Privacy Policy
Last updated: July 22, 2026
This Privacy Policy describes how Contract Peer ("we", "us") collects, uses, and protects your data when you use ContractPeer (contractpeer.com). We are committed to transparency about our data practices.
1. Data We Collect
Account Data
- Email address — used for login, notifications, and account management
- Name (optional) — used to personalize your experience
- Password — stored as a one-way hash (never stored in plaintext)
Contract Data
- Uploaded contract files (PDF, DOCX, TXT) — processed to extract text, then the original file is deleted
- Extracted contract text — sent to a third-party LLM API (OpenAI or Anthropic) for analysis, then stored truncated (first 50,000 characters) in your analysis history
- Analysis results — stored in your account for your review history
Payment Data
- Billing information — processed by Stripe. We never see or store your credit card number. Stripe provides us with your customer ID, subscription status, and payment amounts for record-keeping.
- Billing email — used for receipts and subscription management
Usage Data
- Number of contracts analyzed — tracked for usage limits and billing
- Account creation date, plan, and subscription status
- IP address — logged for security purposes
2. How We Use Your Data
- To provide the contract analysis service
- To manage your account, subscription, and billing
- To send transactional emails (receipts, trial notifications, support responses)
- To maintain analysis history for your reference
- To monitor and improve the Service (using aggregate, de-identified metrics only)
- To prevent fraud and abuse
3. How We Do NOT Use Your Data
- We do not use your contract data to train AI models. The LLM API we use (OpenAI/Anthropic) processes your contract text to generate analysis but does not retain it for training (per their API terms).
- We do not sell your data to third parties.
- We do not share your contract data with third parties except the LLM provider necessary to generate the analysis.
- We do not use your data for marketing without your separate consent.
4. Third-Party Services
| Service |
Purpose |
Data Shared |
| Stripe |
Payment processing |
Email, billing details (card data stays with Stripe) |
| OpenAI / Anthropic |
Contract analysis (LLM) |
Extracted contract text for analysis |
| Hosting Provider |
Website hosting |
Account data, analysis results (stored on server) |
5. Data Storage and Security
- Storage: Your data is stored on our hosting provider's servers. Analysis results are stored in a database on the server. Uploaded contract files are deleted after text extraction.
- Encryption: All data in transit is encrypted via TLS/HTTPS. Passwords are hashed using bcrypt.
- Access control: Only you can access your analysis history. Admin access is restricted and logged.
- Data retention: Your data is retained as long as your account is active. When you delete your account, all data (including analysis history and payment records) is permanently deleted within 30 days.
6. Your Rights (GDPR / CCPA)
If you are in the EU, UK, or California, you have the right to:
- Access: Request a copy of all your personal data (available self-service from your Account page)
- Deletion: Request deletion of all your personal data (available self-service from your Account page)
- Rectification: Request correction of inaccurate data
- Portability: Receive your data in a machine-readable format (JSON export available)
- Objection: Object to certain processing of your data
- Withdraw consent: Withdraw consent for any processing based on consent
To exercise these rights, use the self-service tools on your Account page, or contact us at support@contractpeer.com. We will respond within 30 days.
7. Data Subject Request Handling
When you submit a data access or deletion request through the Account page, the system:
- For access requests: compiles your account data, analysis history, and payment records into a downloadable JSON file
- For deletion requests: permanently deletes your analyses, payment records, subscriptions, and account. This action is irreversible.
- All requests are logged with timestamp and action taken
8. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect data from children.
9. International Data Transfers
Your data may be processed in countries other than your own, including the United States (hosting, Stripe) and potentially the LLM provider's infrastructure. We rely on standard contractual clauses and provider compliance programs for international transfers.
10. Cookie Policy
We use a single session cookie (PHPSESSID) to maintain your login session. This cookie is essential for the Service to function and is not used for tracking. We do not use third-party analytics cookies, advertising cookies, or tracking pixels.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email. Continued use after changes take effect constitutes acceptance.
12. Contact
For privacy questions or data requests, contact us at support@contractpeer.com.
This Privacy Policy was generated for ContractPeer and has not been reviewed by an attorney. It accurately describes our actual data practices.