Trust Center
Your documents are not used to train AI.
ClauseShift trains no AI of its own, and we do not save the contract document as part of your account. The third-party AI and transcription providers that process submitted content have confirmed in writing that they do not use it to train their models and do not share it with third parties for training.
Controls current as of July 28, 2026
Data handling
Source documents
Submitted text and files are processed to generate a report. The source document is not saved to your account. When resumable processing is enabled, an AES-256-GCM encrypted job may hold it temporarily; the payload is cleared on terminal completion and the job expires within 24 hours.
Generated reports
Reports are saved to the user account for sync and history. Users can export, delete, restore from Trash, or delete permanently.
Retention
Trash is permanently purged within 30 days. Read-only report links expire after 30 days and can be revoked sooner.
Account control
Account deletion removes the account and associated reports. A machine-readable account export is available from Settings.
Audio transcription
Audio you upload for transcription is processed by Speechmatics, a provider certified to ISO 27001, SOC 2 Type 2, and HIPAA. On our account, transcription is never used to train models, real-time audio is not stored, and batch transcripts are deleted within seven days. A Data Processing Agreement is in place for this processing.
Security controls
- HTTPS-only production traffic and strict browser security headers
- Owner-scoped PostgreSQL row-level security
- Server-side purchase verification and webhook idempotency
- Encrypted transient payloads for resumable review jobs
- App reports excluded from Android cloud and device-transfer backups
- PII-restricted crash reporting with mobile pre-send scrubbing
- Encrypted nightly database and environment backups
- Automated backup restore validation and payment reconciliation
Sub-processors
ClauseShift shares data with a small set of sub-processors, each only for its role and only the data it needs. Every certification below is published on the provider’s own trust page, linked from its name, so you can verify it directly. Their own terms also apply.
| Provider | Role | Data it receives | Certifications & data terms |
|---|---|---|---|
| Railway | Application hosting | Runs the app; data encrypted in transit and at rest | SOC 2 Type 2, GDPR; DPA available |
| Supabase | Authentication, database, realtime sync | Your account, saved reports, and settings | SOC 2 Type 2, ISO 27001, HIPAA (under BAA); DPA available |
| AI/ML API and model providers | Contract analysis | The contract content you submit for review | No training on submitted content and no sharing with third parties for training, confirmed in writing; content processed transiently to deliver the service; governed by their privacy terms |
| Speechmatics | Audio transcription | Audio you upload and its transcript | ISO 27001, SOC 2 Type 2, HIPAA, GDPR; no training (off by default); batch output deleted within 7 days; DPA in place |
| Paystack (a Stripe company) | Payments and subscriptions | Billing details; card data goes directly to them | PCI DSS Level 1 |
| Resend | Transactional and opted-in email | Your email address and message content | SOC 2, GDPR; DPA available |
| Sentry | PII-restricted crash diagnostics | Scrubbed diagnostic data, processed in the EU | SOC 2 Type 2, ISO 27001, HIPAA attestation; DPA available |
| Cloudflare | DNS, email routing, Turnstile, aggregate analytics | Network metadata and routed email | ISO 27001, ISO 27701, SOC 2 Type 2, PCI DSS; DPA available |
Certifications are held by the named providers, not by ClauseShift, and we list them so you can assess the chain your data passes through. Contract content is sent only to the hosting, database, and AI and transcription providers above; the payment, email, analytics, and diagnostics providers never receive contract content.
Questions or a security report?
Use the contact page and choose Technical issue. Do not send contract content, passwords, tokens, or private keys in the report.