← Agree2What

Privacy Policy (draft — last updated 2026-08-24)

This is a first-draft template pending attorney review, written to accurately reflect what the current app actually does — not aspirational language.

What we collect

- **Account info:** email address, password (stored as a bcrypt hash, never in plain text). - **Contract content:** any text, file, or URL you submit for analysis, the expectations you describe, and the extracted terms, findings, and timeline events generated from them. - **Payment info:** handled entirely by Stripe. Agree2What does not store your card number; we retain only the payment amount, status, and Stripe's own transaction identifiers. - **Usage data:** basic server logs (timestamps, routes accessed) for operating and debugging the service.

What we don't do

- We do not sell your contract content or personal information to third parties. - We do not use your uploaded documents to train third-party AI models without your explicit, separate consent. - We do not share one user's documents with another user.

Third parties involved in providing the service

- **Stripe** — payment processing. - **OpenAI or Anthropic** (only if you've configured an AI provider) — contract text is sent to whichever provider is configured, solely to extract structured terms/expectations. If no provider is configured, extraction happens locally with no third party involved.

Your controls

You can delete a contract, delete your account, or request an export of your data. [Add the actual mechanism/contact for this before launch — currently account deletion isn't yet built into the UI.]

Contact

[Add a real privacy-contact email before launch.]