Privacy Policy

Last updated

This policy explains what information Terms handles, why we use it, who receives it, and the choices you have when you visit, draft, collaborate, or sign.

1. Who we are and what this policy covers

Terms is operated by The Office of Diego Segura LLC d/b/a Family Office (“Terms,” “we,” “us,” or “our”). This Privacy Policy covers terms.so, our contract drafting and signing application, AI features, email agent, and related support services (the “Service”). It applies to visitors, account holders, document participants, and people whose information is included in materials submitted to us.

We determine how personal information is used to administer accounts, operate and secure the Service, manage billing, and communicate with you. When a customer submits documents or another person’s information for processing on their behalf, that customer determines the purpose of that use and is responsible for having an appropriate basis to provide it. In those circumstances, we act as a service provider or processor where applicable law so provides. A separately signed data processing agreement, if any, governs that processing.

This policy describes our practices; it does not replace a customer’s own privacy notice. The Terms of Service govern use of the Service. For privacy questions, contact support@terms.so.

2. Information we collect and its sources

  • Account and profile information. Name, email addresses, verification status, account and organization identifiers, and profile details supplied by you or our authentication provider, Clerk. If you choose Google sign-in, we receive the profile information made available through that sign-in. Our application does not receive your Google password.
  • Documents and files. Contract titles and text, private drafts and unsent revisions, published versions, uploaded PDFs and text files, extracted text, source files retained for reference, document status, and related metadata.
  • Participants and collaboration. Names, email addresses, job titles, organizations, saved signer details, comments, the text comments refer to, and information a sender or another participant supplies about you.
  • Signatures and activity records. Typed signature names, signing consent, timestamps, account identifiers, IP addresses and browser information recorded with relevant events, document versions, and hashes of signed text. These records help document what happened to an agreement.
  • AI interactions. Prompts, conversation history, attached files, generated responses, requested edits, document excerpts or full text retrieved to answer a question, and usage measurements. Conversations can be stored with your drafts.
  • Email and support communications. Messages you send to us or our email agent, sender and recipient details, subject lines, message identifiers, quoted correspondence, attachments, replies, and information needed to authenticate and process a request. Other participants may include your information in these messages.
  • Billing information. Subscription tier and status, customer and subscription identifiers, billing periods, and related transaction records received from Stripe. Payment details entered in Stripe’s hosted checkout are collected by Stripe; full card numbers and security codes are not stored by our application.
  • Technical and usage information. Request and error logs, IP addresses, device and browser information, referring pages, page visits, approximate location inferred by service providers, feature activity, usage limits, and security events. We receive this information from your use of the Service and our infrastructure providers.

We collect information directly from you, automatically through the Service, and from document senders, other participants, identity providers, payment providers, and service providers. Some information is necessary to create an account, deliver a requested feature, or maintain an execution record; without it, we may be unable to provide that feature.

Documents and messages may contain sensitive information that you or others choose to include. Provide only what is necessary, and do not upload passwords, payment card credentials, or regulated information that the Service is not suitable to handle.

3. How we use information

  • Authenticate users, administer accounts, and enforce document access permissions.
  • Create, store, import, search, edit, share, comment on, and sign documents; maintain versions and evidence of execution.
  • Provide requested AI assistance, process attachments, answer questions about accessible documents, and operate the email agent.
  • Send signing invitations, document updates, completion or withdrawal notices, agent replies, service notices, and support responses.
  • Process subscriptions, measure usage, apply plan limits, and maintain transaction records.
  • Diagnose failures, understand usage, improve reliability and usability, and detect fraud, abuse, and unauthorized access.
  • Comply with applicable obligations, resolve disputes, preserve necessary records, and protect the Service and the rights of its users.

We do not sell personal information, use contract content for targeted advertising, or use your documents and conversations to train our own general-purpose AI models.

4. AI processing and uploaded files

We use Anthropic’s API to provide AI drafting, document questions, PDF transcription and import, and email-agent assistance. When you invoke these features, we send the information needed for the task, which can include your prompt, conversation context, comments, signer details, attachments, and document text. A search or drafting request may retrieve other documents available to your account, including your own unsent revisions, and send relevant results or text to Anthropic.

Uploading an attachment to an AI feature may send its contents to Anthropic for processing and token counting before you submit a chat message. Importing a PDF and emailing the agent also involve AI processing; this is not limited to the drafting panel. Ordinary manual editing and signing do not by themselves trigger an AI request.

We configure files uploaded through the AI attachment feature to expire at Anthropic after 24 hours. That expiry applies to the uploaded file, not to saved chats, extracted text, imported source documents, or every copy held in provider logs. Anthropic’s separate API retention rules include standard retention and exceptions for safety, legal requirements, and certain models or features. See Anthropic’s retention explanation.

Anthropic states that commercial API inputs and outputs are not used for model training by default, subject to the choices and exceptions described in its commercial data policy. We do not opt your contract content into model training. AI output may contain inaccurate personal information; check it before relying on or sharing it.

5. Who receives information

We disclose information as needed for the purposes in this policy, including to the following providers:

  • Vercel: application hosting, background workflows, operational logs, and website analytics. Hosted requests and workflows can process document and communication content.
  • Neon: database storage for documents, source files, conversations, participant details, execution records, and application records.
  • Clerk: account creation, identity verification, sessions, and account management.
  • Anthropic: AI requests, attachments, imports, and related processing described above.
  • Resend: sending service emails and receiving and delivering email-agent messages, including message content and attachments where relevant.
  • Stripe: checkout, subscriptions, payments, and billing management.

Google is also involved when you select Google sign-in. Identity and payment providers may process some information independently under their own policies. Their services and other websites you choose to visit are not governed solely by this policy.

Document participants and authorized recipients. Content, comments, signer details, signatures, and relevant execution records are available to people permitted to access the document. An organization’s authorized users may have access within that organization. Recipients can retain or redistribute information they receive; we cannot erase their downloaded copies or inboxes.

Other disclosures. We may disclose information to professional advisers under appropriate confidentiality obligations; when reasonably necessary to comply with law or valid legal process, investigate abuse, or protect rights and safety; at your direction; or in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to applicable protections. Authorized personnel may access information where needed for support, security, and service operations.

7. Services you connect or authorize

If you authorize an integration or give another service access credentials, that service may receive information within the permissions you grant. This can include document titles, status, excerpts, full text, or drafts where the permission allows it. Review the permission scope before connecting a service or sharing a key.

Terms’ read-only connector keys let a service such as Meta Muse search and read contracts available to your account, including drafts and, when explicitly requested, your own unsent revisions. Each request rechecks current account access. These keys expire after 90 days and can be revoked in Connectors. They cannot edit, send, delete, or sign contracts. We store key hashes, creation and expiry dates, last-use time, and revocation state.

We may record authorization, credential identifiers or hashes, and access activity to manage and secure that connection. Use the available revocation controls or contact us to stop future access. Revocation does not delete information already received by another service; its own terms, privacy policy, and retention practices apply to that information.

8. Cookies, browser storage, and analytics

Authentication services use cookies and related technologies to maintain sessions and protect accounts. The application also uses local or session storage for features such as recent documents, acknowledgement status, and conversation continuity. Clearing browser storage may reset these features; blocking authentication cookies may prevent sign-in. Clearing local storage does not delete records stored on our servers.

We use Vercel Web Analytics on the production site to understand traffic and page usage. Before sending page URLs, our application removes query strings and fragments, replaces document identifiers with generic route labels, and excludes routes outside an allowlist. This analytics integration is not configured to send contract text or chat content. Vercel describes its analytics collection, including its cookie-free visitor measurement, in its analytics privacy documentation. Operational and signing logs are separate from website analytics.

We do not use advertising cookies or share personal information for cross-context behavioral advertising. Because we do not sell information or engage in that advertising sharing, there is no such activity for a Global Privacy Control signal to opt you out of. We do not otherwise change essential processing in response to browser Do Not Track signals. You can manage cookies and local storage through your browser.

9. Retention, deletion, and document records

Retention depends on the kind of information, the feature used, account activity, the need to preserve evidence of a transaction, and applicable legal obligations. We retain account and service records for as long as needed to provide the Service, manage our relationship, resolve disputes, prevent abuse, and satisfy those obligations. There is no single automatic deletion period for all information.

  • Documents and execution evidence. Stored documents, published versions, signatures, comments, and audit records can remain available for the life of the account or longer where needed for the parties’ records or legal claims. Voiding a document stops further signing; it does not erase its history or determine its legal effect.
  • Recently deleted drafts. Deleting a draft from the document list marks it as deleted and retains its associated records for the Recently deleted feature. It is not immediate permanent erasure, and the application does not currently apply an automatic purge period to those drafts. Contact us for a permanent-deletion request.
  • Imports and AI data. Some import workflows remove temporary processing copies after completion, while saved source PDFs, extracted text, and conversations remain with the relevant records. The AI attachment expiry described above does not delete these stored records.
  • Email processing. Successful email-agent workflows clear temporary message payloads and reply buffers after delivery. Saved documents, conversation records, request metadata, provider records, and incomplete or failed jobs may persist separately.
  • Billing, security, and backups. Transaction records, security logs, and backup copies may outlast active account data where needed for accounting, security, recovery, or legal obligations. Backup deletion may occur through the provider’s normal retention cycle.

Closing your sign-in account or cancelling a subscription does not necessarily delete application records. Contact support@terms.so to request account-data deletion. We may need to preserve limited information for legal obligations, security, or other parties’ legitimate rights, and will explain applicable limitations. Export agreements you need before requesting deletion.

10. Security

We use encrypted connections and account-based access controls designed to protect information in the Service. Security also depends on our providers, your devices, and the security of your email and authentication accounts. No system can guarantee absolute security or uninterrupted availability.

Terms is not SOC 2 certified and has not undergone an independent third-party security audit. Do not assume that it meets a particular regulated-industry standard. Report suspected unauthorized access or a security issue to support@terms.so.

11. International processing and legal bases

We operate from the United States and use providers that may process information in the United States and other countries. Those countries may have different privacy laws from your country. Contact us for details about the processing locations and transfer safeguards applicable to your information, including how to request a copy of applicable contractual safeguards. This policy does not itself establish a data-transfer agreement or a data-residency commitment.

Where European, UK, or similar data-protection laws apply to processing for which we are the controller, our legal bases depend on the purpose: performing our contract with you to provide accounts and requested services; legitimate interests in securing, supporting, improving, and administering the Service and preserving transaction evidence, balanced against your rights; complying with legal obligations; and consent where required. You may withdraw consent without affecting processing that occurred lawfully before withdrawal.

For content processed on a customer’s behalf, the customer is responsible for identifying its own legal basis. We do not use AI responses to make solely automated decisions about individuals that have legal or similarly significant effects; customers remain responsible for decisions they make using the Service.

12. Your choices and privacy requests

You can update available profile information in your account, choose whether to use optional AI features, manage your browser storage, and stop submitting new content. Essential account, security, billing, and transaction messages may still be necessary while you use the Service.

Depending on your location and the law that applies, you may have rights to confirm processing; access or receive a portable copy of information; correct inaccuracies; request deletion; restrict or object to processing; withdraw consent; and complain to your local privacy regulator. Some rights are subject to exceptions, including the need to preserve an accurate signature record or another person’s rights.

Send requests to support@terms.so with the email address associated with your account or document and a description of the request. Do not send passwords or complete identity documents in your initial email. We may ask for proportionate information to verify identity or an authorized agent’s authority. We will respond within the period required by applicable law, explain any permitted extension or refusal, and will not discriminate against you for exercising protected rights.

If we process the information for a customer, we may refer you to the document owner or assist them in responding. Correcting a profile does not rewrite historical contracts or execution evidence. If you believe we incorrectly denied a request, reply to our response with “Privacy appeal” so we can review it, where an appeal right applies. You may also contact your regulator without first contacting us.

13. Additional information for US residents

Where applicable state privacy laws cover our processing, the categories described above include identifiers, customer and commercial records, internet or network activity, professional information, and information contained in documents and communications. Content you provide may include sensitive personal information, such as private correspondence or government identifiers. The collection sources, purposes, recipient categories, and retention criteria are described in the corresponding sections of this policy.

We use sensitive information to provide requested services and for security, compliance, and other purposes permitted by applicable law, not to infer personal characteristics for advertising. We do not sell personal information or share it for cross-context behavioral advertising, including information about minors, and do not use it for targeted advertising or profiling that produces legal or similarly significant effects.

California and other state residents may have the access, correction, deletion, portability, opt-out, authorized-agent, and appeal rights available under their applicable law. Use the request procedure above. We do not disclose personal information to third parties for their own direct marketing. Nothing in this policy limits rights that cannot be waived under applicable law.

14. Children

The Service is intended for adults, and account holders and signers must be at least 18 and legally able to enter the relevant agreement. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided information to us, contact support@terms.so so we can investigate and take appropriate action. Customers must have a lawful basis before including information about minors in their documents.

15. Changes to this policy

We may update this policy as the Service or our practices change. The date above identifies the latest revision. For material changes, we will provide additional notice appropriate to the change, such as an in-product notice or email. If a change requires consent under applicable law, we will obtain it before applying that change. You may request information about a previous version by contacting us.

16. Contact us

For privacy questions, requests, or complaints, email support@terms.so and identify your request as a privacy matter. The operator responsible for this policy is The Office of Diego Segura LLC d/b/a Family Office.