Privacy policy
Effective April 2026. We try to write these in plain English where we can.
This Privacy Policy describes how ClauseSpark, Inc. ("ClauseSpark", "we", "us") collects, uses, and shares information when you use our website and services. By using ClauseSpark, you agree to this Policy.
What we collect
- Account data. Name, work email, company, role, password (hashed).
- Usage data. Logs of actions taken in the product (uploads, edits, exports), IP addresses, browser metadata.
- Customer content. Contracts and related documents you upload. Stored encrypted; treated as confidential.
- Communications. Emails, support tickets, and demo requests you send us.
How we use it
- To deliver and maintain the service you're paying for.
- To operate, secure, and improve the platform.
- To respond to support requests and communicate about your account.
- To comply with legal obligations.
We do not use your contracts or other customer content to train AI models, sell to third parties, or share for advertising purposes. Period.
How long we keep it
- Customer content: as long as your account is active. Hard-deleted within 30 days of termination on request.
- Account data: until you ask us to delete it.
- Logs and audit data: 7 years for compliance.
- Backups: 30 days, then permanently destroyed.
- Cookie consent: 12 months. After that, we ask again.
Cookies
We use a small number of cookies and equivalent local-storage entries:
- Strictly necessary — session, CSRF, authentication. Required for the site to work; cannot be disabled.
- Analytics (Google Analytics 4) — anonymised usage data so we can see which pages help and which don't. Off by default. Only set if you click Accept all on the cookie banner. Cleared automatically when consent expires.
We use the GA4 Consent Mode v2 — analytics cookies and ad-related signals are denied until you actively opt in. You can change your choice anytime from the Cookie settings link in the footer. We refresh consent every 12 months.
Your rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to access, correct, port, or delete your personal information. Email privacy@clausespark.com and we will respond within 30 days.
Sub-processors
We use a small number of vetted sub-processors to deliver the service: AWS (cloud infrastructure), Stripe (billing), Postmark (transactional email), and Anthropic / OpenAI (AI inference, with no-training clauses). The full list, with locations and purposes, is at privacy@clausespark.com on request.
International transfers
Customer data is stored in the region you select (EU or US) and is not transferred to other regions for processing. Where transfers are necessary (for example, support access), we rely on Standard Contractual Clauses.
Security
See the security page for full detail on encryption, access controls, and compliance status.
Contact
ClauseSpark, Inc. — privacy@clausespark.com.