LLendForma
For SBA brokersFree PFSPricingResourcesSecurity
Sign inStart free

Privacy Policy

Effective August 15, 2026

LendForma is designed for sensitive financial information. This policy explains what we collect, why we use it, which service providers help operate LendForma, and the choices available to you.

Information you provide

When you create an account, financial statement, workspace, invitation or application package, you may provide names, email addresses, roles, contact and employment information, Social Security numbers, assets, liabilities, income, expenses, ownership, guarantor information, loan-request details, schedules, disclosures, signatures, checklist notes and source metadata. You decide which optional profile fields appear on a statement.

Guest use

You can draft a statement without signing in. Guest statement changes are held in the browser session and are not saved to a LendForma account. We may store a small browser preference indicating whether you selected a fresh or demonstration form.

Account and payment information

If you sign in, authentication information is handled through Google or passwordless email. LendForma stores the account identifier needed to associate you with your private statements. Stripe processes LendForma Complete subscriptions; LendForma does not receive or store full payment-card numbers.

How we use information

  • Provide, save, restore, customize, print and export statements and application packages.
  • Create broker workspaces, issue expiring invitations, enforce team roles and record attributable package activity.
  • Authenticate accounts, protect access and prevent abuse.
  • Process a LendForma Complete subscription and retain the corresponding account entitlement.
  • Respond to support, privacy and security requests.
  • Maintain, troubleshoot and improve LendForma without intentionally placing statement values in analytics or application logs.

Service providers

LendForma currently relies on Vercel for application hosting, Neon for managed PostgreSQL storage, Google and Auth.js for supported sign-in flows, Resend for magic-link and workspace invitation email, and Stripe for payment processing. When a user explicitly chooses an enabled AI intake or review feature, OpenAI processes the minimized content needed to provide that feature. These providers process limited information on our behalf under their own security and privacy terms. We do not sell your personal or financial information.

AI processing

Deterministic quick commands operate within LendForma. Conversational, extraction and readiness features require separate consent before AI processing. For a live interview, microphone audio is transmitted from the browser to OpenAI over an encrypted WebRTC connection. LendForma also sends the user’s typed or transcribed narrative and a minimized statement index containing section names, row names, current amounts and stable identifiers. The index excludes Social Security numbers, dates of birth, signatures, addresses, full account numbers, applicant names and row details. Obvious Social Security numbers, account-number patterns and full dates in typed or transcribed narratives are redacted before structured validation. Users should still avoid speaking or typing them.

LendForma does not store raw audio or transcripts by default. The browser holds the working transcript only for the active review, and LendForma stores approved changes plus operational metadata such as model, request identifier, latency, token use and status—never the prompt, transcript or financial values. OpenAI states that API content is not used to train its models by default, although abuse-monitoring logs may retain content for up to 30 days unless separate Modified Abuse Monitoring or Zero Data Retention controls apply.

Document intake

When document intake is enabled and a user explicitly submits a supported file, the full PDF or image is transmitted to OpenAI only to extract proposed facts. LendForma processes the upload in memory and does not add the source binary to a permanent document vault. The binary is discarded after processing, including on success, failure, cancellation or timeout. If the user approves extracted facts, LendForma may retain those facts, a sanitized source label and date, confidence information and a one-way file fingerprint for duplicate detection. “Document-backed” does not mean bank-verified.

Sharing, workspaces, and cases

The “Share LendForma” feature shares only the public website link and does not grant access to your statement. A workspace manager can create a time-limited invitation for a named email address and role. A broker can also invite a borrower, guarantor, or spouse to a specific case. LendForma stores only a hash of each invitation token, and acceptance requires a signed-in account with the invited email. Case participants can access only their assigned tasks and contributed information; they cannot view another participant’s PFS or the full broker package. Supporting-document uploads are not currently offered.

Security

LendForma uses HTTPS, authenticated owner- and workspace-scoped access, role checks, hashed expiring invitation tokens, request validation, rate limiting, attributable case events and application-layer encryption for stored Social Security numbers. Password-protected PDFs are created in your browser, and the PDF password is not saved by LendForma. No system can guarantee absolute security, so protect account access, invitation links, exports and document passwords.

Retention and your choices

Account data, saved statements, application packages, memberships, invitations and case activity are retained while needed to provide LendForma, meet legal or security obligations and resolve disputes. Archived statements remain recoverable from your account. Signed-in users can export account data and delete their account after cancelling an active subscription. Workspace content owned by another user may remain available to that workspace after a member deletes their account. To request access, correction, export or deletion, email hello@lendforma.com. Limited records may be retained when required by law, fraud prevention, payment reconciliation or backup cycles.

Cookies and local storage

LendForma uses session cookies and related browser storage required for sign-in, security and guest preferences. We do not currently use advertising cookies.

Children and changes

LendForma is intended for adults and is not directed to children under 18. We may update this policy as the service changes. Material changes will be posted here with a revised effective date.

Contact

Questions or privacy requests can be sent to hello@lendforma.com.

LLendForma

The submission-readiness workspace for SBA loan brokers, packagers, and their borrowers.

ExploreFor SBA brokersFree PFSCRE debt schedulesFinancial intakePricingResources
TrustSecurityPrivacyTermsContact
© 2026 LendFormaSoftware for packaging—not a lender or approval service.