Privacy Policy

Effective date: September 2, 2026

Final ("Platform") is operated by Final Contracts LLC ("we," "us," or "our").

30-Day Document Deletion

Your documents do not live on Final. When a negotiation ends (whether by agreement, cancellation, or a declined invitation), it enters a 30-day deletion window. After 30 days, an automated process permanently deletes the uploaded templates, every AI-prepared draft and tracked-changes version, the final executed document, all chat messages, and the verbatim text of negotiated provisions, from both file storage and our database. Negotiations with no activity for 90 days are treated as abandoned and put on the same 30-day deletion clock.

1. Information We Collect

We collect only what the Platform needs to run a negotiation between two parties:

  • Account information. Name and email address for account holders. Passwords are managed by our authentication provider and stored only in hashed form; we never see them.
  • Participant information. Names, email addresses, titles, and organizations of the people each party adds to a negotiation: business contacts, legal counsel, and team members. Counterparties do not create accounts; they access the Platform through a secure token link, scoped to a single negotiation, sent to their email.
  • Documents. The NDA templates and markups you upload, and the drafts, tracked-changes versions, and final documents the Platform prepares. Documents are stored in a private bucket and served only through short-lived signed URLs.
  • Negotiation activity. Template preferences, approval and revision decisions, chat messages between the parties, and an audit trail of actions taken in the negotiation.
  • Diagnostic data. When something goes wrong, a scrubbed error report (browser and system metadata, with credentials and personal details redacted) is sent to our error-monitoring provider; see Service Providers below.
  • Billing information. Payments are processed by Stripe. We store your subscription tier and status; we never see or store card numbers.
  • Product usage events. Basic product events (for example, that a negotiation was started or a template uploaded), associated with the acting user and negotiation, used to operate and improve the Platform.
  • Waitlist requests. If you request an invitation during the private beta, we store the email address you submit so we can contact you about access.

2. How We Use Your Information

We use the information above to run your negotiations: preparing merged drafts, delivering documents and notifications by email, enforcing each party's access boundaries, processing subscriptions, and providing support. We also derive de-identified, aggregated insights about how provisions are typically resolved (see Section 5) to improve the Platform. We do not sell your personal information or your documents, and we do not use them for advertising.

3. AI Document Processing

Final prepares merged drafts by sending the documents both parties submit to Anthropic's Claude API. Under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models. The AI reads only the documents the parties submit for synthesis; chat messages between the parties are never sent to the model.

4. Data Retention

Document content and negotiation substance follow the 30-day deletion schedule described at the top of this policy. After that deletion runs, what remains is account and participant identity (names, email addresses, organizations), negotiation metadata (status and dates), and the audit trail, which we retain to operate your account and preserve a record that the negotiation took place. If you want your account and associated personal information deleted as well, contact us at the address in Section 9 and we will process the request.

5. De-identified Provision Insights

Before a negotiation's content is deleted, the Platform extracts a de-identified record of how its provisions were resolved: the provision type, normalized values (for example, a confidentiality term in years), the resolution type, and coarse industry and company-size categories. These records carry no names, no document text, and no link back to the negotiation or the parties. We use them to understand market norms and improve the Platform's resolutions.

6. Service Providers and Data Location

Final operates in the United States and processes all data there.

Final runs on a small set of infrastructure providers, each processing your data only to provide their service to us:

  • Vercel: application hosting.
  • Supabase: database, authentication, and document storage.
  • Anthropic: AI document processing via the Claude API (Section 3).
  • Resend: transactional email delivery.
  • Stripe: payment processing, once subscriptions are live.
  • Sentry: error monitoring. Error reports are scrubbed before sending: no request bodies, no document content, no email addresses, and no access tokens or invite links leave the Platform in an error event.

7. Security

All traffic is encrypted in transit. Documents live in a private storage bucket and are only reachable through short-lived signed URLs issued after an authorization check. Counterparty access is scoped to a single negotiation through per-recipient token links, and a party's response to a draft is not visible to the other party unless both parties approve it. Access to negotiation data is enforced server-side on every request.

8. Your Rights and Choices

You can request a copy of the personal information we hold about you, correction of inaccurate information, or deletion of your account and associated personal data by contacting us at the address below. Document deletion is automatic on the 30-day schedule and requires no request. Depending on where you are located, you may have additional rights under local data protection law; we will honor valid requests accordingly.

9. Contact

If you have questions about this Privacy Policy or want to exercise any of the rights above, contact us at support@finalcontracts.com.

10. Changes to This Policy

We may update this policy as the Platform evolves. Material changes will be communicated by email or a notice on the Platform, and the effective date above will be updated. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.