Locked tight.
No fine print.
A year of receipts, leases, and scale tickets is no small thing to trust to an app. Here's exactly how endrow guards it — in plain English, no security-theater jargon.
Eight straight answers.
The questions a careful operator asks before trusting an app with the books — and what's actually true on each one.
Encrypted coming and going
Data sent between your device and endrow uses TLS 1.3. Data stored in our managed infrastructure is encrypted at rest. Access to production systems is limited to the operations needed to run the product and handle account requests.
Your records aren't a product we sell
Identifiable farm information is not sold or shared with advertisers. It may be shared when you approve access or when service providers are needed to run endrow or answer your request, such as hosting, storage, email, and the AI services used inside the app. If you opt into the Regional Benchmark Network, endrow uses de-identified, aggregated observations that are designed not to include names, user IDs, or direct farm identifiers.
Nobody sees the farm you didn't hand them
In normal product use, people only see the parts of the farm you authorize them to see. When you add family members or partners, you control what they can access, and any support access should stay limited to the minimum needed to help you. Regional benchmark views show aggregated readouts, not another farm’s full records.
On American soil
Your data is hosted in the United States through Supabase on AWS infrastructure. Supabase publishes SOC 2 Type II information for its service.
Your farm data isn't training anyone's model
When you use AI features, endrow sends the needed farm context to Anthropic and OpenAI API services so those features can answer your request. Those API workflows are configured not to use submitted farm data for model training.
Your tickets and leases stay your tickets and leases
Photos of elevator tickets, receipts, leases, and manuals are stored with the rest of your account data. Controlled server-side jobs read them to pull out the details that matter to your farm records. Those document-processing workflows are not used for model training.
Walk out with all of it — or none of it
You can request an export from Settings. If you delete your account, endrow starts the account-data removal flow right away. Some narrow billing, governance, security, and aggregate benchmark records may remain as described in our Privacy Policy.
No ad pixels riding shotgun
We do not currently use third-party advertising cookies, pixels, or analytics tags. Browser storage is limited to first-party essentials like login, invites, referrals, the signup path you intentionally chose, and campaign click IDs already present in an endrow signup URL.
One tap, and it's gone.
At any time, you can go to Settings and tap ‘Delete All My Data.’ That starts the account-data removal flow right away. There is an explicit confirmation step, and the remaining exceptions are described in the Privacy Policy.
Want to see what's stored before you decide anything? Pull a full export from Settings first — then keep it, leave, or both.
We'd rather hear it from you first.
Spotted something that looks off, or just want a real answer to a security question? A human reads every one of these.