Privacy Policy

Last updated: September 2026 — see our Security page for the technical controls behind these commitments.

Who We Are

TriageCounsel is the trade name for our connected contract review platform. We are completing formation of our operating company; this policy will be updated with the legal entity name and address once registration is finalized. In the meantime, "TriageCounsel," "we," "us," and "our" refer to the operator of triagecounsel.com.

1. Information We Collect

We collect information you provide when creating an account (name, email, password) and the contract data you submit for analysis — the extracted text of each document, plus the findings, risk scores, and AI explanations generated from it. We also automatically collect basic usage and acquisition data (IP address, user agent, referrer, and UTM parameters) so we can secure the service and understand how it's used. We do not collect payment card details — those go directly to Stripe.

2. Document Handling

The original file you upload (the PDF or DOCX bytes) is never written to disk or persisted — only the extracted text is stored, in our database, so you can revisit your analysis later. That stored text, along with the findings and AI explanations derived from it, is encrypted at rest with AES-256-GCM before it touches the database. We do not use object storage or any third-party file host for your documents.

3. How We Use Your Information

Account information is used to provide and maintain your TriageCounsel account, process payments, and communicate service updates. Contract data is used solely to generate and display your analysis and review history. Usage and acquisition data is used to secure the platform (rate limiting, abuse detection, audit logging) and to understand product usage — never to profile or advertise to you.

4. AI and Data Training

Your documents and analysis results are never used to train AI models — by us or, per OpenAI's standard API terms, by OpenAI. OpenAI may receive contract content and analysis context as required by the features you use, which can range from short excerpts to broader passages depending on configuration. Optional features you enable (such as AI-assisted playbook import) may send additional document content you choose to upload. The AI cannot create authoritative policy outcomes or change your risk score — those are computed outside the AI. See our Subprocessors page for details.

5. Data Security

Contract text and the detailed analysis derived from it are encrypted at rest with AES-256-GCM, with support for key rotation. All data in transit is encrypted with TLS. Passwords are hashed with PBKDF2-HMAC-SHA256 and never stored in plaintext. You can enable optional two-factor authentication (TOTP) on your account. Every account, contract, and playbook query is scoped to your account, so other customers cannot reach your data through the application. Uploads, exports, deletions, shares, and admin access are all recorded in an append-only audit log. See our Security page for the full list of controls.

6. Data Retention and Deletion

Your contracts are retained while your account is active, unless you delete them sooner. You can permanently delete an individual contract — its text, findings, and share link — from your history page at any time; this is a hard deletion, not a soft flag. Deleting your account permanently deletes all of your contracts and playbooks along with it. Every deletion is recorded in our audit log (who deleted what, and when). Audit and security records may be retained after underlying contract data is deleted. Automated server backups on our hosting provider (Hetzner Cloud) use a 7-slot rotation; deleted data may persist in backups for up to approximately seven days before the oldest backup is replaced.

7. Subprocessors and Third-Party Services

We use service providers to operate TriageCounsel. Production hosting and storage of customer content is located in Germany. A current list of subprocessors, processing locations, and high-level data categories is maintained on our Subprocessors page.

In summary: Hetzner Online GmbH (Germany) hosts the application and stored customer data; OpenAI processes contract content and analysis context as required by enabled features; Stripe processes billing metadata; Google supports optional sign-in; and an SMTP email provider delivers transactional email in production. We do not sell personal information.

8. Cookies and Analytics

We use essential cookies for authentication and CSRF protection. We collect usage and acquisition metadata (referrer, UTM parameters, session identifiers, IP address, user agent) to secure the platform and understand product usage. We do not use third-party advertising cookies.

9. Security Incidents

If we become aware of a security breach that affects your personal information or stored contract data, we will investigate promptly and notify affected users and relevant authorities as required by applicable law.

10. Your Rights

You can access, export, and delete your contract data at any time from your account. Deleting a contract or your account is a real, permanent deletion of primary contract content, and is available to you directly — you don't need to file a request and wait for us to act on it. For other privacy requests, contact us using the information below.

11. Contact

For privacy-related questions, contact us at our contact page.