Legal

Privacy Policy

How TermHarbor handles personal information, uploaded contract content, and AI processing.

Last updated May 13, 2026

1. Introduction

TermHarbor provides AI contract intelligence software, including contract review, clause analysis, obligation tracking, renewal monitoring, playbook management, and related collaboration and reporting workflows. This Privacy Policy explains what information we collect when you visit termharbor.com, sign up for an account, or use the TermHarbor application, and how that information is used, shared, and protected.

This policy applies to the TermHarbor marketing site, the TermHarbor web application, and any related communications. It does not apply to third-party websites, integrations you connect, or services operated by your own organization.

2. Information we collect

We collect the following categories of information:

  • Account data. Name, work email, password credentials, role, and authentication identifiers.
  • Workspace and organization data. Workspace name, team structure, member roles, invitations, and configuration settings.
  • Contact and inquiry data. Information you submit through contact, sales, support, or security forms, including company name and message content.
  • Contract files and uploaded documents. Files you or other authorized members of your workspace upload to the platform for review, storage, or analysis.
  • Extracted contract metadata. Parties, effective dates, term lengths, renewal windows, governing law, and similar structured fields derived from uploaded documents.
  • AI analysis inputs and outputs. Text excerpts sent to AI processing, model responses, suggested edits, summaries, and confidence indicators.
  • Clause findings. Risk flags, deviations from playbook positions, and review comments.
  • Playbooks and approved clause language. Clause libraries, fallback positions, and negotiation guidance you save in your workspace.
  • Obligations and renewal data. Tasks, assignees, due dates, reminders, and renewal status records you create or that are extracted from your contracts.
  • Vendor and customer metadata. Counterparty names, categories, owners, and notes entered by users in your workspace.
  • Product usage data. Pages visited, features used, actions taken, and timestamps used to operate and improve the service.
  • Device and log data. IP address, browser and operating system information, request logs, and error reports.
  • Billing-related metadata. If billing is enabled through a payment provider, we may receive billing identifiers, plan, and transaction status. Card numbers are handled by the payment provider, not by us.
  • Email preference and consent data. Subscription status, consent timestamps, and unsubscribe events for transactional and marketing email.
  • Cookies and similar technologies. Identifiers used to maintain your session and measure aggregate usage. See section 7.

3. How we use information

We use the information described above to:

  • Provide and secure the service. Operate the platform, host your workspace data, and protect accounts.
  • Authenticate users. Verify identity, manage sessions, and enforce access controls.
  • Process contract reviews. Run AI analysis, redlining, and review workflows you initiate.
  • Extract clauses, risks, obligations, and renewal windows. Generate structured insights from uploaded contract content.
  • Generate summaries and briefs. Produce condensed views, deal briefs, and reporting outputs for authorized reviewers.
  • Support collaboration and audit history. Record actions, comments, and approvals attributable to specific users.
  • Provide support. Respond to questions and troubleshoot issues you report.
  • Send transactional email. Send account, security, billing, workflow, and service notifications.
  • Send marketing email only with consent. Send product updates, field notes, and educational content only to people who explicitly opt in.
  • Improve reliability and product experience. Diagnose errors, measure aggregate feature usage, and prioritize improvements.
  • Detect abuse and security issues. Investigate suspicious activity and protect customers and the platform.
  • Comply with legal obligations. Respond to lawful requests and meet record-keeping requirements.

4. AI feature usage

TermHarbor uses AI to analyze contract content, extract risk signals, identify obligations, suggest review language, and generate summaries. AI outputs are review aids and should be checked by an authorized human reviewer before business or legal decisions are made.

When you use AI features, contract content and related context may be processed by AI models, including models operated by third-party AI providers acting under contract with us, in order to generate review outputs such as clause analysis, summaries, suggested redlines, obligation extraction, and risk indicators.

AI outputs are review aids, not legal advice. They may be incomplete, inaccurate, or out of date, and should be verified by a qualified human reviewer before any business or legal decision is made. TermHarbor does not provide legal advice and does not create an attorney–client relationship with users.

Sensitive information should only be uploaded by authorized users acting under the rules and policies of their organization. Workspace administrators are responsible for governing who is permitted to upload content and run AI features.

5. Uploaded contract content

Customers and authorized users remain responsible for the rights, permissions, and authority to upload any document to TermHarbor. Uploaded files may contain confidential business and legal content, personal data of third parties, and commercially sensitive terms.

TermHarbor uses uploaded content solely to provide the service to your workspace — including storage, parsing, AI analysis, search, obligation and renewal tracking, reporting, and collaboration. Access to uploaded content is scoped to your workspace and the members and roles your administrators have authorized.

Workspace administrators can manage retention, deletion, and export of workspace content according to in-product controls and the retention rules described in section 8. Deletion requests submitted through account controls are honored subject to backup, audit, and legal-hold considerations.

6. Sharing and subprocessors

We do not sell personal information. We share information with service providers that help us operate TermHarbor, and only to the extent needed to provide the service. Categories of providers may include:

  • Hosting and database providers. Cloud infrastructure used to run the application and store workspace data.
  • Authentication providers. Identity services used to sign users in and manage sessions.
  • AI service providers and gateways. Model providers used to generate review outputs from contract content.
  • Email providers. Transactional and marketing email delivery (for example, Resend) for service notifications and opt-in updates.
  • Analytics providers. Aggregate product analytics, where used, to understand feature reliability and usage.
  • Payment providers. If billing is enabled, payment processing and subscription management partners.
  • Legal, compliance, and safety. Disclosure where required by law, lawful request, or to protect the rights, safety, and security of users and the platform.

The specific list of subprocessors evolves with the product. To request an up-to-date list of subprocessors used in your environment, contact privacy@termharbor.com.

7. Cookies and analytics

TermHarbor uses cookies and similar technologies for essential session management, preferences, and limited aggregate analytics. We do not use cookies for cross-site advertising. For details on categories and choices, see our Cookie Policy.

8. Data retention

TermHarbor retains account, contract, usage, and communication records only as needed to provide the service, maintain security, meet legal obligations, and honor user-controlled deletion or export requests.

In practice, retention generally follows these categories:

  • Account data. Retained while your account is active. Deleted or anonymized after account closure, subject to legal and audit requirements.
  • Workspace and contract content. Retained for the life of the workspace and according to administrator-controlled retention settings, deletion requests, and legal-hold rules.
  • AI inputs and outputs. Retained alongside the contract or workflow they relate to, so reviewers can audit how a result was produced.
  • Logs and security records. Retained for a limited period needed to operate, debug, and protect the service.
  • Email events and consent records. Retained as needed to honor consent, suppression, and compliance obligations.
  • Contact form submissions. Retained as needed to respond to your inquiry and maintain a reasonable record of the conversation.

9. Security

We use reasonable administrative, technical, and organizational safeguards to protect information processed by TermHarbor, including:

  • Access controls. Role-based permissions and least-privilege access for internal systems.
  • Organization scoping. Workspace-level isolation of customer data so members only see content authorized for their workspace.
  • Encryption in transit. TLS for connections between your browser, the application, and supporting services.
  • Limited internal access. Access to production systems is restricted to a small set of personnel with a documented operational need.
  • Activity logging. Auditable records of meaningful actions where implemented, supporting investigation and review.
  • Secure integration handling. Credentials for connected services are stored server-side and never exposed to the browser.

No service can guarantee perfect security. Report suspected vulnerabilities to security@termharbor.com.

TermHarbor completed a SOC 2 Type II audit in March 2026. ISO 27001 is in progress and not yet certified. A DPA is available for GDPR and CCPA jurisdictions. We do not claim HIPAA or PCI compliance.

10. User rights and choices

Depending on your role and jurisdiction, you may be able to:

  • Access and update account data. Edit profile information from inside the application.
  • Delete account data. Request deletion of your account; workspace content is governed by your administrator and retention rules.
  • Export data. Use export controls where available, or contact us for assistance.
  • Manage email preferences. Update marketing preferences from the email preferences page.
  • Unsubscribe from marketing. Use the unsubscribe link in any marketing email or visit the preferences page.
  • Manage cookies. Adjust browser-level cookie settings; essential cookies are required for the service to function.
  • Contact privacy. Reach the privacy team at privacy@termharbor.com for any privacy-related request.

Manage email preferences: /email-preferences.

11. International users

TermHarbor is operated from the State of Texas, United States. If you access the service from another country, you understand that information may be processed in jurisdictions whose data protection rules differ from those of your home country. We take reasonable steps to apply appropriate safeguards in line with the practices described in this policy.

12. Children

TermHarbor is a business tool and is not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@termharbor.com so we can address it.

13. Changes to this policy

We may update this Privacy Policy as the product, our subprocessors, or applicable law evolve. When we make a material change, we will update the “Last updated” date above and, where appropriate, notify customers through the application or by email. Continued use of TermHarbor after an update means you accept the revised policy.

14. Contact

For privacy questions and requests: