Skip to main content

Privacy Policy

Last updated: March 5, 2026

Contract.DIY (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at Contract.DIY.

1. Information We Collect

We collect information in the following categories:

  • Account data. When you sign up via Google OAuth, we receive your name, email address, and profile picture from Google. We store your email and display name to identify your account.
  • Contract content. The descriptions, party names, clauses, and other text you provide when generating contracts. This content is submitted to our AI provider to generate your contract.
  • Usage data. Log data including your IP address, browser type, pages visited, features used, and timestamps. We use this to improve the service and monitor for abuse.
  • Billing data. Subscription and payment information is handled by Polar. We do not store your payment card details directly.

2. How We Use Your Information

  • Service delivery. To authenticate you, generate contracts, store your history, and process your subscription.
  • AI processing. Your contract inputs are sent to OpenAI's API to generate contract text. See the AI Processing Disclosure section below.
  • Service improvement. Aggregated, anonymised usage patterns help us improve features. We do not sell your data.
  • Communications. We may send transactional emails (receipts, account security) and, if you opt in, product updates.

3. Data Storage & Security

Where your data is stored. Our primary database is hosted in the United States (AWS us-east-1, via Neon). The application itself runs on Cloudflare's global edge network, which serves requests from the location nearest to you. Some processors run inside the EU (session cache in AWSeu-central-1, error monitoring and product analytics on EU infrastructure) and others in the United States — the table in section 5 states the region for each one.

We use industry-standard encryption in transit (TLS 1.2+) and at rest. Access to production data is restricted to authorised personnel only.

Retention. We retain your account and contract data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where we are required to retain it by law.

4. AI Processing Disclosure

Important - how your content is processed

When you generate a contract, the text you provide (party names, contract type, special terms, etc.) is transmitted to OpenAI's API. OpenAI processes this data under their API data usage policy.

Your contract content is not used to train AI models. We use the OpenAI API under terms that prohibit training on your inputs. We do not use your contract content to train any models ourselves.

5. Third-Party Services

We work with the following processors, who may handle your data in the region shown. Regions are the ones we have verified in our own infrastructure, not the vendor's marketing claim.

  • Neon (United States, AWS us-east-1) - our primary database. Accounts, contracts, and contract content are stored here.
  • Cloudflare (global edge) - application hosting and delivery. Requests are served from the nearest edge location.
  • OpenAI (United States) - AI contract generation. Your contract inputs are processed per OpenAI's API terms.
  • Polar (United States) - subscription billing and payment processing. Polar's privacy policy applies to billing data.
  • Google (United States) - authentication via Google OAuth, and Google Tag Manager for the analytics and advertising tags described in section 7. Google's privacy policy applies when you sign in.
  • Resend (United States) - transactional email: receipts, account security, and signing notifications.
  • Upstash (European Union, AWS eu-central-1) - session cache and rate limiting.
  • Sentry (European Union) - error monitoring on Sentry's EU instance.
  • PostHog - product analytics and usage insights. PostHog tracks page views, feature interactions, and user flows in a pseudonymised manner. Data is stored on EU servers. PostHog analytics are only loaded after you have given your consent via the cookie banner.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

5b. International Data Transfers

We are established in the Netherlands, and several of our processors are located in the United States. Using the service therefore involves transferring your personal data outside your own country, including outside the EEA and outside Türkiye.

For data subjects in the EEA, the UK, or Switzerland. Each of our US processors publishes a data processing agreement that we are bound by as a condition of using the service, and each provides a transfer mechanism for European personal data: the European Commission's Standard Contractual Clauses (Decision 2021/914), the EU-US Data Privacy Framework, or both. Neon, OpenAI, Polar, Resend and Cloudflare incorporate that agreement automatically under the terms we accepted when we signed up. Google's Ads Data Processing Terms apply to the tags described in section 7. You may request the specific agreement and clauses that apply to any processor at privacy@contract.diy.

For data subjects in Türkiye. Under Law No. 6698 (KVKK) article 9, as amended on 2 March 2024, transferring personal data abroad requires an adequacy decision (yeterlilik kararı) from the Personal Data Protection Board, or an alternative safeguard such as explicit consent (açık rıza) obtained specifically for the transfer. The Board has not issued an adequacy decision for any country to date, and we have not yet built a transfer-specific consent flow — the cookie banner on this site covers cookie consent, not the cross-border transfer of your account data. We therefore do not currently have a lawful basis for transferring the personal data of a data subject in Türkiye abroad. If you are in Türkiye, please do not use the service until we publish that flow. If you have already signed up, email privacy@contract.diy and we will delete your data.

6. Your Rights

If you are in the EU or EEA, you have rights under the General Data Protection Regulation (GDPR):

  • Access. Request a copy of your personal data.
  • Correction. Ask us to correct inaccurate data.
  • Deletion. Request deletion of your account and associated data.
  • Export. Download your contracts at any time from your dashboard in PDF or DOCX format.
  • Objection. Object to processing based on legitimate interests.
  • Complaint. Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we have violated your rights.

To exercise these rights, email privacy@contract.diy.

6b. Legal Basis for Processing (GDPR Article 6)

We process your personal data only where we have a valid legal basis under the General Data Protection Regulation (GDPR):

  • Contract performance (Article 6(1)(b)). Account data, contract content, and billing information are processed to deliver the service you have subscribed to.
  • Legitimate interests (Article 6(1)(f)). We process usage logs to improve our product and to detect and prevent abuse or fraud, where our interests are not overridden by your rights.
  • Consent (Article 6(1)(a)). Analytics cookies (PostHog) and any marketing communications are only processed after you have given your explicit consent via the cookie banner or opt-in mechanism. You may withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)). Where required by applicable law, we may retain certain data to comply with legal or regulatory obligations.

7. Cookies

We use essential cookies to keep you signed in and maintain your session. We also load Google Tag Manager, which can set analytics and advertising cookies. What is allowed to run before you choose depends on where you are: in the EEA, the UK, Switzerland and Türkiye nothing non-essential runs until you consent; elsewhere some categories may default on, and you can change them at any time from the cookie banner. The cookies we set include:

  • Session cookie - identifies your authenticated session. Expires when you sign out.
  • Preference cookie - stores UI preferences (e.g. theme). Persists for 1 year.
  • Analytics cookies (PostHog) - when you consent via the cookie banner, PostHog sets cookies to track page views, feature usage, and user flows in a pseudonymised manner.
  • Advertising cookies (Google Tag Manager) - when advertising consent is granted, Google tags may set cookies used for ad measurement and personalisation. These are denied by default in the EEA, the UK, Switzerland and Türkiye until you opt in.
  • Consent cookie - stores your cookie consent preferences. Persists for 1 year.

8. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify you by email. Your continued use of the service after changes take effect constitutes your acceptance of the updated policy.

9. Contact & Data Controller

Questions about this Privacy Policy or your data rights? Reach us at privacy@contract.diy or our contact page.

Contract.DIY is a document preparation service, not a law firm. Generated contracts are templates for informational purposes and do not constitute legal advice. We recommend having any contract reviewed by a qualified attorney before signing.