Legal

Privacy Policy

Last updated: August 2026

1. We don't want your data.

T&C Lens is built on a fundamental principle of privacy-by-default. If you use the "Bring Your Own Key" (BYOK) version of our extension, your API key is stored locally in your browser's extension storage. We do not have access to it, and your document analyses are sent directly from your browser to your chosen AI provider (e.g., Anthropic, OpenAI). We never see your queries.

2. T&C Lens AI (Hosted Tier)

If you create an account to use the hosted T&C Lens AI tier, we collect your email address via GitHub OAuth for authentication and billing purposes. We store a cryptographically hashed version of your API key.

When you highlight text and send it to our `/api/analyze` endpoint, the text is held in memory purely for the duration of the request to the LLM (DeepSeek). We do not log, store, or train on any text you highlight. Period.

3. Third-Party Services

We use Stripe for payment processing. We do not store your credit card information. We use Supabase for authentication and database hosting (which stores your credit balance and hashed API key).

4. Contact

If you have any questions about this policy, or want your account and email completely deleted from our database, please contact privacy@tclens.com.