Featherlily Productions LLC

Privacy Policy

Effective Date:

Featherlily Productions LLC (“Featherlily,” “we,” “us,” or “our”) provides GoodOrder and related websites, software, customer portals, and support services collectively referred to as the “Services.”

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our website, purchase or activate GoodOrder, use the GoodOrder software, contact us, or otherwise interact with the Services.

GoodOrder is currently offered only to customers located in the United States. It is not directed to individuals or organizations located in the European Economic Area, United Kingdom, or Switzerland.

By using the Services, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

The information we collect depends on how you interact with the Services.

A. Account and Contact Information

We may collect:

  • your email address;
  • your name, firm name, or organization name, when provided;
  • verification and activation status;
  • support correspondence;
  • other information you voluntarily provide to us.

GoodOrder currently uses email verification rather than a traditional password-based customer account.

B. Subscription and Billing Information

Payments and subscription management are provided through Stripe.

We may receive or maintain information such as:

  • Stripe customer identifiers;
  • subscription status;
  • billing-period dates;
  • payment, invoice, refund, dispute, and cancellation status;
  • products or page packages purchased;
  • usage amounts associated with billing;
  • limited billing contact information made available through Stripe.

Featherlily does not directly receive or store complete payment-card numbers entered through Stripe Checkout.

Stripe separately processes payment and financial information under its own terms and privacy practices.

C. Installation and Activation Information

To activate, authorize, secure, and support GoodOrder, we may collect or generate:

  • installation identifiers;
  • activation tokens and related token records;
  • account-entitlement information;
  • activation, deactivation, and recovery status;
  • application version and build revision;
  • dates and times associated with verification, activation, and use;
  • information necessary to enforce the one-active-installation policy;
  • technical information related to failed or attempted activations.

Long-lived installation credentials are designed to be stored on the customer’s computer through Windows Credential Manager.

D. Usage and Page-Accounting Information

Because GoodOrder includes subscription allowances, prepaid pages, and usage-based overages, we may collect and maintain:

  • the number of pages submitted for processing;
  • the date and time a processing request was accepted;
  • the source of the page allowance used, such as included, prepaid, or automatic-overage pages;
  • reservation, commitment, release, retry, and reconciliation status;
  • metered-usage reporting status;
  • run identifiers;
  • error and completion status;
  • records necessary to prevent duplicate billing or unauthorized use.

These records may be retained even when the underlying customer documents are no longer available to Featherlily.

E. Customer Documents and Customer Content

GoodOrder is designed to process documents selected by the customer. These documents may contain confidential, privileged, personal, medical, financial, employment, litigation, or other sensitive information.

“Customer Content” includes:

  • source PDF files and document images;
  • text extracted through optical character recognition;
  • Bates numbers and other page identifiers;
  • page images or page representations;
  • document metadata;
  • duplicate-comparison information;
  • model inputs and outputs;
  • resulting PDFs, reports, CSV files, and other processing artifacts.

GoodOrder’s primary run workspace and outputs are stored locally on the customer’s Windows computer under the customer’s application-data directory. GoodOrder works from local copies and creates separate result files; it does not modify the original files selected by the customer.

However, GoodOrder is not a completely offline application. Customer Content may be transmitted through Featherlily-controlled infrastructure and to service providers when necessary to provide functions such as:

  • page counting;
  • optical character recognition;
  • Bates-number reading;
  • duplicate analysis;
  • artificial-intelligence-assisted review;
  • run authorization;
  • usage accounting;
  • error recovery.

Featherlily does not claim ownership of Customer Content.

Featherlily does not use Customer Content to advertise to customers or data subjects, create marketing profiles, or sell information about the contents of customer files.

Featherlily does not use Customer Content for model training or model improvement.

F. Local Application Data

GoodOrder may store information locally on the customer’s computer, including:

  • staged customer documents;
  • run history;
  • OCR results;
  • Bates-reading results;
  • duplicate-analysis state;
  • resumable processing state;
  • output PDFs;
  • CSV reports;
  • logs and status files;
  • application configuration.

The standard GoodOrder storage location is:

%LOCALAPPDATA%\Featherlily\GoodOrder

The standard workspace location is:

%LOCALAPPDATA%\Featherlily\GoodOrder\workspace

Local application data remains under the control of the customer and anyone with authorized or unauthorized access to the customer’s computer.

Uninstalling GoodOrder may not automatically remove all customer documents, outputs, run history, credentials, or workspace artifacts. Customers are responsible for reviewing and securely deleting local files when they are no longer needed.

G. Website and Technical Information

When you access our website, verification pages, gateway, or other online components, we or our hosting and security providers may automatically receive limited technical information, including:

  • Internet Protocol address;
  • browser and device information;
  • requested pages or endpoints;
  • date and time of access;
  • referring information;
  • network and error information;
  • security and rate-limiting events;
  • information used to detect abuse, fraud, automated attacks, or unauthorized access.

We do not currently sell this information or use it for third-party targeted advertising.

H. Transactional Email Information

Featherlily uses a transactional email provider to deliver messages such as:

  • email-verification links;
  • activation messages;
  • operational notices;
  • billing or account notices;
  • support-related communications.

In connection with these messages, we and our provider may process:

  • email address;
  • message content;
  • sending and delivery status;
  • bounce and suppression status;
  • dates and times;
  • limited technical delivery information.

Email-verification links are short-lived and single-use. Opening or previewing a verification link alone does not complete verification; the user must affirmatively confirm verification on a Featherlily-controlled page.

Transactional account messages are not, by themselves, enrollment in promotional marketing.

2. How We Use Information

We may use information to:

  • provide, operate, maintain, and improve the Services;
  • verify customer email addresses;
  • create and manage customer entitlements;
  • activate and authorize software installations;
  • enforce subscription and installation limits;
  • process documents at the customer’s direction;
  • calculate included, prepaid, and overage page usage;
  • create and reconcile billing records;
  • prevent duplicate charges;
  • process payments, refunds, disputes, and cancellations;
  • provide customer support;
  • diagnose errors and restore interrupted processing;
  • protect the security and integrity of the Services;
  • prevent fraud, abuse, circumvention, or unauthorized use;
  • investigate violations of our agreements;
  • comply with legal obligations;
  • establish, exercise, or defend legal claims;
  • communicate changes to the Services, policies, or account status;
  • develop and evaluate product improvements using information that does not unnecessarily identify the contents of customer matters.

We may use aggregated or de-identified information for operations, security, product analysis, and business planning when that information cannot reasonably be used by Featherlily to identify an individual.

3. How We Disclose Information

We may disclose information in the following circumstances.

A. Service Providers

We use service providers to operate portions of the Services. Depending on the customer’s use of GoodOrder, these providers may include companies that provide:

  • payment processing and subscription management;
  • cloud hosting and application infrastructure;
  • transactional email delivery;
  • optical character recognition and document analysis;
  • artificial-intelligence processing;
  • logging, security, and technical support.

Current material providers may include Stripe, Render, Postmark, Microsoft Azure, and OpenAI.

These providers process information to perform services for Featherlily, subject to their agreements with Featherlily and applicable law. They may also retain or disclose information when independently required by law.

Customer Content transmitted to a service provider may be processed in locations and systems controlled by that provider.

B. GoodOrder Provider Details

Featherlily processing. Document content passes through Featherlily infrastructure when needed to provide GoodOrder’s processing service. Featherlily does not use customer document content for model training or model improvement.

Microsoft Azure Document Intelligence. GoodOrder sends document content to Azure Document Intelligence for optical character recognition and document reading. Microsoft states that customer content submitted to Document Intelligence is not used to train its Document Intelligence models. Featherlily has not configured an additional Azure Monitor diagnostic export for the GoodOrder Document Intelligence resource. This does not mean Azure has zero retention; Microsoft documents temporary service storage and other provider-controlled practices in its Document Intelligence data, privacy, and security documentation.

OpenAI. GoodOrder may send document-derived text and page images to OpenAI for supported Bates-reading and duplicate-review functions. Featherlily does not permit this customer content to be shared with OpenAI for model training or model improvement. At the Featherlily organization level, model-feedback sharing, evaluation and fine-tuning data sharing, API input/output sharing, and API call logging are disabled. These controls reduce unnecessary sharing and logging, but they do not establish zero retention. OpenAI’s Responses API may still keep request and response data under its endpoint rules, and OpenAI may retain limited information for security, abuse prevention, legal, operational, or feature-related purposes. See OpenAI’s API data controls.

Stripe. Stripe receives account, subscription, billing, payment, invoice, and usage information needed to provide subscription checkout and payment processing. Litigation documents are not sent to Stripe. Complete card numbers entered through Stripe Checkout are not directly received or stored by Featherlily.

Microsoft Store. Microsoft Store distributes, installs, and updates the GoodOrder Deduplication Engine Windows app. Case documents are not sent to Microsoft Store as part of GoodOrder’s document-processing pipeline.

C. Customer-Directed Disclosures

We may disclose information when a customer directs, authorizes, or causes the disclosure, including when a customer submits documents for third-party processing through GoodOrder.

D. Legal and Safety Reasons

We may preserve, access, or disclose information when we reasonably believe doing so is necessary to:

  • comply with applicable law, regulation, subpoena, court order, or legal process;
  • respond to lawful requests from government authorities;
  • protect the rights, property, or safety of Featherlily, our customers, data subjects, or others;
  • detect, prevent, or investigate fraud, abuse, security incidents, or unlawful conduct;
  • enforce our agreements;
  • establish, exercise, or defend legal claims.

Where legally permitted and reasonably practicable, Featherlily may notify the affected customer before disclosing Customer Content in response to compulsory legal process.

E. Business Transactions

Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction.

Any successor receiving personal information will remain subject to this Privacy Policy unless and until the policy is lawfully changed.

F. Professional Advisers

We may disclose information to attorneys, accountants, insurers, auditors, consultants, and other professional advisers when reasonably necessary for legitimate business, legal, security, or compliance purposes.

G. With Consent

We may disclose information for another purpose with the customer’s or affected individual’s authorization.

4. We Do Not Sell Personal Information

Featherlily does not sell Customer Content or personal information for money.

Featherlily does not share personal information for cross-context behavioral advertising or use Customer Content to create advertising audiences.

If Featherlily’s practices materially change, we will update this Privacy Policy and provide any choices required by applicable law.

5. Customer Responsibilities

GoodOrder is intended for use by legal professionals and other authorized business users.

Customers are responsible for:

  • ensuring they have lawful authority to upload and process Customer Content;
  • providing any notices and obtaining any permissions required from clients, employees, witnesses, patients, opposing parties, or other data subjects;
  • complying with applicable privacy, confidentiality, privilege, professional-responsibility, protective-order, contractual, and data-security obligations;
  • determining whether GoodOrder is appropriate for a particular matter or category of information;
  • maintaining secure computers, networks, email accounts, and login credentials;
  • controlling who can access locally stored documents and outputs;
  • securely deleting local Customer Content when it is no longer needed;
  • preserving original files and maintaining appropriate backups;
  • reviewing GoodOrder’s results before relying on them or removing documents from a production, review set, or case file.

GoodOrder’s availability does not by itself establish compliance with HIPAA, the Gramm-Leach-Bliley Act, state medical-privacy laws, court protective orders, legal-ethics rules, client requirements, or other specialized obligations.

Customers should not submit information to GoodOrder when doing so would violate an applicable law, court order, contract, ethical duty, or client instruction.

6. Confidentiality, Privilege, and Legal Materials

Customer Content may include attorney-client communications, attorney work product, protected health information, personally identifiable information, or material subject to a confidentiality agreement or protective order.

Featherlily treats Customer Content as customer confidential information. However:

  • Featherlily is not the customer’s attorney;
  • use of GoodOrder does not create an attorney-client relationship with Featherlily;
  • Featherlily does not determine whether privilege applies;
  • Featherlily does not guarantee that uploading information to any technology provider will preserve privilege or satisfy a customer’s professional duties;
  • customers remain responsible for evaluating providers and obtaining any necessary client, firm, court, insurer, or contractual approval.

7. Artificial Intelligence and Automated Processing

GoodOrder uses deterministic and artificial-intelligence-assisted methods to process documents.

Customer Content may be transmitted to artificial-intelligence or document-processing providers to perform specific operations requested through the Services.

Featherlily does not make decisions concerning a person’s employment, credit, housing, insurance, medical treatment, legal rights, eligibility for public benefits, or similar significant matters based solely on GoodOrder’s automated processing.

GoodOrder may produce inaccurate, incomplete, or uncertain results. Customers must review all results before relying on them.

Additional operational limitations are described in the GoodOrder Beta and Mandatory Review Notice and the applicable Terms of Service.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain billing and entitlement records, comply with law, resolve disputes, prevent fraud, and enforce our agreements.

Retention varies by category.

A. Customer Content

GoodOrder is designed so that the primary run workspace, source documents, intermediate artifacts, and outputs remain on the customer’s computer.

Featherlily infrastructure may process or temporarily handle Customer Content while a request is being completed, retried, or reconciled. We do not promise that all temporary, cached, backup, security, or provider-held copies are deleted immediately after each request.

Third-party providers may retain information according to their service configuration, contracts, security requirements, legal obligations, and retention practices.

B. Account, Billing, and Usage Records

We may retain account, subscription, usage, payment-status, invoice, refund, dispute, installation, and entitlement records for as long as reasonably necessary to:

  • provide paid-through access;
  • administer subscriptions;
  • maintain accurate business and tax records;
  • investigate billing questions;
  • prevent duplicate charges;
  • resolve disputes;
  • comply with legal obligations.

C. Verification and Security Records

We may retain verification, activation, rate-limiting, fraud-prevention, security, and access records for as long as reasonably necessary to secure the Services and demonstrate account activity.

Raw verification and activation tokens are not intended to be stored in readable form by Featherlily after they are generated. Token-related records may be stored in hashed or otherwise protected form.

D. Support Records

We may retain support communications and associated materials for as long as reasonably necessary to respond to the request, identify recurring defects, protect the parties’ rights, and maintain business records.

E. Local Data

Local Customer Content remains on the customer’s computer until the customer or an authorized system administrator deletes it.

Featherlily ordinarily cannot remotely delete files stored only on a customer-controlled computer.

9. Security

Featherlily uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include:

  • encrypted network transmission;
  • token hashing;
  • short-lived and single-use verification links;
  • Windows Credential Manager storage;
  • installation authorization;
  • access controls;
  • signed webhook verification;
  • rate limiting;
  • billing idempotency controls;
  • logging and monitoring;
  • restricted access to production systems;
  • separation of customer software from provider credentials.

No method of transmission, storage, or processing is completely secure. Featherlily cannot guarantee absolute security or that a security incident will never occur.

Customers are responsible for maintaining appropriate endpoint security, operating-system updates, access controls, backups, and secure deletion practices.

10. Security Incidents

If Featherlily discovers a security incident involving personal information, we will investigate and take steps we determine appropriate under the circumstances.

We will provide notice to affected customers or individuals when required by applicable law.

Customers should promptly report suspected unauthorized access, credential exposure, fraudulent charges, or security vulnerabilities to:

hello@featherlilyproductions.com

Do not include confidential client documents, passwords, complete payment-card information, or other unnecessary sensitive information in the initial report.

11. Privacy Choices and Requests

Depending on applicable law and the circumstances, an individual may request that Featherlily:

  • confirm whether we maintain personal information about the individual;
  • provide access to certain personal information;
  • correct inaccurate personal information;
  • delete certain personal information;
  • provide information about categories of personal information collected or disclosed;
  • restrict or object to certain uses;
  • provide a portable copy of certain information;
  • review a decision concerning a privacy request.

To submit a privacy request, contact:

hello@featherlilyproductions.com

Please use the subject line:

Privacy Request

We may need to verify the requester’s identity and authority before completing a request. Verification may include confirming control of the email address associated with the account or requesting additional information reasonably necessary to prevent unauthorized disclosure.

An authorized agent may submit a request where permitted by law. We may require proof of the agent’s authority and direct verification from the affected individual.

Certain information may be exempt from access, correction, portability, or deletion requirements. For example, we may retain information necessary to complete a transaction, maintain billing and tax records, detect fraud, protect legal rights, comply with law, or preserve security records.

Submitting a privacy request will not result in unlawful discrimination.

Because much of GoodOrder’s Customer Content is stored only on the customer’s computer, Featherlily may not possess or be capable of retrieving that local information.

12. State Privacy Rights

Residents of certain U.S. states may have additional rights under applicable state privacy laws.

Whether a particular state law applies may depend on factors such as:

  • the individual’s state of residence;
  • the type of information involved;
  • the purpose of processing;
  • whether an exemption applies;
  • Featherlily’s size, revenue, or processing volume;
  • whether the information is processed in a business or employment context.

Featherlily will respond to verified requests as required by applicable law.

Where a right to appeal a denied privacy request applies, the response will explain how to submit an appeal.

13. Children’s Privacy

The Services are business software and are not directed to children under thirteen years of age.

Featherlily does not knowingly collect personal information directly from children under thirteen through account registration or marketing.

Customer documents may contain information concerning minors when a customer lawfully submits that information in connection with legal or business work. In that circumstance, Featherlily processes the information at the customer’s direction rather than collecting it directly from the minor.

A parent, guardian, or authorized customer who believes information concerning a child has been submitted improperly may contact us using the information below.

14. Geographic Scope

GoodOrder is currently offered only to customers located in the United States.

The Services are not presently directed to individuals or organizations located in the European Economic Area, United Kingdom, or Switzerland.

A document’s inclusion of information about a foreign national does not necessarily mean Featherlily has directed services to that person or jurisdiction. Customers remain responsible for determining whether their use of GoodOrder is permitted under any international privacy, confidentiality, professional-responsibility, or data-transfer requirements applicable to their matters.

Customers must not use GoodOrder in a manner that would cause Featherlily to violate a law applicable to Featherlily.

Before intentionally offering the Services in additional countries or regions, Featherlily may adopt supplemental notices, contractual terms, transfer mechanisms, or other compliance measures.

15. Third-Party Websites and Services

The Services may link to or integrate with third-party websites and services, including payment portals and service-provider interfaces.

Featherlily does not control the independent privacy practices of third parties. Customers should review the privacy notices and terms provided by those services.

This Privacy Policy governs Featherlily’s practices and does not replace the privacy policies of Stripe, Microsoft, OpenAI, Postmark, Render, or other independent providers.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Services;
  • new features or providers;
  • operational or security changes;
  • changes in law;
  • changes to our business practices.

The revised policy will state its effective date.

When a change is material, we may provide additional notice through the website, the application, email, or another reasonable method.

Continued use of the Services after an updated policy becomes effective is subject to the updated policy, except where applicable law requires additional notice or consent.

17. Contact Us

Questions, privacy requests, and security reports may be sent to:

Featherlily Productions LLC Email: hello@featherlilyproductions.com

For privacy requests, use the subject line:

Privacy Request

For security reports, use the subject line:

Security Report