PrefMark
Back to site
Legal

Privacy, Terms &
Security

Effective date: June 2026 · Last updated: September 2026
Operator: PrefMark project, pending formal entity formation.
Questions: hello@prefmark.com

Contents
Privacy PolicyWhat we collectWhat we do not sellNo training on customer dataHow we use informationAI processingConnected AI appsService providersData sharingAccess by PrefMarkData retentionYour rightsConfidential and sensitive informationCookies and browser storage
Terms of ServiceWhat PrefMark isWhat PrefMark is notBeta and early-access natureUser contentAI-generated outputsProhibited usesSensitive information and regulated useExported documentsLimitation of liability
Security and TrustSecurity principlesNo training on customer dataCompliance status
Privacy Policy

How we handle your data

PrefMark is built around a simple principle: customer deal data should be handled carefully, used only to provide the product, and not sold or used for advertising. This Privacy Policy explains what we collect, how it is used, when it may be shared, and what rights you have.

By using PrefMark, you agree to this Privacy Policy.

What we collect

Account information. When you create an account, we may collect your email address, authentication credentials, account settings, and login and session information. Passwords are handled through our authentication provider and are not stored by PrefMark in plain text.

Deal workspace information. When you use PrefMark you may create, upload, generate, or save company names, company profile fields, deal notes, investment materials, uploaded documents, extracted deal signals, diligence questions, answers, evidence notes, statuses, calculations, AI-generated reads, investment memos, IC memos, conviction memos, and PDF or DOCX exports.

You should only upload information that you are authorized to upload and process.

Usage and technical information. PrefMark may collect limited technical information needed to operate, secure, and improve the service, including browser type, device type, IP address, log-in events, error logs, feature usage, AI generation metadata, and performance information. Where possible, logs avoid raw confidential deal content.

What we do not sell

PrefMark does not sell customer data. PrefMark does not sell uploaded documents, deal information, memos, diligence answers, or usage data to advertisers or data brokers. PrefMark does not use customer deal materials for advertising targeting.

No training on customer data

PrefMark does not use customer-uploaded investment materials, deal workspaces, diligence answers, memos, calculations, or exports to train general AI models. AI providers may process inputs and outputs only to provide the requested AI functionality, subject to their applicable commercial, security, and data-processing terms.

How we use information

PrefMark uses information to create and manage user accounts, authenticate users, store saved companies and deal workspaces, process uploaded investment materials, extract structured deal information, generate Quick Reads and triage outputs, generate diligence questions, track diligence status, generate investment memos and exports, provide calculators and AI-assisted reads, maintain security, debug errors, communicate with users about account or product matters, and comply with legal obligations.

AI processing

PrefMark uses AI systems to assist with document extraction, summarization, diligence question generation, memo generation, deal analysis, and related product features. AI outputs may be inaccurate, incomplete, outdated, or misleading. Users should review all AI outputs before relying on them.

PrefMark may send relevant deal materials, extracted fields, user inputs, diligence answers, and related context to AI providers in order to generate requested outputs. PrefMark avoids logging raw uploaded documents or full confidential prompt payloads.

Connected AI apps

You can connect third-party AI apps, such as Claude, ChatGPT, Cursor or Gemini, to your PrefMark account through PrefMark's MCP server. A connection exists only after you sign in to PrefMark and approve it, and it can do only what you approved. The permissions are: read your deals, evidence, diligence questions and memos; edit your diligence tracker (add questions, record answers and evidence, change status); add deals, edit deal details and save notes to a deal; suggest updates that wait for you to accept them in PrefMark; and rewrite a section of an Investment Memo after you approve the exact text in the app. You can untick any permission when you connect.

What the AI app receives. When a connected app calls PrefMark, the information that call returns (for example deal names, stance, facts, evidence tiers, open questions and pending proposals) is sent to that app. The app's provider, such as Anthropic, OpenAI or Google, handles it under your own agreement with that provider, not under this policy. Only connect apps your organization allows you to use with deal information.

What PrefMark receives. PrefMark receives the tool calls the app makes, such as a company name to look up, a question or answer to save, notes to add to a deal, a statement you ask it to send as a proposal, or memo text you approved. PrefMark does not receive your conversation with the app, and connected apps cannot read other information in your account beyond what the approved tools return.

What PrefMark stores. For each connection PrefMark stores the app's registration details, the permissions you approved, and hashed access and refresh tokens (never the tokens themselves). PrefMark records which tools were called and when, for security and rate limiting, without the call arguments or deal content. Changes an app makes with your permission (diligence questions and answers, deal details, new deals and notes) are saved to your workspace like changes you make yourself. PrefMark also keeps a record of each such change, with the item as it was before and after, so the deal shows which app made it and you can undo it or restore a removed question. That record is deleted with the deal or your account. A proposal an app sends is stored with your deal as part of its history, along with whether you accepted or dismissed it, and changes nothing unless you accept it. Every change to a memo section, including edits approved in an app, Undo and restores, is kept in that section's version history so you can restore an earlier version.

Your controls. You can see and revoke every connection in PrefMark under Settings, then Connected agents. Revoking takes effect immediately. Access tokens expire after one hour, and a connection left unused for 30 days must be approved again. Deleting your PrefMark account deletes its connections, tokens and this history. How to connect each app is described at prefmark.com/connect.html.

Service providers

PrefMark uses trusted infrastructure providers to operate the product. Current providers include:

  • Supabase: database, authentication, storage, and edge functions. Supabase Privacy Policy
  • Cloudflare: hosting and delivery.
  • Anthropic: AI model processing. Inputs relevant to the requested feature are processed to generate outputs. No account or identity data is sent. Anthropic Privacy Policy
  • Resend: transactional email (password resets and account confirmation only). Resend Privacy Policy

These providers may process data only as needed to provide services to PrefMark.

Data sharing

PrefMark may share information only in limited cases: with service providers needed to operate the product; when required by law, regulation, subpoena, or legal process; to protect the rights, safety, or security of PrefMark, users, or others; in connection with a merger, acquisition, or sale of assets subject to appropriate confidentiality protections; or with the user's direction or consent. PrefMark does not share customer deal data with other customers.

Sharing a deal you choose to share: when you create a share link for a deal and another PrefMark user opens it, PrefMark copies that deal (its memo, materials and files, diligence questions and deal math) into their account as their own independent copy. Nothing else from your account is shared, later changes on either side are not copied, and you can turn a link off at any time. Links expire after 7 days. A copy already made belongs to the person who added it. An original file you already deleted is not copied; the copy keeps its analysis.

Access by PrefMark

PrefMark stores your materials so its software can read them and build your memo. That reading is automated. A person at PrefMark opens your deals or account data only when needed, for example to fix a problem you report. Each time that happens, PrefMark records when, which deal and why, emails you, and lists it in Settings, under Privacy, Access by PrefMark.

This is a commitment, not a technical barrier: someone with administrative access to PrefMark's database could read stored data without recording it. Only PrefMark's founder holds that access.

Ask PrefMark to look. When something fails, you can send PrefMark a request from the screen where it failed or from Help. The request carries the failed step and error codes, the deal's name and ids, and your optional note. PrefMark's founder receives it by email (without your note, which is read only in PrefMark) and, if you allow it, may open that deal to fix it, which is recorded and emailed to you as above. You can take that permission back at any time from the deal or from Settings, under Privacy, Your requests to PrefMark, and the request is deleted with the deal or your account.

Data retention

PrefMark keeps customer data for as long as needed to provide the service, comply with legal obligations, resolve disputes, and maintain security. When a user deletes a deal, file, or account, PrefMark deletes or disables active access to that data within a reasonable period, subject to backup retention windows, security logs, legal obligations, and technical limitations.

Your uploaded files. In Settings, under Your files, you choose what happens to the original files you upload or forward (decks, documents, emailed attachments, Drive imports and meeting notes stored as files): delete them 30 days after you upload them (the default), delete them as soon as PrefMark has read them, or keep them until you delete them or your account. You can also delete any original yourself from the deal's Materials. Deleting an original removes the file and the copy of its text PrefMark kept for reading it. The deal, its memo, the figures and risks taken from it, and its diligence questions stay, so the analysis keeps working, but the original can no longer be opened or read again; to re-analyze it, upload it again. A file PrefMark could not read, or read without finding anything, is kept until it is read or you delete it. Sample deals keep their files. Deleted files may remain in backups for a limited period.

Your rights

  • Access: you can request a copy of all data we hold about you.
  • Deletion: you may request deletion of your account and associated saved data.
  • Correction: you may request correction of inaccurate account information.
  • Portability: we can provide your saved data in a portable format on request.

To exercise any of these rights, email hello@prefmark.com.

EU and UK users: you have rights under GDPR and UK GDPR including access, erasure, portability, restriction of processing, and the right to object. Our legal basis for processing is performance of a contract. To exercise these rights, email hello@prefmark.com.

Confidential and sensitive information

Important: PrefMark may be used with confidential investment materials only if you have the right to upload and process those materials. Do not upload information you are not authorized to process, information prohibited by your employer, fund, or compliance team, material non-public information without appropriate authorization, or information subject to special handling rules unless your organization has approved use of PrefMark for that purpose. PrefMark is not designed to determine whether information is MNPI or otherwise legally restricted. Users are responsible for that determination.

Cookies and browser storage

PrefMark asks for your choice before storing anything optional. The banner offers Essential only and Allow analytics with the same prominence, and you can change your answer at any time using the Cookie settings control in the footer of any page, or in Settings inside the app.

Essential. Always on, and not subject to consent, because the product cannot work without them. These cover your sign-in session and authentication tokens, your appearance and interface preferences, the short-lived markers that stop an upload or a memo being processed twice, and the security checks that protect the sign-in and access request forms from automated abuse. PrefMark stores the choice you make on the banner in your browser, so you are not asked again on every visit. When you are signed in, the same choice (which categories you allowed, and when) is also saved with your PrefMark account, so a new browser, a new device or PrefMark added to your Home Screen does not ask you again. A choice made while signed out stays in that browser only: it is never added to the account of whoever signs in next. It is not sent to anyone else, and it is deleted with your account.

Analytics. Off unless you allow it. It covers PrefMark's own product events: which screens and actions are used, so we can tell whether a suggested memo change gets accepted, edited or ignored. An event is a fixed name, the ids of rows already in your account, and counts. It never carries memo text, a filename, a figure, an email address or anything from your Lens. It stays in PrefMark's own database under your account, only you can read it, and it is deleted when you delete your account. There is no third-party analytics, advertising or session recording tool, and nothing loads before you have consented.

Marketing. Off unless you allow it. PrefMark runs no advertising, retargeting or social media tracking, and this category is empty. PrefMark does not sell or share personal information for advertising.

The Geist typeface is served from prefmark.com rather than a font service, so opening a page does not disclose your IP address to a third party in order to load a font.

Children

PrefMark is designed for professional users and is intended for users 18 and over. We do not knowingly collect data from anyone under 18.

Changes to this policy

If we make material changes to this Privacy Policy, we will provide notice through the product or by email before the change takes effect. The current version is always at prefmark.com/legal.html.

Contact

hello@prefmark.com

Terms of Service

Terms of use

By accessing or using PrefMark, you agree to these Terms of Service. If you do not agree, do not use PrefMark. If you use PrefMark on behalf of a company, fund, or organization, you represent that you have authority to accept these terms on its behalf.

What PrefMark is

PrefMark is a mobile-first investment decision workspace for early-stage private deals. It helps users move from raw deal materials to a clearer investment decision through the following workflow:

Investment Intake → Quick Read → Diligence → Evidence → Investment Memo → Decision → Export

PrefMark may provide investment intake, document extraction, deal signal extraction, Quick Reads, initial triage, missing information analysis, key risks, diligence questions, diligence tracking, deal calculators, AI-assisted reads, investment memos, IC memos, conviction memos, PDF and DOCX exports, and deal workspace tools.

What PrefMark is not

PrefMark is not a registered investment adviser, broker-dealer, law firm, accounting firm, valuation firm, tax adviser, compliance adviser, fiduciary, exchange, or marketplace for securities. PrefMark does not provide legal, tax, accounting, investment, financial, valuation, regulatory, or compliance advice. No output from PrefMark should be treated as a recommendation to invest, not invest, buy, sell, hold, issue, or offer securities. Users remain solely responsible for their own investment, legal, tax, compliance, and business decisions.

Beta and early-access nature

PrefMark may be offered in beta, pilot, early-access, or experimental form. Features may be incomplete, unstable, changed, removed, or interrupted. AI outputs, document extraction, memo generation, export formatting, and diligence workflows may contain errors. Users should not rely on PrefMark as the sole basis for any investment or business decision.

Accounts

Users are responsible for maintaining accurate account information, keeping login credentials secure, all activity under their account, and promptly notifying PrefMark of unauthorized access. Use of PrefMark must comply with applicable policies and laws. PrefMark may suspend or terminate accounts that violate these terms or create security, legal, or operational risks.

User content

"User Content" includes any data, files, materials, documents, notes, answers, evidence, calculations, deal information, or other content that users upload, enter, save, or generate through PrefMark. Users retain ownership of their User Content. Users grant PrefMark a limited right to host, process, transmit, display, and use User Content solely as needed to operate, secure, and provide the service. Users represent that they have all rights needed to upload and process User Content through PrefMark.

AI-generated outputs

PrefMark may generate AI-assisted outputs including extracted fields, summaries, diligence questions, risk analysis, memos, and exports. AI outputs may be wrong, incomplete, misleading, outdated, or unsupported by source material. Users are responsible for reviewing, verifying, editing, and approving all outputs before using them. PrefMark does not guarantee that AI outputs are accurate, complete, compliant, investment-grade, or suitable for any specific purpose.

Prohibited uses

  • Violate laws or regulations
  • Upload content you are not authorized to use or process
  • Upload unlawful, harmful, or malicious content
  • Misrepresent AI outputs as independently verified facts
  • Make unlawful securities offers or provide unauthorized investment advice
  • Reverse engineer, copy, or redistribute the service
  • Interfere with service security or attempt unauthorized access
  • Scrape, overload, or abuse the service or circumvent rate limits
  • Use PrefMark to develop a competing product by copying proprietary workflows, design, prompts, or outputs
  • Violate employer, fund, compliance, confidentiality, or fiduciary obligations

Sensitive information and regulated use

PrefMark is not designed to determine whether information is material non-public information, restricted information, confidential supervisory information, or otherwise legally restricted. Users are responsible for determining whether they are permitted to upload, process, or analyze particular information using PrefMark. If you are regulated, employed by a fund, or subject to compliance obligations, you should obtain appropriate approval before using PrefMark with live deal materials.

Exported documents

PDF, DOCX, memo, and other exports are user work product generated from user inputs, uploaded materials, extracted fields, and AI assistance. Users are responsible for reviewing exports before sharing them. PrefMark does not guarantee that exports are accurate, complete, compliant, or appropriate for any investment committee, legal process, fundraising process, or investor communication.

Availability and changes

PrefMark may change, suspend, limit, or discontinue features at any time. PrefMark may experience downtime, delays, degraded performance, generation failures, or data-processing errors. PrefMark is not liable for losses caused by downtime, delays, failed outputs, or service interruptions.

Intellectual property

PrefMark owns the service, software, design, workflows, branding, prompts, templates, interface elements, and documentation. Users may not copy, modify, distribute, resell, or reverse engineer PrefMark without written permission. Users retain ownership of their User Content.

Disclaimers

PrefMark is provided "as is" and "as available." To the maximum extent permitted by law, PrefMark disclaims warranties of accuracy, reliability, availability, merchantability, fitness for a particular purpose, non-infringement, and suitability for investment, legal, tax, regulatory, or compliance use.

Limitation of liability

To the maximum extent permitted by law, PrefMark and its operators will not be liable for indirect, incidental, consequential, special, or punitive damages, including lost profits, lost opportunities, investment losses, loss of data, or reliance on outputs. PrefMark's total liability for any claim will not exceed the amount paid by the user in the twelve months before the claim. If the user has paid nothing, the maximum liability is zero.

Indemnification

Users agree to indemnify and hold harmless PrefMark and its operators from claims, damages, and expenses arising from User Content, unauthorized uploads, violation of these terms, violation of law, misuse of PrefMark, use of PrefMark outputs in investment or business decisions, or violation of third-party rights.

Termination

Users may stop using PrefMark at any time. PrefMark may suspend or terminate access if a user violates these terms, creates risk, abuses the service, or uses the product unlawfully. Upon termination, access to the account and data may be limited or removed, subject to applicable retention obligations.

Changes to these terms

If we make material changes to these Terms of Service, we will provide reasonable notice through the product or by email before the change takes effect. Continued use of PrefMark after changes take effect means the user accepts the updated terms. The current version is always at prefmark.com/legal.html.

Contact

Questions about these terms: hello@prefmark.com

Security & Trust

Security and Trust Notice

PrefMark is designed for sensitive investment workflows. Users may upload confidential investment materials, deal notes, diligence answers, and memo drafts. The product is built around data minimization, access control, and careful handling of AI processing.

Current security principles

  • User authentication via a managed authentication provider
  • Row-level security so each user can only access their own data
  • Private storage for uploaded files
  • Signed URLs for temporary file access where applicable
  • No public file buckets for sensitive user materials
  • Service-role keys not exposed client-side
  • AI logs that avoid raw confidential content where possible
  • Server-side memo saving
  • Deletion behavior that does not reuse deleted cached outputs unless the user re-uploads
  • Infrastructure access protected by strong credentials
  • Separation of user workspaces
  • Encryption in transit and at rest provided by infrastructure vendors

No system is perfectly secure. PrefMark cannot guarantee absolute security.

No training on customer data

PrefMark does not use customer deal materials to train general AI models. Customer data is processed only to provide requested product functionality. AI providers may process inputs and outputs as needed to generate requested AI responses, subject to their applicable terms.

Source traceability

PrefMark's product direction is to make generated outputs traceable to source materials where possible, including source document, extracted field, related diligence question, evidence note, and memo impact. This supports user review of AI outputs before reliance.

Compliance status

PrefMark does not currently claim SOC 2 certification, ISO 27001 certification, GDPR compliance certification, DORA readiness, HIPAA compliance, or other formal compliance certification. Formal certifications may be pursued if required by firm or enterprise customers.

User security responsibilities

Users should use strong passwords, protect account access, avoid sharing accounts, upload only authorized materials, review all outputs, and follow applicable employer, fund, legal, and compliance policies.

Security contact

Security questions: hello@prefmark.com

PrefMark
© 2026 PrefMark  ·  Home  ·  App ·