Privacy Policy

Last updated: April 7, 2026

1. Who we are

Lumara LLC, doing business as ClauseCheck ("we", "us", "our"), operates the website tryclausecheck.com and provides AI-powered contract analysis services. If you have any questions about this policy, contact us at support@tryclausecheck.com.

2. What information we collect

Account information: When you create an account, we collect your name, email address, and password (stored securely via Supabase Auth).

Contract content: When you upload or paste a contract for analysis, we temporarily process the text to generate your analysis report. We store the analysis results and a short preview of your contract text so you can access your history.

Payment information: Payments are processed by Stripe. We do not store your credit card number, expiry date, or CVC. We receive and store your Stripe customer ID and subscription status.

Usage data: We collect anonymized analytics data (pages visited, features used, events) via PostHog to improve the product. This data does not include your contract content.

Device & technical data: IP address, browser type, and device information collected automatically when you use the service.

3. How we use your information

  • To provide and improve the contract analysis service
  • To manage your account and subscription
  • To send transactional emails (account confirmation, receipts)
  • To analyze usage patterns and improve the product (using anonymized analytics where possible)
  • To comply with legal obligations

4. Your contract data — our commitment

We take your contract privacy seriously:

  • We never sell your contract content to third parties
  • We never use your contract text to train AI models
  • Contract text is sent to OpenAI's API for analysis — OpenAI's data usage policies apply to API usage (they do not train on API data by default)
  • You can delete your account and all associated data at any time by contacting us

5. Data sharing

We share your data only with the following trusted service providers, strictly to operate the service:

  • Supabase — database and authentication
  • OpenAI — AI contract analysis processing
  • Stripe — payment processing
  • Vercel — hosting and infrastructure
  • Resend — transactional email delivery
  • PostHog — anonymized usage analytics

We do not sell, rent, or share your personal data with advertisers or unrelated third parties.

6. Data security

We implement industry-standard security measures including encryption in transit (HTTPS/TLS), encrypted data at rest via Supabase, and row-level security policies ensuring users can only access their own data.

7. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Export your data
  • Opt out of marketing communications

To exercise these rights, email support@tryclausecheck.com.

8. Cookies

We use essential cookies for authentication (to keep you logged in) and analytics cookies via PostHog. We do not use advertising cookies or tracking pixels.

9. Children's privacy

ClauseCheck is not intended for users under 18 years of age. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users of significant changes by email. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions or requests: support@tryclausecheck.com