Privacy Policy
Effective Date: January 1, 2026 | Last Reviewed: March 2026
This privacy policy helps you understand what data ContractExtract collects and how it is used.
1. Introduction
This Privacy Policy describes how ContractExtract ("we," "us," or "our") collects, uses, and protects your information when you use our website and services. By using ContractExtract, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Documents you upload for analysis (contracts, agreements, etc.)
- Payment information processed through our third-party payment provider (Stripe)
- Any communications you send to us
2.2 Information Collected Automatically
- Usage data (pages visited, features used, time spent)
- Device information (browser type, operating system)
- IP address and approximate location
- Cookies and similar tracking technologies
3. How We Use Your Information
- To provide and improve our contract analysis service
- To process payments and manage your account
- To communicate with you about your account or our services
- To ensure the security and integrity of our platform
- To comply with legal obligations
4. Document Handling and AI Processing
We are committed to full transparency about how your uploaded documents are handled. Please read this section carefully.
Summary: Documents you upload are sent to Anthropic's Claude AI for analysis. We do not store your documents. Anthropic does not use API data for model training.
4.1 How Documents Are Processed
When you upload a contract or document for analysis, the content of that document is transmitted to Anthropic's Claude API for AI-powered analysis. This is the core mechanism that powers our service. Without sending the document to Claude, we cannot generate an analysis.
4.2 Anthropic Does Not Use API Data for Training
Anthropic does not use data submitted through its API to train its AI models. Documents you submit via ContractExtract are processed by Anthropic under their API usage policies, which explicitly exclude API inputs and outputs from model training. You can review Anthropic's privacy commitments at anthropic.com/privacy.
4.3 We Do Not Store Your Documents
We do not store your uploaded documents on our servers. Documents are processed in real-time: they are sent to Claude's API, the analysis result is returned to your browser, and no copy of your document is retained by us after processing is complete. Analysis results are stored temporarily in your browser's session storage and are never sent to or retained on our servers.
4.4 Encrypted Transmission
All data — including your uploaded documents — is transmitted exclusively over encrypted HTTPS connections. Data in transit between your browser and our servers, and between our servers and Anthropic's API, is protected by TLS encryption. We do not transmit document content over unencrypted connections under any circumstances.
5. Third-Party Services
We use the following third-party services:
- Anthropic (Claude AI) — Document content is sent to Anthropic's API for AI analysis. Anthropic does not use API data for model training. See Anthropic's Privacy Policy.
- Stripe — for secure payment processing. Stripe's privacy policy governs payment data handling. We never see or store your full payment card details.
- Vercel — for hosting and infrastructure. Vercel may process request logs including IP addresses per their privacy policy.
- Google (AdSense) — for displaying advertisements on marketing and informational pages. Google may collect and process data including cookies, device identifiers, and browsing behavior for ad personalization. See Google's Privacy Policy.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including TLS encryption for all data in transit, access controls on our infrastructure, and serverless architecture that minimizes data retention. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
Because we do not store your uploaded documents or analysis results on our servers, there is no retained document data for us to delete or provide upon request.
8. Cookies and Advertising
We use essential cookies and localStorage to maintain your session preferences (such as free-tier usage tracking). We may also use analytics cookies to understand how our service is used. You can control cookie settings through your browser preferences.
We work with third-party advertising partners, including Google, who may use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads based on your visit to this site and/or other sites on the Internet.
You may opt out of personalized advertising by visiting Google Ad Settings or optout.aboutads.info.
9. Children's Privacy
Our service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights regarding your personal information. These rights are effective as of January 1, 2026.
Information We Collect
In the past 12 months we have collected the following categories of personal information:
- Identifiers: IP address, email address (if account created), browser type, device identifiers.
- Internet or network activity: Pages visited, tool usage patterns, time on site.
- Document content: Contract text submitted for analysis. This data is processed server-side and deleted immediately after extraction is complete. It is never stored, logged, or shared.
- Inferred data: Interests inferred from browsing behavior via advertising partners (marketing pages only).
Sensitive Personal Information
As of January 1, 2026, California law defines an expanded category of sensitive personal information. Contracts you upload may contain sensitive personal information belonging to third parties (e.g., names, financial terms, health-related clauses). ContractExtract processes this data solely to perform the requested extraction and deletes it immediately upon completion. We do not store, analyze for our own purposes, sell, or share contract content. We collect only what is necessary to provide the service.
Data Minimization
We collect only the minimum personal information necessary to operate this service. Contract documents are processed in memory and deleted immediately after extraction. We do not retain document content beyond the active processing session.
How We Use Your Information
- To perform contract key-term extraction using AI processing
- To display advertising on marketing and informational pages through Google AdSense
- To analyze aggregate site traffic and improve service quality via analytics
- To maintain site security, prevent fraud, and enforce rate limits
We do not sell your personal information. We do not use contract content for advertising targeting.
Your Rights as a California Resident
- Right to Know: Request disclosure of personal information collected in the past 12 months.
- Right to Delete: Request deletion of personal information. Note: contract documents are deleted automatically upon processing completion.
- Right to Correct: Request correction of inaccurate personal information such as account details.
- Right to Opt-Out: Opt out of sharing personal information for advertising. We honor Global Privacy Control (GPC) signals automatically.
- Right to Limit Use of Sensitive Information: Direct us to limit use of sensitive personal information to necessary service functions.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
Do Not Sell or Share My Personal Information
We do not sell personal information. To opt out of sharing for advertising purposes, use a Global Privacy Control (GPC)-enabled browser, or contact us via the Contact page.
How to Submit a Request
Contact us via the Contact page. We will respond within 45 days. Identity verification may be required.
Data Retention
Account data is retained until account deletion. Analytics data is retained for 26 months. Contract documents are deleted immediately after processing. Server logs are retained for 90 days.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us through our website.