Privacy Policy

Effective date: September 3, 2026  ·  Last updated: September 24, 2026

Our commitment in plain language

We do not sell your data. We never will. Here is exactly what we do with your engagement files.

1

Your files stay within AWS in the United States: stored in our own account and processed only by AWS services under our agreement with AWS. No other company receives them.

2

Your documents cannot be used to train any AI model, whether by us or by our technology provider. This is a contractual guarantee, not a configuration option.

3

Delete any engagement from your dashboard whenever you want. If you ran a review before creating an account, write to us and we will delete those files, no account needed.

4

Only you can reach your submissions from outside PeerReviewReady. Our team opens one to fix a problem and improve the review, never to share, market, or train a model, and that access is logged.

1. Who we are

PeerReviewReady is operated by PeerReviewReady LLC ("we," "us"), a Florida limited liability company at 2204 NW 62nd Drive, Boca Raton, FL 33496. It is a web application that helps CPA firms review their compilation and review engagement files against AICPA standards before peer review.

Service availability. We offer the Service only to users in the United States. We do not direct it to the European Economic Area, the United Kingdom, or anywhere else outside the United States, and we do not knowingly collect personal information from users outside it.

2. What we collect

Account information

Your email address, used to sign you in and manage your account. We do not collect card details ourselves. Stripe handles those.

Engagement documents

The PDF, Word, and Excel files you upload for an engagement. They may hold client financial information, engagement letters, and workpapers. Section 4 covers how we handle them.

Intake answers

Engagement type, financial reporting framework, period end date, report date, and a client identifier you choose.

Your responses

What you type when you clear a finding. Stored with the engagement and deleted with it.

Feedback votes

When you flag a finding as accurate or wrong, we record your vote with the document type, standards reference, confidence level, and engagement type. No document content.

Product usage

Which pages and buttons you use, and where you came from, including the click identifier a search engine or advertising network adds to a link. If you reach us through a link in an email we sent you, that link carries a short code, so we know which email you came from. Never document content. We record these events in our own AWS account and send them to no one.

Usage logs

Standard server access logs: request timestamps, HTTP status codes, duration. No document content.

3. What we use it for

We use your information only to run the service:

  • Classify your documents and find the completeness gaps
  • Review document content against AICPA standards
  • Write up the pre-issuance review summary and the draft templates
  • Keep completed reports on your dashboard
  • Improve review accuracy from aggregate feedback vote patterns, never from individual document content
  • Improve review accuracy and speed from de-identified metadata: document types, standards cited, finding severity and disposition, processing times. Never your clients' information
  • Investigate and fix problems. Our team may open one submission, documents and findings included, for that purpose alone, and we log the access
  • Build test cases from the problems we investigate, always fictionalized with invented names, amounts, and details, so they hold nothing about you or your clients

We do not sell your data. We do not share your data with third parties for marketing purposes.

4. How your documents are handled

Your files are encrypted, processed only by AWS services in the United States under our agreement with AWS, and never used to train an AI model. We keep them until you delete them.

In more detail: your documents go into a private S3 bucket in our AWS account. Text extraction and the review itself run on AWS services in the United States; the review runs on AWS Bedrock, Amazon's own service, under our agreement with AWS, and Bedrock does not train on your files.

Your documents cannot be used to train, improve, or fine-tune any model, by us or by our technology provider. That is a contractual commitment, not a setting. No other company receives them, no outside model provider ever sees them, and we share document content for no purpose at all: not marketing, not training, not resale.

This is the section a CPA forwards to a peer reviewer. Section 8 covers the professional-responsibility side of it.

5. How long we keep things, and how to delete them

Short version: your files stay available while your account is active, so you can come back to any engagement. Nothing is deleted on a timer. Delete any engagement from your dashboard whenever you want, and close your account and everything goes within 30 days.

Data typeRetention periodDeletion method
Raw engagement documentsWhile your account is activeDelete the engagement from your dashboard; everything goes within 30 days of closing your account
Extracted document textWhile your account is activeDeleted with the raw documents
Review results (findings, citations, your responses)As long as you keep the engagementDeleted with the engagement, including your response to each finding. Holds short evidence excerpts (300 characters or less per finding), never full documents
Feedback votesLife of your accountMetadata only, no document content. Deleted within 30 days of an account deletion request
Files you upload before you have an accountUntil you ask us to delete themWrite to us and we will remove everything. You do not need to create an account first
Account informationUntil you close your accountWrite to us to close it

You can run a review without signing up, and those files are kept on the same terms as everyone else's. The one thing you cannot do without an account is delete them yourself, so write to us at the address below and we will remove everything.

One exception to the schedule. If we are investigating a problem with a submission, at your request or under the quality review in Section 3, and you delete it or close your account while that is open, we may keep that submission's documents until the investigation is resolved. Then we delete them.

6. How we protect it

  • Encrypted in transit and at rest. All data is protected with industry-standard encryption, both while it travels over the internet and while it sits on our servers.
  • Passwords never stored by us. A dedicated identity service handles authentication. PeerReviewReady never holds your password.
  • Access control. Once you have an account, every request confirms that the engagement is yours before returning anything. You cannot reach another firm's files, and they cannot reach yours. Before you have an account, a review is reachable only from the browser session that started it. Within PeerReviewReady, we open a submission only for the purposes in Section 3, and we log that access.
  • Access is logged. Infrastructure-level access to your engagement files is logged via AWS CloudTrail.
  • United States infrastructure. PeerReviewReady runs entirely on AWS within the United States. All data stays domestic.

7. Cookies and local storage

We set no advertising cookies and run no third-party tracker, which is why you never see a cookie banner here.

We do use your browser's own storage to keep the product working across page loads: your sign-in session, an identifier for a review you started before creating an account, a draft of your intake answers so a refresh does not lose them, your display name and firm defaults, and the identifiers behind the usage events in Section 2. One cookie goes with it, a signed value that ties a pre-account review to the browser that started it so nobody else can claim your upload.

Only this site can read any of it, and clearing your browser data clears it. Clear it while a pre-account review is open and you lose the link back to that review, so finish or claim the review first.

8. Your professional responsibility

PeerReviewReady is a software tool. It does not create a CPA-client relationship and does not constitute professional services. Findings come out of an automated review and must be read by a licensed CPA before you act on them.

Your files are encrypted, processed only by AWS services in the United States under our agreement with AWS, and never used to train an AI model. We keep them until you delete them. We send document content to no other company. AICPA ET §1.700.040 ("Disclosing Information to a Third-Party Service Provider") puts the responsibility for reviewing a service provider's practices on you, the CPA. This documentation exists to help you do that. You remain responsible for deciding whether automated review tools fit your engagement.

9. California privacy rights

This section applies to California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Categories we collect. Identifiers (email address), professional information (firm name and CPA name in your firm defaults), commercial information (subscription and billing records held by Stripe), and internet activity information (session identifiers and product usage events).

Sources. From you when you create an account, upload documents, or use the Service. From Stripe for subscription status. From AWS Cognito for authentication metadata.

Purposes. To run and improve the Service, sign you in, process subscriptions, answer support requests, and meet legal obligations.

We do not sell personal information. We do not sell personal information as defined by the CCPA, and we have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months. We report nothing about you to any advertising network.

Your rights. You have the right to (a) know what personal information we hold about you, (b) request its deletion, (c) request correction of anything inaccurate, (d) request portability, and (e) be free from retaliation for exercising these rights. Send your request to privacy@peerreviewready.com from the email address on file. We verify your identity and respond within 45 days.

Sensitive personal information. The Service does not intentionally collect sensitive personal information as defined by CPRA. Engagement documents you upload may hold sensitive information about your clients. That content is encrypted, never used to train AI, and deletable by you at any time.

10. Children, changes, and contact

Children under 18. PeerReviewReady is a professional tool for licensed CPAs and CPA firms. The Service is not directed to anyone under 18 and we do not knowingly collect personal information from children.

Changes to this policy. When a change reduces your rights, we will email you at least 14 days before it takes effect. When a change is in your favor, such as keeping your files longer instead of deleting them on a timer, we may make it immediately and tell you afterwards. Every revision is listed below with its date.

Contact. For questions about this policy, deletion requests, or privacy concerns, write to privacy@peerreviewready.com, or to PeerReviewReady LLC, 2204 NW 62nd Drive, Boca Raton, FL 33496.

PeerReviewReady LLC · 2204 NW 62nd Drive, Boca Raton, FL 33496 · Florida limited liability company