Your Privacy Matters
Last Updated: July 13, 2026
Termwise (operated by Termwise) is the data fiduciary for personal data processed through termwise.ai. This Privacy Policy explains how we collect, use, store, and protect your data when you use our digital agreement analysis platform, including obligations under India's Digital Personal Data Protection Act, 2023 (DPDPA), and related principles under GDPR and CCPA where applicable.
Information We Collect
Personal Information
- • Name, email address, and contact information you provide
- • Year of birth only (not full date of birth), used solely for age verification (18+)
- • User account information and privacy preferences
- • Payment and billing information (processed securely through third-party payment providers)
- • Document text, URLs, or files you submit for analysis (sent to our servers and AI processors solely to produce a risk analysis)
Usage Information
- • Product usage signals you opt into (anonymous insights to improve Termwise — no ad trackers)
- • Analysis results and risk assessments stored in your account history
- • Device and browser details needed for authentication and product function
- • Cookies and local storage required for session, security, and consent records
We do not collect IP addresses or geolocation for analytics, profiling, or advertising. Transient network identifiers may be used in memory only for rate limiting and abuse prevention, and are not stored in your account.
How We Use Your Information
We use your information to:
- • Provide and improve our digital agreement analysis services
- • Analyze terms and conditions, privacy policies, and other digital agreements using AI
- • Deliver risk assessments and recommendations for documents you submit
- • Communicate important updates and security alerts you have opted into
- • Process payments and manage subscriptions
- • Ensure platform security and prevent fraud
- • Comply with legal obligations, including DPDPA
AI Document Analysis & Third-Party Processors
Document analysis is opt-in. Before your first analysis, we ask you to confirm that document text may be processed as described below. You can enable or disable this anytime in Settings → Privacy & data.
- • When you analyze a document, its text is transmitted to Termwise servers and may be processed by an AI language-model provider (for example OpenAI, or another configured openai-compatible endpoint) solely to produce a risk analysis
- • We require contractual safeguards with LLM providers: purpose limitation (analysis only), confidentiality, and no use of your content for model training where the provider allows opt-out
- • LLM providers may process content outside India; we apply transfer safeguards consistent with DPDPA Section 16
- • We do not sell your personal information or document content
Processing, Storage & Sharing
Beyond AI analysis (above), we handle your data as follows:
- • Analysis metadata (summaries, risk findings) may be stored in your account for dashboard history
- • Raw document text is encrypted at rest (AES-256-GCM) on our servers, retained for up to 90 days, then automatically purged; risk metadata may be kept longer for your account history until you delete it or your account
- • LLM subprocessors are used only when you have opted in to document analysis; we require contractual safeguards and purpose limitation (analysis only; not for model training where the provider allows opt-out)
- • We share personal data with contracted processors who help us operate the service (hosting, storage, payments, AI analysis) under confidentiality and data-processing terms — not for their own marketing
- • We may disclose information when required by law or to protect our rights and users
- • Core processors typically include cloud database/storage providers, our LLM provider, and payment processors — contact us for a current list
Data Security
We implement security measures including:
- • Encryption of data in transit (TLS) and encryption of stored analysis document text at rest
- • Regular security reviews and access controls
- • Restricted access to personal information on a need-to-know basis
- • Rate limiting and safeguards on analysis endpoints
- • Incident response procedures aligned with DPDPA Section 8(6)
Your Rights (DPDPA)
As a data principal you may exercise the following rights from Settings → Privacy & data when signed in. We aim to respond within 72 hours for access/export and erasure requests where technically feasible:
- • Access and review your personal information
- • Request corrections to inaccurate profile data
- • Download a structured export of your personal data (Section 11)
- • Delete your account and associated data (Section 12) — permanent hard delete
- • Opt-out of non-essential communications via notification preferences
- • Withdraw consent for optional processing (AI analysis, email updates, product insights) at any time
Cookies & Preferences
We use cookies and local storage as needed for authentication, security, and product function. You can manage optional preferences (document analysis, email updates, risk alerts, product insights) in Settings or via our first-visit privacy dialog. Disabling essential storage may prevent sign-in and core features from working.
Children's Privacy
Under India's DPDPA, a child is a person under 18 years of age. Termwise does not knowingly create accounts for users under 18. Registration requires year of birth and confirmation that you are 18 or older. We do not offer a parental-consent pathway for under-18 accounts at this time.
International Data Transfers
Primary application data is stored with providers configured for India regions where available. Document text sent for AI analysis may be processed by subprocessors outside India (such as OpenAI). We apply contractual and technical safeguards for such transfers consistent with DPDPA Section 16.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above. Continued use of Termwise after changes constitutes notice of the updated policy; for significant changes we may also notify you by email when appropriate.
Contact & Grievance Officer
For privacy-related questions, grievances, or to exercise your rights, contact our Grievance Officer:
Harsh Vitra · Termwise