Security

How we handle your data

No marketing spin. Here's exactly what happens to your files, where your data goes, and what we're still working on.

Quote files are read in memory and never stored. The extracted text is kept only until the Negotiation Playbook has been built, the deal closes or 90 days pass; the analysis itself stays until you delete it.

01

1. You Upload

We read the text from your PDF or image. The file is held in memory only.

02

2. AI Analyzes

Extracted text is sent to Anthropic's API over TLS for analysis.

03

3. File discarded

The original file is discarded when the request ends. It never reaches our database or storage.

Bottom line: Your original quote files are never stored. The extracted text is temporary; the analysis is yours until you delete it.

Encryption

In Transit

All data transmitted over TLS (HTTPS). This applies to file uploads, API calls to Anthropic, and all communication with Supabase and Vercel.

At Rest

Supabase encrypts all stored data with AES-256 encryption. This covers saved deal analyses, account data, and any metadata in our database.

File Deletion

Originals never stored

When you upload a quote, we read its text in memory and discard the file when the request ends. It is never written to a database or to storage. Our application logs record timings, sizes and a few top-level fields such as the vendor name and total, never the document text. If you ask TermLift to negotiate for you and attach a document, that file is stored with your consent and removed 30 days after the case closes, or 12 months after upload at the latest.

Extracted Text

Temporary, by design

The text extracted from your quote is stored with the deal so the Negotiation Playbook can be built later without a re-upload. It is not a permanent copy: it is removed once the Playbook is built, when the deal closes, or 90 days after upload at the latest. What stays is the AI-generated analysis, the structured deal facts (vendor, product, totals, term) and the outcome you record. You can delete any deal at any time.

Never Used for AI Training

Anthropic doesn't train on API data

We use Anthropic's API (Claude) for analysis. Anthropic's API terms explicitly state that data sent through the API is not used to train their models. Your contract text is not being fed into future AI models. We also don't use your data to train any models ourselves. Outcomes of closed negotiations may become de-identified benchmark rows (vendor, product, price, term, month of close), reviewed by a person and stripped of any account, deal or document reference. That is a pricing dataset, not training data, and the Privacy Policy describes it.

GDPR Compliance

Your rights are respected

We comply with GDPR. You can request access to your data, request deletion, correct inaccurate information, or export your data at any time. Email us and we'll handle it. Our database and file storage are hosted in the EU (Supabase, eu-west-1). Processing happens where our providers run: our application on Vercel in the US and AI analysis at Anthropic in the US, under Standard Contractual Clauses.

Our Infrastructure

Supabase — Auth & Database
Handles authentication and stores saved deal data. SOC 2 Type II certified. Data encrypted at rest with AES-256. EU-hosted infrastructure. Row Level Security (RLS) is enabled on every table in our database. It enforces account-level access controls at the database layer, so each query only returns the rows that belong to the signed-in account. That is an additional safeguard against cross-account access on top of the checks in the application itself.
Vercel — Hosting
Application hosting and edge functions. SOC 2 certified. Provides DDoS protection, automatic HTTPS, and edge caching. Our serverless functions run here, including the file processing and AI analysis endpoints.
Anthropic — AI Analysis
Extracted text is sent to Anthropic's Claude API for contract analysis. Anthropic does not use API data to train models. Data is transmitted over TLS and is not stored by Anthropic beyond their standard API log retention for abuse monitoring.

What We Don't Do

  • Sell your data to anyone — ever
  • Use your data for advertising or marketing profiles
  • Train AI models on your uploads or saved data
  • Store your original quote files
  • Share data with third parties beyond the services listed above
  • Access your saved deals, except to give support you ask for, to run a negotiation you requested, or to review a closed outcome for the de-identified benchmark described in the Privacy Policy

Being Honest: Limitations

In the interest of transparency, here is where TermLift’s security programme stands today:

  • Not SOC 2 certified. Our providers (Supabase, Vercel) are. TermLift has not yet completed its own certification.
  • No independent penetration test yet. Third-party testing is planned as the platform scales.
  • Not end-to-end encrypted. Data is encrypted in transit and at rest and access is restricted, but TermLift can read stored data server-side. That is what lets us provide support and run the negotiation service.

Security controls and independent testing will continue to mature as the platform scales. If you have specific requirements, ask and we will tell you plainly whether we meet them.

Questions?

If you have security concerns or questions about how we handle your data, we'd rather you ask than wonder.

Security questions:
hello@termlift.com
Privacy requests:
hello@termlift.com
General support:
hello@termlift.com

Ready to analyze your first contract?

Your quote files are never stored. Extracted text is temporary, and the analysis stays only as long as you keep the deal.