Privacy Policy
Last updated: August 2026 — see our Security page for the technical controls behind these commitments.
1. Information We Collect
We collect information you provide when creating an account (name, email, password) and the contract data you submit for analysis — the extracted text of each document, plus the findings, risk scores, and AI explanations generated from it. We also automatically collect basic usage and acquisition data (IP address, user agent, referrer, and UTM parameters) so we can secure the service and understand how it's used. We do not collect payment card details — those go directly to Stripe.
2. Document Handling
The original file you upload (the PDF or DOCX bytes) is never written to disk or persisted — only the extracted text is stored, in our database, so you can revisit your analysis later. That stored text, along with the findings and AI explanations derived from it, is encrypted at rest with AES-256-GCM before it touches the database. We do not use object storage or any third-party file host for your documents.
3. How We Use Your Information
Account information is used to provide and maintain your TriageCounsel account, process payments, and communicate service updates. Contract data is used solely to generate and display your analysis and review history. Usage and acquisition data is used to secure the platform (rate limiting, abuse detection, audit logging) and to understand product usage — never to profile or advertise to you.
4. AI and Data Training
Your documents and analysis results are never used to train AI models — by us or, per OpenAI's standard API terms, by OpenAI. The LLM never receives your full contract text: this is enforced in code, not just policy. It receives only short, already-detected excerpts (capped at 300 characters, screened for prompt-injection attempts) needed to write a plain-language explanation of a finding our deterministic rule engine already made. The AI cannot create findings or change your risk score — those are computed entirely outside the AI.
5. Data Security
Contract text and the detailed analysis derived from it are encrypted at rest with AES-256-GCM, with support for key rotation. All data in transit is encrypted with TLS. Passwords are hashed with PBKDF2-HMAC-SHA256 and never stored in plaintext. You can enable optional two-factor authentication (TOTP) on your account. Every account, contract, and playbook query is scoped to your account, so other customers cannot reach your data through the application. Uploads, exports, deletions, shares, and admin access are all recorded in an append-only audit log. See our Security page for the full list of controls.
6. Data Retention and Deletion
Your contracts are retained while your account is active, unless you delete them sooner. You can permanently delete an individual contract — its text, findings, and share link — from your history page at any time; this is a hard deletion, not a soft flag. Deleting your account permanently deletes all of your contracts and playbooks along with it. Every deletion is recorded in our audit log, though the audit record itself (that a deletion happened, by whom, and when) is retained even after the underlying contract data is gone.
7. Third-Party Services
We use Stripe for payment processing (Stripe receives only what's needed to process your subscription; we never see or store your card details), OpenAI for the AI explanation layer (bounded excerpts only, as described in section 4), and Google for optional sign-in. We do not sell your data or share your document content or analysis results with any other third party.
8. Your Rights
You can access, export, and delete your contract data at any time from your account. Deleting a contract or your account is a real, permanent deletion, and is available to you directly — you don't need to file a request and wait for us to act on it.
9. Contact
For privacy-related questions, contact us at our contact page.