This Privacy Policy explains how MagicIntake collects, uses, and protects your information when you use our service. We've tried to write this in plain language. If anything is unclear, email us at support@magicintake.com.
1 · Who we are
MagicIntake is an AI-powered document intake platform operated by Del Pino Care LLC d/b/a MagicIntake ("MagicIntake," "we," "us," or "our"), a Florida limited liability company. We provide software that businesses use to collect, classify, and manage required documents from their staff, clients, and contractors.
This Privacy Policy applies to:
- Account holders — businesses or individuals who sign up for MagicIntake to collect documents.
- Recipients — people who receive a magic-link invitation from an account holder to upload documents.
- Visitors — anyone who visits magicintake.com without signing up.
2 · What we collect
Information you provide directly
- Account information: name, email address, password, and (for paid plans) billing information processed by Stripe.
- Workspace information: business name, branding (colors, logo), team structure, document templates you create.
- Phone number (optional): collected only if you explicitly opt in to SMS notifications. See Section 6.
- Documents: files you or your recipients upload through the service.
- Communications: messages you send to us, support requests, feedback.
Information we collect automatically
- Usage data: pages visited, features used, time spent in the app, errors encountered.
- Device data: browser type, operating system, IP address, approximate location derived from IP.
- Cookies and similar technologies: session cookies for authentication and basic analytics. We do not use third-party advertising cookies.
Information from third parties
- Payment information from Stripe — we receive transaction confirmations and partial card details (last 4 digits), but never your full card number.
- Authentication information if you sign in via a third-party identity provider (when supported).
3 · How we use your data
We use your information to:
- Provide, maintain, and improve the MagicIntake service.
- Process your documents through our AI classification system.
- Send service-related emails (account verification, document status updates, billing receipts).
- Send SMS notifications, but only if you have explicitly opted in.
- Process payments and prevent fraud.
- Respond to your support requests.
- Comply with legal obligations and enforce our Terms of Service.
- Analyze usage patterns to improve product and detect security issues.
We do not use your data to train third-party AI models. We do not sell your personal information to anyone.
4 · Documents and AI processing
When you or your recipients upload documents, our service automatically:
- Stores the file in encrypted cloud storage (Supabase Storage).
- Sends the file content to an AI classification system to identify the document type (e.g., "Driver's License," "CPR Certification").
- Records metadata such as upload time, file size, and detected document type.
The AI processing is performed by trusted subprocessors (currently OpenAI and Anthropic) under contractual obligations not to retain your data for model training. Document content is sent for classification only and is not used to train AI models.
6 · SMS notifications
We send SMS messages only to recipients who have explicitly opted in by:
- Checking an unchecked consent checkbox in the document portal, AND
- Providing their phone number on the same form.
SMS messages are strictly transactional and limited to:
- Document status updates (approved, rejected, missing).
- Credential expiration reminders.
- Required document reminders.
You can opt out at any time by replying STOP to any MagicIntake SMS, toggling SMS off in your account settings, or emailing support@magicintake.com. Message and data rates may apply. See our SMS opt-in page for full details.
7 · Health information (PHI)
If you are a customer in healthcare, behavioral health, mental health, or any other field that handles Protected Health Information ("PHI") as defined by the U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA), you should not upload PHI to MagicIntake without your own compliance arrangement.
Specifically:
- You must not upload patient medical records, diagnoses, treatment notes, or other PHI to MagicIntake.
- Documents containing routine staff credentials (CPR certifications, state licenses, background checks, I-9 forms) are generally acceptable.
- If you are uncertain whether a document contains PHI, do not upload it without consulting your own privacy officer or counsel.
- You, as the customer, are solely responsible for ensuring that your use of MagicIntake complies with HIPAA and all other applicable laws.
We may, in the future, offer a HIPAA-compliant tier with a signed BAA. Contact support@magicintake.com to discuss your needs.
8 · Data retention and deletion
We keep your information for as long as your account is active or as needed to provide the service. After account closure:
- Active account data is deleted within 30 days of account closure or written request.
- Backup copies are deleted within 90 days through our normal backup rotation.
- Some information may be retained longer when required by law (e.g., billing records for tax purposes, generally 7 years).
- Anonymized usage statistics may be retained indefinitely to improve the service.
To request deletion of your account or specific documents, email support@magicintake.com. We will honor verified requests within 30 days.
9 · Security
We protect your data with reasonable and industry-standard security measures, including:
- Encryption in transit (TLS 1.2 or higher) for all communications.
- Encryption at rest for stored documents and database content.
- Role-based access controls within our infrastructure.
- Daily automated database backups with point-in-time recovery.
- Regular security review of subprocessors.
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you within the timeframes required by applicable law (typically 72 hours for incidents requiring notification).
10 · Your rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information (subject to limited legal exceptions).
- Export your data in a portable format.
- Opt out of certain data uses, including SMS.
- Object to certain processing.
California residents have additional rights under the California Consumer Privacy Act (CCPA). EU/UK residents have rights under GDPR. To exercise any of these rights, email support@magicintake.com with the subject line "Privacy Request." We will verify your identity before responding.
We do not discriminate against you for exercising any of these rights.
11 · International users
MagicIntake is operated from the United States. If you access the service from outside the U.S., your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
By using the service, you consent to this transfer. We do not currently market the service in regions where this is not permitted.
12 · Children's privacy
MagicIntake is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at support@magicintake.com and we will promptly delete it.
Note that account holders may use MagicIntake to collect documents about their clients' minor children (for example, in pediatric therapy contexts). In such cases, the parent/guardian is the account-facing user, and the responsibility for verifying age and obtaining appropriate consents rests with the account holder.
13 · Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify account holders by email if the change is significant.
- Where required by law, request renewed consent.
Continued use of the service after a change indicates acceptance of the updated policy.
14 · Contact us
For privacy questions, requests, or concerns:
- Email: support@magicintake.com
- Mail: Del Pino Care LLC d/b/a MagicIntake, 407 Lincoln Rd, Suite 6H, Miami Beach, FL 33139, United States
We aim to respond to all privacy requests within 7 business days, and to fulfill verified data requests within 30 days.