Privacy policy
What we collect
- Account details — email address, first and last name, and an optional phone number, used to identify you and secure your account.
- Agreements you upload— the original file (where file storage is configured; otherwise the PDF is read in memory and not kept), the text extracted from it, and the analysis we generate. Be aware that both the text and the analysis contain personal data about people other than you: the analysis records the landlord’s, tenant’s and broker’s names and the property address, and quotes clauses verbatim. Those people have not signed up here and cannot exercise rights over it through this site — if one of them asks us to remove their details, use the contact form and we will handle it by hand.
- Q&A chat messages — the questions you ask about an agreement and the replies, so the conversation persists.
- Product telemetry — coarse events such as sign-up, upload, and share-link creation, used to operate and improve the service. Controlled by the
ENABLE_TELEMETRYsetting.
Where your agreement goes
Two parts of an uploaded agreement leave our systems, and they leave separately. Both involve a transfer outside India.
- The document file is placed in private object storage run by Cloudflare (R2). The bucket has no public address and no public hostname: there is no link that serves the file to anyone, and the only way to retrieve it is through this site, after we have checked that the account asking for it is the account that uploaded it.
- The document text is sent to an AI provider, which is how the clause analysis and chat answers are produced. This is the transfer most people do not expect, so to be plain about it: the words of your agreement are read by a model run by another company, outside India, at the moment you request an analysis.
Who else handles your data
Named, because “our processors” is not a disclosure. These are the companies that hold or see your data today:
- Google— the Gemini API, which performs the clause analysis and answers chat questions. Your agreement’s text is processed on Google’s infrastructure outside India. We record which provider and model processed each agreement, so that question is answerable later for any specific document.
- Cloudflare— sits in front of this entire site and terminates TLS at its edge, which means every request, including the upload of your agreement, is decrypted on Cloudflare’s network before it reaches our server. It also stores the document files (R2) and holds our nightly database backups, which are encrypted on our own server before they are sent, so that copy is ciphertext to Cloudflare.
- The database host.Your account, your agreements’ extracted text, the analyses and your chat history live in a Postgres database. Where that database runs depends on the deployment: this service is moving from a managed Postgres provider to an instance on our own server, reachable only from that machine. If you need to know which applies on the day you are reading this, ask through the contact form and we will tell you.
- Email.No third-party email vendor holds your messages, and none can: there is no such transport in this service’s code, so sign-in and account mail can only ever go through a mail server we run ourselves. Until this service is deployed on that infrastructure, no mail is sent at all — messages are recorded and held rather than delivered. Either way, only your email address and the message itself are involved; agreement text is never emailed.
Authentication is deliberately not on that list: sign-in identities, password hashes and two-factor secrets are kept in our own database rather than with a third-party identity provider, so signing in does not disclose you to anyone else.
If you request a lawyer referral, we share the contact and preference details you submit with the matched professionals — that one is a transfer to a person, not a system, and it only happens when you ask for it.
What the AI provider may do with your text
This is the part we would rather be able to write differently, so it is stated plainly. We do not currently have a zero-retention or no-training agreement in place for the AI provider.The Gemini API tier this deployment uses does not carry such a commitment, and Google’s terms for it permit prompts to be retained and used to improve their products, including review by human reviewers. Your agreement’s text is sent under those terms.
What we do today is narrower, and real: we send less. Redaction (below) is on by default, so the direct identifiers we can recognise are replaced before the text leaves; and we record which provider and model saw each document, so the question of what went where is answerable per document rather than in general.
Planned, not current: moving to a paid enterprise binding (Vertex AI or equivalent) under a data-processing agreement with no-training and retention terms, so that the paragraph above can say something better. The system already records a zero-retention flag against each configured provider, but that flag is presently only recorded and displayed to our administrators — it does not yet gate or alter any request. Until that changes, treat this page as saying there is no such protection, because there is not.
What limits those transfers
- The storage bucket is private, with no public hostname and no pre-signed links. Documents are served only through an ownership-checked request.
- Analysis is about clauses, not people, so we replace direct identifiers before the text is sent and put them back in what you are shown. This is on by default. It covers Aadhaar and PAN numbers, Indian mobile and landline numbers, email addresses, UPI IDs, bank account numbers, IFSC and GSTIN codes, and driving licence numbers. It does not cover names or the property address — there is no reliable way to detect an Indian personal name without also deleting clause text, and a wrong analysis would be its own harm — so the provider still receives a document from which you could be identified. This reduces what is transmitted; it is not anonymisation and we do not treat the result as anonymous.
- Where we route through an aggregator rather than calling a model directly, we pin the list of downstream providers permitted to serve a request and disable silent fallback to unlisted ones, so the set of companies that can see your text is a list we choose rather than whoever is cheapest at that moment. This applies to that routing path only; the direct Google binding described above does not involve it.
- Which provider processes documents is a setting, not something written into the software. If the law changes about where this data may be sent, we can move analysis to a different provider — including one operating in India — as a configuration change rather than a rewrite.
Your rights
You can export everything we hold about you, and request erasure, from your account page. Erasure is partial today, and it is worth knowing which part is which before you rely on it.
Actually deleted.The uploaded document files are deleted from object storage. Your sign-in credentials, password hash and any two-factor secrets are deleted. Your Q&A chat history is deleted, as are any questions submitted for a lawyer referral. Live share links stop working immediately. Product-telemetry rows are unlinked from you and kept only as anonymous counts.
Retained after erasure.Your account row and your agreements are marked deleted rather than removed. That means your email address and name, the extracted text of every agreement you uploaded, and the analyses generated from them — which include the landlord’s, tenant’s and broker’s names and the property address — remain in our database. Nothing serves them: signing in is refused, and every route that reads an agreement checks ownership and the deleted marker first. But unreachable is not erased, and we would rather say so than imply otherwise. Payment records — amount, plan, status and the transaction reference — are also kept, because they are what lets a payment be reconciled and disputed afterwards; the free-text note you wrote alongside one is cleared, as are the preferences you gave for any lawyer referral.
Backups.Once this service runs on its own infrastructure, the database will be backed up nightly — encrypted on our server before the copy leaves it — and the last 30 days kept. No backup has been taken yet, because nothing is deployed. It is described here anyway, because of what it will mean for erasure: since erasure leaves the rows in place, a backup taken after your erasure will contain your data exactly as one taken before it does. The 30-day window will not age your data out, and it is honest to say a copy would persist for as long as the account row does. A previous version of this page said residual copies age out on the backup cycle; that was wrong, and it is the reason for the paragraph above.
Planned, not current: a hard delete that removes the account row and clears the stored document text and analysis, so that backups stop re-capturing an erased person and the sentence above can be shorter. If you need your data removed for real before that ships, ask us through the contact form and we will do it by hand.
Share links
Creating a share link publishes a read-only view of that analysis to anyone holding the link. It does not expose your email or other account details. Links remain live until revoked.
Privacy questions: use the contact form.
Last updated: 30 August 2026.