Privacy Policy
Last updated: May 1, 2026
The short version
- • Your contracts are deleted within 24 hours of upload, whether you view the report or not.
- • We do not use your contracts to train any AI model, ours or anyone else’s.
- • We collect your email only when you give it to us (waitlist or payment).
- • Files are encrypted in transit (HTTPS) and processed in memory.
- • We use sub-processors (Anthropic, Stripe, Upstash, Vercel) — listed below.
What we collect
Contract files. When you upload a PDF, we extract its text, store it temporarily so the report can be generated after payment, and delete it within 24 hours. We do not retain copies.
Payment information. Stripe handles all payment data. We never see or store your card number, CVC, or banking details. We receive only the Stripe session ID, payment status, and (if you provide it at checkout) your billing email.
Email addresses. If you sign up for our waitlist or contact us, we store the email address you provide so we can reply or notify you of launches.
Server logs. Vercel records standard request logs (IP address, user agent, response codes) for up to 30 days for security and debugging.
How we use it
We use the contract text only to generate your report — we send it to Anthropic’s Claude API to produce the plain-English summary, risk flags, and questions to ask. We instruct Anthropic not to use this data for training (Anthropic’s API policy already excludes API traffic from training by default).
We use email addresses only to communicate about the product you signed up for or asked about. We do not sell or share email addresses.
Retention
- • Contract text: 24 hours, then auto-deleted.
- • Analysis results: 24 hours, then auto-deleted. If you want to keep your report, save the page or PDF before it expires.
- • Payment records: retained by Stripe per their policy; we keep only the session ID and metadata for accounting.
- • Waitlist emails: retained until you ask us to remove them or until the waitlist is closed.
- • Server logs: 30 days.
Sub-processors
We use the following third-party services to run the product:
- • Vercel — hosting and serverless compute.
- • Anthropic — Claude API for contract analysis.
- • Stripe — payment processing.
- • Upstash — short-lived storage of contract text and analysis results.
Your rights
You can request deletion of any data we hold about you (waitlist email, payment records) by emailing hello@contractplainly.com. Contract text deletes itself within 24 hours so there’s nothing to request there.
Cookies
We don’t set tracking cookies. Stripe may set its own cookies during checkout (covered by their privacy policy).
Contact
Questions or concerns: hello@contractplainly.com.