Draft — not reviewed by a lawyer
This is a starting point written to match what the software actually does. It is not legal advice and is not fit to publish as-is. Have a qualified lawyer in your jurisdiction review it, fill in every [[ PLACEHOLDER ]], then delete app/legal/draft-notice.tsx and its imports.
Privacy Policy
Last updated: [[ EFFECTIVE DATE ]]. This describes how [[ LEGAL ENTITY NAME ]] handles data in ContractLens. It is written to match what the software actually does — if you change the code, change this.
What we collect
- Account details — your email address and name, from Clerk when you sign up.
- Documents you submit — the contract text you paste, or the file you upload. Text is extracted from PDFs and DOCX files. If a PDF has no text layer, the file itself is sent to our AI provider so it can be read visually.
- Analysis results — the risk score, flagged clauses, summary, and suggested terms produced for each document.
- Usage records — timestamps, document size, page count, which model ran, token counts, and estimated cost. These drive quota and billing.
- Payment records — held by Stripe. We store only your Stripe customer and subscription identifiers, plan, status, and billing period. We never see or store card numbers.
Who else processes it
- [[ Anthropic or OpenAI — name whichever you deploy with ]] — receives your document text (or the PDF) to produce the analysis.
- Clerk — authentication and account management.
- Stripe — payments and subscription management.
- [[ DATABASE HOST ]] — stores everything described above.
- [[ HOSTING PROVIDER ]] — runs the application.
- Upstash — rate limiting. Stores a hashed request key and a counter; no document content.
[[ Confirm each provider's data-processing terms and the regions data is stored in, and list any onward transfers. If you serve EU or UK customers you will need a lawful transfer mechanism for any provider outside that area. ]]
Training
Your documents are not used to train our models or, under our provider agreements, our AI provider's models. [[ Verify this against your current provider plan and link to their policy. ]]
How long we keep it
Reviews are kept until you delete them. When you delete a review, the contract text, file name, and analysis are erased immediately; a record that a review was performed remains, with no document content in it, so that quota cannot be reset by deleting history.
Account and billing records are kept for as long as your account exists, and afterwards only as long as required for tax and accounting purposes. [[ State the retention period your jurisdiction requires. ]]
Your rights
Depending on where you live you may have the right to access, correct, export, or erase your personal data, to object to or restrict processing, and to complain to a regulator. To exercise any of these, contact [[ SUPPORT EMAIL ]].
[[ Detail the specific regimes that apply to you — GDPR/UK GDPR, CCPA, or others — including your lawful basis for each processing purpose, and response deadlines. Counsel to advise. ]]
Security
Traffic is encrypted in transit. Access to review data is scoped to the account that created it. Passwords are handled entirely by Clerk and never reach our servers.
No system is perfectly secure. Consider whether a contract is too sensitive to upload to any third-party service before you upload it.
Cookies
We use the cookies Clerk needs to keep you signed in, and Stripe's cookies during checkout. [[ If you add analytics or advertising, list them here and implement a consent banner where required. ]]
Contact
[[ SUPPORT EMAIL ]] · [[ REGISTERED BUSINESS ADDRESS ]]