Legal
Privacy Policy
PRIVACY POLICY
Last Updated: [Date]
This Privacy Policy explains how [LLC Name] ("Company," "we," "us," or "our") collects, uses, stores, and shares information when you use LegalScanner (the "Service") at legalscanner.net and through our LegalScanner mobile application for iOS (the "App"). References to the "Service" in this Policy include the App unless stated otherwise. By using the Service, you agree to the practices described in this Policy.
─────────────────────────────────────────
1. WHO WE ARE
─────────────────────────────────────────
[LLC Name] is a [State] limited liability company operating the LegalScanner platform. For privacy inquiries, contact us at:
[LLC Name]
[Address]
[contact@legalscanner.net]
For users in the European Economic Area (EEA) or United Kingdom, [LLC Name] acts as the data controller for personal data processed through the Service.
─────────────────────────────────────────
2. DATA WE COLLECT
─────────────────────────────────────────
2.1 Account Information. When you create an account, we collect your email address, name (if provided), and authentication credentials via our identity provider (Clerk). If you subscribe to a paid plan, your payment information is processed directly by Stripe — we do not store full payment card details.
2.2 Uploaded Documents. When you upload or paste a document for analysis, that document text is transmitted to and processed by our AI analysis pipeline. For free-tier users, documents are held in temporary storage (Redis cache) for up to 24 hours and are not permanently stored. For paid users (Pro and Team plans), analyzed documents and their results are stored in a persistent, encrypted database (Supabase) tied to your account, accessible through your document vault.
2.3 Analysis Output. The flags, summaries, and other AI-generated analysis produced from your document are stored alongside the document (for paid users) or in temporary cache (for free users).
2.4 Usage and Product Analytics Data. We collect data about how you interact with the Service so we can understand where people succeed or get stuck and improve the product. This is limited to a defined set of events, which currently include: pages viewed (URL and referring page), account created, terms accepted, a scan started, a scan completed (including your plan and the number and severity of flags found — never the document text or the flag content), an upgrade or checkout started, a subscription started or cancelled, and, in the App, progress through onboarding steps (welcome screen viewed, sign-in started, purpose selected, first-scan prompt viewed) and paywall views. We also collect page performance metrics (load speed).
2.5 What We Do NOT Collect for Analytics. We do not use screen recording, session replay, or any equivalent technology anywhere in the Service. We do not record your screen, your keystrokes, or your mouse movements. The content of your documents — including document text, flagged clauses, AI-generated analysis, and document filenames — is never transmitted to our analytics provider. Our analytics is limited to the named events described in Section 2.4.
2.6 Device and Technical Data. We automatically collect certain technical information, including IP address, browser or app version, device type and operating system, screen size, language, referring URLs, and general geographic location (country/region level, derived from IP). This data is used for security, abuse prevention, and analytics.
2.7 Communications. If you contact us by email or through support channels, we retain those communications to respond to your inquiry and improve our support.
2.8 Cookies and Tracking. See Section 8 for details on cookies and tracking technologies.
─────────────────────────────────────────
3. HOW WE USE YOUR DATA
─────────────────────────────────────────
We use collected data to:
(a) Provide the Service — process your uploaded documents through our AI pipeline and return analysis results;
(b) Manage your account — authenticate you, manage your subscription, and process payments;
(c) Enforce usage limits — track scan counts against your plan's monthly allowance and apply rate limiting and abuse prevention controls;
(d) Improve the Service — analyze usage patterns to understand which features are used, where users encounter difficulty (for example, which step of onboarding people abandon), how well the Service converts and retains users, and how quickly pages load. We do not use the content of your uploaded documents to train AI models, and document content is never included in this analysis;
(e) Communicate with you — send transactional emails (receipts, account notices), respond to support requests, and notify you of material changes to these policies;
(f) Comply with legal obligations — respond to lawful requests from law enforcement or regulatory authorities;
(g) Protect against fraud and abuse — detect and prevent unauthorized access, misuse, and fraudulent activity.
─────────────────────────────────────────
4. DATA SHARING AND THIRD PARTIES
─────────────────────────────────────────
We do not sell your personal data or your uploaded documents to third parties. We share data only in the following limited circumstances:
4.1 Anthropic (AI Processing). Document text is transmitted to Anthropic's Claude API for AI analysis. Anthropic processes this data as a data processor on our behalf, subject to Anthropic's privacy and data processing terms. Document content transmitted to Anthropic is not used to train their models under their current API usage policies.
4.2 Supabase (Database Storage — Paid Users Only). For paid subscribers, analyzed documents and results are stored in Supabase, a cloud database provider. Supabase processes this data as a data processor subject to their data processing agreement.
4.3 Clerk (Authentication). Account identity and authentication data is managed by Clerk, which processes user identity information as a data processor.
4.4 Stripe (Payments). Payment processing is handled by Stripe. We share only the data necessary to complete your transaction. Stripe's privacy policy governs their handling of payment data.
4.5 Upstash (Temporary Cache). Temporary session data (including document text for free-tier users) is stored in Upstash Redis with short-lived expiration. Upstash acts as a data processor subject to their privacy terms.
4.6 PostHog (Product Analytics). We use PostHog, a product analytics provider, to understand how the Service is used. PostHog acts as a data processor on our behalf and stores data on servers in the United States. PostHog receives: the usage events listed in Section 2.4, the device and technical data listed in Section 2.6, and — once you sign in — your account identifier and the email address and name associated with your account, so that activity can be attributed to a single account across our website, our App, and our servers. PostHog does not receive your document content, flagged clauses, AI-generated analysis, or document filenames, and we do not use session replay or screen recording. We do not permit PostHog to use your data for its own purposes or to sell it.
4.7 Legal Requirements. We may disclose your information if required by law, subpoena, court order, or other legal process, or to protect the rights, property, or safety of [LLC Name], our users, or the public.
4.8 Business Transfers. If [LLC Name] is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy.
─────────────────────────────────────────
5. DATA STORAGE, SECURITY, AND RETENTION
─────────────────────────────────────────
5.1 Storage Location. Your data is stored on servers located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.
5.2 Security Measures. We implement industry-standard technical and organizational security measures, including encryption in transit (TLS), access controls, and API key management, to protect your data against unauthorized access, loss, or disclosure. In addition, document content at rest — including document text, extracted clauses, analysis results, and file names, in both permanent vault storage and temporary session storage — is encrypted with AES-256 using keys held separately from the databases themselves, so database contents are not readable without access to our application environment.
5.3 Retention — Free Users. Documents uploaded by free-tier users are stored only in temporary cache and are automatically deleted within 24 hours. We do not retain free-user document content beyond this window.
5.4 Retention — Paid Users. Documents stored in the vault are retained for as long as your account is active. If you delete a document from your vault, it is removed from our database. If you close your account, vault documents are retained for 30 days to allow export, then permanently deleted.
5.5 Account Data. Account information (email, subscription history, usage records) is retained for the duration of your account and for a reasonable period thereafter as required for legal, financial, and support purposes (typically up to 3 years post-closure).
5.6 Retention — Analytics Data. Usage events and associated technical data held by our analytics provider are retained for no longer than necessary for the purposes described in this Policy, in accordance with the retention period configured in our analytics account. Because we do not use session replay, there are no screen recordings to retain. If you delete your account, we will delete or de-identify the analytics profile associated with your account on request (see Section 7.3).
5.7 No Guarantee. While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
─────────────────────────────────────────
6. CHILDREN'S PRIVACY
─────────────────────────────────────────
6.1 Age Restriction. The Service is intended solely for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18.
6.2 Inadvertent Collection. If we discover or are notified that we have inadvertently collected data from a user under 18, we will promptly delete that account and all associated data.
6.3 Documents Involving Minors. If an uploaded document incidentally contains personal information relating to a minor (for example, a custody agreement or a contract involving a child), that data is processed solely to provide the analysis requested and is subject to the same retention rules as all other documents. We do not separately use, sell, or disclose personal information of minors contained within uploaded documents.
6.4 COPPA. The Service is not directed to children under 13 and does not fall under the scope of the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has used the Service, contact us immediately at [contact@legalscanner.net].
─────────────────────────────────────────
7. YOUR RIGHTS AND CHOICES
─────────────────────────────────────────
7.1 Access and Portability. You may request a copy of the personal data we hold about you by contacting [contact@legalscanner.net].
7.2 Correction. You may update your account information directly in your account settings or by contacting us.
7.3 Deletion. You may request deletion of your account and associated personal data at any time. Paid users may delete individual vault documents through the vault interface. Account deletion requests submitted to [contact@legalscanner.net] will be processed within 30 days.
7.4 Opt-Out of Marketing. You may opt out of non-transactional marketing emails at any time using the unsubscribe link in any such email. You will continue to receive transactional communications (receipts, account alerts).
7.5 GDPR Rights (EEA/UK Users). If you are located in the European Economic Area or United Kingdom, you have the following additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure ("right to be forgotten") (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object to processing (Article 21)
- Right to withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at [contact@legalscanner.net]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Our legal basis for processing your personal data is:
- Performance of a contract (providing the Service you requested, including processing the documents you submit for analysis)
- Legitimate interests (security, fraud prevention, abuse detection, and understanding and improving how the Service is used)
- Legal obligation (compliance with applicable laws)
- Consent (where you have provided it — specifically, analytics cookies set after you accept our cookie banner, and marketing communications)
Withdrawing consent for analytics cookies: clear your browser's site data for legalscanner.net and choose "Decline" when the banner reappears. Declining does not affect your access to the Service; analytics will simply run without cookies (see Section 8.3). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7.6 CCPA/CPRA Rights (California Users). If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the CPRA:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your privacy rights
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use advertising or retargeting technologies.
To submit a verifiable consumer request, contact us at [contact@legalscanner.net].
─────────────────────────────────────────
8. COOKIES AND TRACKING TECHNOLOGIES
─────────────────────────────────────────
8.1 What We Use. The website uses cookies and similar technologies for the following purposes:
- Authentication cookies (set by Clerk) to maintain your logged-in session
- Functional storage to remember your preferences (for example, your cookie choice)
- Analytics cookies to recognize a returning visitor so usage can be measured across visits
8.2 Essential Cookies. Authentication, session, and security cookies are essential for the Service to function. You cannot opt out of these while using the Service.
8.3 Your Analytics Choice. On your first visit we show a banner asking whether to accept analytics cookies:
- If you accept, we set a cookie containing a randomly generated identifier so that repeat visits can be recognized as the same visitor.
- If you decline, our analytics runs without cookies. A temporary identifier is held in memory for the current page session only and is not persisted, so you are not recognized across visits.
In either case, we do not record your screen and your document content is never sent to our analytics provider. You can change your choice at any time by clearing your browser's site data for legalscanner.net, which will cause the banner to appear again.
8.4 No Advertising or Cross-Site Tracking. We do not use advertising cookies, retargeting pixels, or cross-site tracking technologies, and we do not share your data with advertising networks.
8.5 Third-Party Cookies. Our service providers (Clerk, Stripe, PostHog) may set their own cookies subject to their respective privacy policies.
8.6 Managing Cookies. You can manage or delete cookies through your browser settings. Disabling cookies may affect the functionality of the Service.
8.7 Mobile App. Our iOS App does not use cookies. It collects the same limited usage events described in Section 2.4 using a device-local identifier, and it does not record your screen.
─────────────────────────────────────────
9. INTERNATIONAL DATA TRANSFERS
─────────────────────────────────────────
Our servers and third-party processors are primarily located in the United States. If you access the Service from outside the United States, your data will be transferred internationally. For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as required under applicable data protection law.
─────────────────────────────────────────
10. CHANGES TO THIS PRIVACY POLICY
─────────────────────────────────────────
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or prominent notice in the Service before the changes take effect. The "Last Updated" date at the top of this Policy reflects the most recent revision. Continued use of the Service after the effective date of changes constitutes acceptance of the revised Policy.
─────────────────────────────────────────
11. CONTACT US
─────────────────────────────────────────
For privacy-related questions, requests, or complaints, contact us at:
[LLC Name]
[Address]
[contact@legalscanner.net]
For EEA/UK users, our representative for GDPR purposes can be reached at the same address.