Privacy Policy
Effective January 1, 2026. Last reviewed August 2, 2026.
This policy explains the data flow for ContractExtract. Read it before uploading a document that contains confidential or personal information.
Data the service processes
- Uploaded content: the file, file name, selected contract type, and generated report needed to perform the requested extraction.
- Service and security data: request path, status, IP address, user agent, timing, and limited security-event names processed by hosting and rate-limit systems.
- Entitlement data: a signed random token and month for free access. It does not contain contract content or an account profile.
- Communications: information a visitor chooses to send through the contact method.
- Optional analytics: only after consent, a sanitized page title and path without query parameters. Analytics is never loaded on upload or results routes.
Why the data is used
- To validate a supported upload and produce the requested report.
- To enforce monthly access, rate limits, and security controls.
- To operate, diagnose, and protect the service.
- To answer a communication the visitor initiates.
- To measure non-sensitive public-page use only when the visitor opts in.
Document handling and retention
ContractExtract processes uploads in server memory and does not intentionally write documents or generated reports to its own database. The report is returned to the browser and placed in session storage for the results page. Closing the browser tab normally ends that page session.
Uploaded content is sent to Anthropic's API to create the report. Anthropic currently states that standard API inputs and outputs are deleted from its backend within 30 days, with exceptions for different agreements or services, usage-policy enforcement, and legal obligations. See Anthropic's current API retention notice.
Hosting, security, and network providers may retain operational records under their own settings and policies. ContractExtract therefore does not promise immediate deletion or zero third-party processing.
Service providers
- Anthropic: processes document input and model output for the requested extraction.
- Vercel: hosts the application and processes network and runtime traffic.
- Upstash: supports pseudonymous rate limits and entitlement counters without document content.
- Google Analytics: receives sanitized public-page events only after explicit consent.
- Stripe: paid checkout is currently disabled. Stripe integrations may still process identifiers associated with previously created billing records; ContractExtract does not receive full card numbers.
Each provider processes data under its own terms. ContractExtract's current cookie behavior is described in the Cookie Policy.
Analytics, advertising, and privacy choices
Google Analytics is blocked until a visitor explicitly allows it. Advertising storage, ad personalization, Google Signals, and enhanced measurement are disabled. A Global Privacy Control signal keeps optional analytics off. Withdrawing consent persists a denial on the device, removes the analytics script, and attempts to clear its cookies.
ContractExtract does not sell personal information, use contract content for targeted advertising, or currently load an AdSense advertising script. Publisher ownership metadata may remain present for site verification, but ads are not served.
Payments
ContractExtract does not currently initiate paid checkout and is not accepting payment on this site. If paid access is introduced later, this policy and the published terms must be updated before checkout is enabled.
Security
Data is transmitted over HTTPS. The application limits accepted file types and sizes, validates DOCX archive structure before decompression, does not log contract content or model output, and applies restrictive headers to upload, results, and API routes. No internet service can guarantee absolute security.
Privacy requests
Depending on applicable law, a person may have rights to request access, correction, deletion, portability, or limits on certain processing. Submit a request through the Contact page. Identity verification may be required, and requests will be handled as required by applicable law.
Because ContractExtract does not intentionally maintain a database copy of uploaded documents or reports, it may not be possible to locate content after the request has ended. Service providers may hold limited records under their own retention rules.
Children
ContractExtract is not directed to children under 13 and does not intentionally collect personal information from children under 13.
Changes and contact
Material changes will be posted on this page with a revised review date. Questions or privacy requests can be submitted through the Contact page.