Legal
Privacy Policy
Last updated 2026-07-13
This policy describes how Contract10 ("we", "us") collects, uses and protects information when you use our website, API and MCP server (the "Service"). Contract10 turns the executed contract youupload into a page-cited closing timeline. It is not a law firm, a broker or an escrow agent, and provides no legal advice.
Your uploaded contract is stored, not discarded
When you upload a contract, we store the PDF in a private storage bucket, scoped to your account by Postgres Row Level Security, at a path like contracts/<your account id>/<transaction id>/<file>.pdf. That's what lets a deadline in your timeline link straight back to the page it was read from. We don't use the content of contracts you upload to train models for other customers, and we don't sell your data. See our Security page for more detail.
Information we collect
- Account information, your name, email address and password (or sign-in provider identifier) when you create an account.
- Your contract, the PDF you upload for a transaction, stored in your private bucket until you delete the transaction or your account.
- Contract fields, the page-cited values the engine read off your contract (dates, periods, amounts), which you can review and correct.
- Deadlines, the dates the engine computed from those fields. These are recomputed automatically whenever an underlying field changes and are not stored as free-standing, hand-edited values.
- API usage data, the endpoints you call, timestamps, response status and call counts, used for rate limiting, billing and the inspectable request log in your dashboard. Your API key value itself is shown only once, at creation; you can rotate or revoke it at any time.
- Billing information, if you subscribe to a paid plan, payment is processed by Stripe; we store your plan, billing status and Stripe customer reference, never your full card number.
- API usage records, when you call the API with a key: the endpoint, the timestamp and the response status, so you can inspect what your own integrations did. We do not run product analytics, and we do not send your behaviour to a third-party monitoring service.
How we use your information
- To operate the Service: run contract extraction, compute closing timelines, enforce API rate limits and monthly call allowances.
- To send account and billing notifications (a password reset, a receipt).
- To process payments for paid plans via Stripe, and to meter usage-based API overage.
- To diagnose and fix bugs, and to understand which features are useful so we can improve them.
- To keep the Service secure and prevent abuse (including by automated/agent traffic).
We do not sell your personal information, and we do not use the contents of contracts you upload to train third-party models.
Data storage & security
Your account, transaction, contract-field, deadline and API usage data is stored in Supabase (Postgres and private storage), with access restricted to the systems and personnel that need it to operate the Service and scoped per account by Row Level Security. We use industry-standard transport encryption (HTTPS/TLS) for all data in transit.
Data retention & your choices
You can delete an individual transaction, which removes its stored contract PDF along with its fields and deadlines, revoke an API key, or delete your account at any time. If you close your account, we honor deletion requests and remove your account and transaction data within a reasonable period, except where we're required to retain billing records for tax or legal purposes.
Cookies & analytics
We use a small number of cookies required to keep you signed in. That is all. There is no analytics script on this site, no session recording, no advertising tracker, and no third-party tag of any kind. The free calculator runs entirely in your browser and sends us nothing.
Third parties
We share data with the vendors that operate the Service on our behalf: our database and storage provider (Supabase) and Stripe for billing, each bound to use it only to provide their service to us.
Children
The Service is intended for licensed real estate agents, transaction coordinators, and the businesses and agents building on top of them, and is not directed to, or knowingly used by, children under 16.
Changes to this policy
If we make a material change to this policy, we'll update the date above and, where appropriate, notify you by email.
Contact
Questions about this policy or your data, including requests to access, export or delete it, can be sent to hello@contract10.com.