The short version: your contracts are parsed and filled in your browser. We run no ads, no third-party trackers, and we never sell your data. Ever.
Reading a contract, computing deadlines, and filling forms all run locally on your device. Dropping a PDF on recontract.ai does not upload it anywhere — the file never leaves your browser.
The contract terms you save are the only sensitive information we hold, and we encrypt them at rest (AES-256-GCM) under a key kept separate from the database. Passwords are stored only as a salted PBKDF2 hash, never in the clear. You can turn on two-factor authentication (an authenticator-app code) to protect sign-in, and we rate-limit and lock out repeated failed attempts. Everything travels over TLS, and the site is served with a strict security policy. The contract document itself is never uploaded at all — it is read and filled in your browser.
Payments are processed by Stripe. Your card number never touches our servers. We store only the Stripe customer reference and your subscription status. If you subscribe, checkout also collects your billing address so that any applicable sales tax can be calculated.
One cookie: your sign-in session. No advertising cookies, no analytics cookies, no cross-site anything.
Nobody, except the processors that make the service run: Stripe (payments), Cloudflare (hosting), and Google only if you choose Google sign-in. We never sell or rent your information.
Delete contracts and listings yourself, any time, from the dashboard. You can also delete your entire account from your profile under Security — one action erases your account, saved contracts, and listings immediately. It cannot be undone. (Document integrity seals, which contain only a fingerprint and no contract terms, are kept but detached from your identity, so a document you produced can still be verified as unaltered.)
Questions about your data, or a request to exercise any of the above: support@recontract.ai.