Privacy Policy
Last updated: June 29, 2026
This Privacy Policy is provided in English. The English version is the sole legally binding text. Any translation is provided for convenience only and is not authoritative.
Conditio ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI contract risk analysis service at conditio.org.
1. Information We Collect
We collect the following types of information:
- Account information: Your email address when you register or sign in with Google.
- Contract files: PDF or DOCX files you upload for analysis. The original file is never stored on our servers — see Section 3 for the full lifecycle of a contract you upload.
- Analysis results: The risk scores, flags, and summaries generated from your contracts are stored in your account history.
- Chat messages: If you use the contextual AI chat (available on the Pro plan) to ask questions about a report, those messages are stored in your account, linked to that specific analysis, so you can resume the conversation later.
- Usage data: Basic analytics such as pages visited and actions taken, collected via Google Analytics.
2. How We Use Your Information
- To provide and improve our contract analysis service.
- To store your analysis history so you can access previous results.
- To authenticate you and manage your account.
- To send you important updates about the service (no marketing emails without your consent).
3. Your Contracts Are Private
We treat the confidentiality of your contracts as our most important commitment. Here is exactly what happens — and what does not happen — to a contract you upload:
- The original file is never stored. When you upload a PDF or DOCX, the file lives only in memory while we extract its text, and is discarded immediately after. We do not save it to disk, we do not back it up, we do not log its contents.
- The full text of the contract is not stored either. The extracted text is sent to our AI provider to generate the analysis, and then discarded. It is not persisted in our database.
- What we do store, linked to your account: the filename you uploaded (e.g. services_agreement.pdf), the results of the analysis (risk score, flagged clauses, summary, recommendation), the context you provided (your role, contract type, jurisdiction), and the date. It is technically impossible to reconstruct the original contract from what we store.
- Your contracts are never used to train AI models. Contract text is sent to Anthropic's Claude API solely to generate your analysis, under Anthropic's Data Processing Addendum (DPA), which is automatically incorporated into Anthropic's Commercial Terms of Service and includes Standard Contractual Clauses for international data transfers. Anthropic's standard API data retention is 7 days, used only for abuse monitoring and trust & safety purposes — not for model training.
- Zero Data Retention available on request. For Business customers with heightened confidentiality requirements, we can route your analyses through Anthropic's Zero Data Retention (ZDR) configuration, under which no prompt or output is retained by Anthropic beyond the immediate response. Contact us to enable ZDR for your organization.
- Only you can access your analysis history. We enforce row-level security in our database: your data is invisible to other users at the infrastructure level, not just at the application level.
4. Data Storage and Security
Your data is stored in Supabase (EU West, Ireland). We use HTTPS encryption for all data in transit, and Supabase's at-rest encryption at the database storage layer. Our application enforces additional security headers — Content Security Policy, HTTP Strict Transport Security, and X-Frame-Options — to protect against common web attacks. Rate limiting is in place on sensitive endpoints (analysis, chat, authentication, team invitations) to prevent abuse.
5. Third-Party Services
To provide our service, we rely on the following sub-processors. Each one receives only the data strictly necessary for its function.
- Anthropic — AI analysis engine. Receives the extracted text of your contract to produce the analysis. Governed by Anthropic's Data Processing Addendum. Privacy policy
- Supabase — database and authentication, hosted in the European Union (Ireland, AWS eu-west-1). Stores account information, analysis results, and team data. Privacy policy
- Railway — backend application hosting, European Union (eu-west region). Provides compute infrastructure; does not have application-level access to your analyses. Privacy policy
- Stripe — payment processing for paid subscriptions. Handles card details directly; we only receive a customer identifier and subscription metadata. Privacy policy
- Resend — delivery of transactional emails (account confirmation, password reset, team invitations). Processes recipient email addresses and email contents. Email contents never include contract data. Privacy policy
- Google Analytics — anonymous usage statistics on the conditio.org landing site. Privacy policy
- Google OAuth — optional sign-in method. Privacy policy
6. Your Rights
If you are located in the European Union, the United Kingdom, or another jurisdiction with similar data protection laws, you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate personal data.
- Erasure ("right to be forgotten") — request that we delete your account and all associated data. We process erasure requests within 30 days.
- Portability — receive your analysis history in a machine-readable format.
- Restriction and objection — ask us to limit how we process your data, or object to specific processing activities.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Lodge a complaint with your national data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
To exercise any of these rights, email us at support@conditio.org. We will verify your identity before processing the request. If you delete your account, all your data — including analysis history — will be permanently removed within 30 days.
7. Cookies
We use essential cookies for authentication and Google Analytics cookies for anonymous usage tracking. You can disable analytics cookies in your browser settings.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website.
9. Contact
If you have any questions about this Privacy Policy, please contact us at: support@conditio.org