Closefile

Privacy

Privacy policy

Last updated: July 14, 2026

Information collected

The review request form collects your name, email, team or company name, website, team type, team size, current escrow tools, and a short description of where your escrow review workflow currently needs more control.

Why it is collected

This information is used to review whether Closefile is a fit and to identify the first forwarded-email, deadline-review, source-context, or calendar-handoff step that may be worth tightening.

Public form limits

The public form is for workflow context only. Do not submit confidential escrow files, wire instructions, bank details, social security numbers, or private client documents.

No deadline guarantee

Closefile is a workflow review surface. It does not guarantee legal, contractual, regulatory, title, escrow, wire, or deadline outcomes.

No selling of submitted information

Closefile does not sell submitted review request information.

Google Calendar data we access

When you connect Google Calendar, Closefile requests the owned Calendar Events scope, https://www.googleapis.com/auth/calendar.events.owned. It applies only to events on calendars you own. Closefile accesses the OAuth authorization code, access token, and refresh token; the configured Calendar identifier; user-approved event details; the Google-returned event ID and Calendar link; response fields read by a known Closefile-created event ID; and coarse OAuth and Calendar audit and error metadata.

Closefile uses this data to authorize the connection, create and update approved all-day escrow deadlines, run a one-time connection self-test, prevent duplicate events, verify or remove known Closefile-created events, show the Calendar receipt, and diagnose sync failures. It does not list or browse unrelated Calendar events. Closefile does not create aggregated, anonymized, or derived datasets from Google user data.

Google user data sharing and disclosure

Closefile discloses Google user data only to the recipients needed to provide and operate the Calendar connection. Google APIs receive OAuth credentials and the approved event details needed to authorize the connection and create, update, verify, or remove Closefile-created events. Closefile's hosting and database infrastructure providers store and process encrypted refresh tokens, Calendar event identifiers and links, and related audit records as service providers for application hosting, storage, backup, and security. Access by authorized personnel and contractors is limited to support, security, compliance, or legal work that requires it. Closefile may also disclose this information to government authorities or other parties when required by law or necessary to protect users or the service.

Anthropic processes forwarded escrow email content for deadline extraction, and Resend processes separate intake and notification email workflows. Google Calendar API data is not sent to Anthropic, Resend, or another third-party AI/ML provider.

Closefile does not sell Google user data or disclose it to advertisers or data brokers. It does not use Google user data for advertising, credit or lending decisions, an unrelated purpose, or to train AI or machine-learning models. These restrictions apply to raw, aggregated, anonymized, or derived Google user data.

Google user data protection

Closefile encrypts Google refresh tokens at rest using AES-256-GCM. Browser connections to Closefile and Closefile requests to Google APIs use HTTPS/TLS. The authorization flow uses PKCE and one-time, time-limited state values bound to the signed-in account and session. OAuth credentials stay on the server and are not included in customer-facing responses. Account-scoped sessions, time-bounded and rate-limited reviewer access, and restricted operator access limit who can reach stored Google data. Audit and error handling redacts tokens, authorization codes, and event content.

Closefile operates only on approved escrow deadline events, connection self-test events, and known Closefile-created event IDs used for verification, update, or removal. Disconnecting disables the stored credential locally, attempts revocation with Google, and requires fresh consent before Calendar access resumes.

Data retention and deletion

Forwarded escrow email bodies and headers are kept only as long as needed for extraction, review, and audit, and are removed within 30 days after an escrow reaches a closed or terminal state, unless a legal hold or active dispute requires longer retention.

The Google refresh token is kept while Calendar is connected. Calendar identifiers and links, approved event details, and related audit records are kept as the chain of custody for the escrow transaction. When data is deleted from the active system, it may remain in restricted backups until those backups age out through the normal backup lifecycle. Backups are used only for service recovery.

You can revoke access from your Google Account or request account-data deletion at the email address below. Closefile disables the stored credential and stops further Calendar calls. It deletes Google credentials and Google-derived identifiers and links unless bounded retention is required for an active escrow, dispute, or legal hold.

Google API Limited Use

Closefile's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Questions can be sent to aaron@gradualsystems.io.