← Back to home
Legal Document

Privacy Policy

Last updated: August 2026

01. Core Principle

We do not want your data.

T&C Lens is built on a fundamental principle of privacy-by-default. If you use the "Bring Your Own Key" (BYOK) version of our extension, your API key is stored locally in your browser's extension storage. We do not have access to it, and your document analyses are sent directly from your browser to your chosen AI provider. We never see your queries.

02. Hosted Tier

If you create an account to use the hosted T&C Lens AI tier, we collect your email address via GitHub OAuth for authentication and billing purposes. We store a cryptographically hashed version of your API key.

When you highlight text and send it to our /api/analyze endpoint, the text is held in memory purely for the duration of the request to the LLM provider. We do not log, store, or train on any text you highlight. Period.

03. Third-Party

We use Stripe for payment processing. We do not store your credit card information. We use Supabase for authentication and database hosting (which stores your credit balance and hashed API key).

We do not use tracking cookies, analytics pixels, or any third-party marketing trackers. The extension uses your browser's local storage exclusively to save your settings and preferences.

04. Your Rights

Because we do not store or keep any of the documents or text you scan, there is no document data to delete. However, if you use the Hosted Tier, you can request a complete deletion of your account (email and API key hash) and all associated billing data at any time by contacting us.

05. Contact

If you have any questions about this policy, or want your account and email completely deleted from our database, please contact privacy@tclens.com.