available and choose with the reply code provided. A summary recipient must also accept their email invitation. The account holder can always see their own records. Get permission before inviting another adult; being related does not authorize you to consent for them.
Use People & sharing in your Lookover account to withdraw sharing permission for one person or everyone. New account views, summaries, alerts and exports will exclude your records for those people. Removing a sender also stops their new submissions and withdraws their sharing permissions. Removing a summary recipient stops their future summaries and alerts. These actions do not delete the records or recall messages and copies already delivered. Contact us to request deletion or help with your rights.
Automated reading and authorized human access
Software generates document explanations without requiring a human reviewer first. Authorized staff can access stored originals, explanations and processing records through restricted administrative tools for support, troubleshooting, quality review, security or other necessary service operations. Access to originals and document content is logged. Human support staff can read and answer requests for help. Automated reading does not mean human access is impossible.
Service providers and other disclosures
Providers receive information needed for their role. The configured provider can change, and providers may retain limited records under their own terms and legal obligations.
- Hosting and email: Amazon Web Services supplies infrastructure, storage and email delivery.
- Document processing: Anthropic processes submitted content to generate explanations and translate outgoing messages into your chosen language. The service also supports routing through OpenRouter to selected model providers. For that route we request providers that disallow data collection for training. This setting is not a guarantee of zero retention or zero human access.
- Text messages: supported messaging providers include Twilio and Telnyx, along with participating carriers. They process numbers, message content, attachments and delivery records as needed for messaging.
- Payments: Stripe handles checkout, payment methods, subscription billing and payment-related fraud prevention for web purchases. Apple and Google manage purchases made through their respective app stores.
Our original-document retention setting does not control every provider’s separate retention. For example, Anthropic’s standard commercial API retention is generally up to 30 days, with exceptions for agreed terms, certain features, safety investigations and legal requirements. Provider settings and contractual terms determine the processing that applies.
We may also disclose information when legally required, to protect rights and security, or as part of a business transfer subject to applicable privacy commitments and required notices or consents. These purposes do not authorize selling text-message consent or using your documents for unrelated advertising.
How long we keep information
- Originals and temporary content: the default original-document and model-archive retention is 30 days, or you can choose 7 days. “Keep explanations only” temporarily stores originals to process your request, then removes them and does not save new model input/output archives. Existing originals are removed during the next cleanup. Failed processing and cleanup retries can delay removal. Support-message bodies have a separate minimum 7-day window so people can answer your request. Provider retention is separate.
- Your ongoing record: explanations, saved questions and answers, extracted facts, corrections, reminders and sharing records remain while the account is active so the service can provide context and summaries.
- When service ends: account-content deletion is scheduled after 30 days. The cleanup process also requests supported provider deletions and retries failures. This is not a promise that every copy on every system disappears at exactly 30 days.
- Limited exceptions: backups may remain until replaced or expired. We may retain billing, security, consent, audit and deletion records, or information necessary for a legal obligation or dispute, for as long as that purpose requires. These records are restricted and are not a continuing document archive.
A verified request to exercise a legal deletion right is handled under the applicable legal deadline, separately from routine cancellation cleanup. Copies received by family members or retained by your own email provider or carrier are outside our direct control.
Security, cookies and location
We use encryption for stored document content and explanations, account-specific encryption keys and restricted administrative access. No system is completely secure. Ordinary email and SMS are not end-to-end encrypted, and messages may be visible on shared devices or lock screens.
The app keeps your sign-in credential in the phone’s secure storage and does not store explanations or documents on the phone. It contains no advertising or analytics software. You can see and sign out every phone from Your account, and turning notices off there stops them without affecting texts, emails or your subscription.
Account pages use cookies and similar storage for sign-in and security. The marketing site does not use advertising trackers. We do not sell or share information for cross-context behavioral advertising, regardless of a browser’s opt-out signal. Technical security and request logs may still be created.
Lookover is operated in the United States. Providers may process information in the United States and other locations where they operate; privacy protections can differ by location. Lookover is intended for adults and is not directed to children under 18. Contact us if you believe a child has opened an account.
Your choices and privacy rights
In the website, you can export the records you are allowed to see and manage your sharing choices. The person managing a household can change its original-document retention or close it. Your account settings separately let you manage sign-in addresses and delete your sign-in after transferring or closing households you manage and ending subscriptions you pay for. Deleting a sign-in removes its addresses and sessions; earlier documents and contact information in household records follow that household’s retention policy. You can also email legal@lookoverit.com to request access, correction, deletion, a copy of your information, or withdrawal of consent where processing depends on it. Withdrawal does not undo lawful processing already completed and may prevent the requested feature from working.
Rights vary by location. We will verify requests using information reasonably needed to protect your account and respond within the time required by applicable law. An authorized agent may contact us with evidence of their authority. If we deny a request, you can appeal by replying to our response or emailing the same address and identifying it as a privacy appeal. You may also contact your state privacy regulator. We do not discriminate against you for exercising a protected privacy right.
Changes and contact
We will update the effective date when this policy changes, notify account holders before material changes take effect, and obtain consent where required. Contact legal@lookoverit.com or write to Webspin, LLC, 5900 Balcones Drive #31281, Austin, TX 78731.