Safe Clause

Legal

Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how Safe Clause (“we”, “us”, or “our”) collects, uses, shares, and protects information when you use our platform for AI-assisted, lawyer-certified contract drafting, review, and negotiation (the “Service”). We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, and authentication details, handled through our identity provider (Clerk), along with your role (client or lawyer).
  • Contracts and documents — the contracts, uploads, deal descriptions, concerns, and other materials you submit for drafting, review, countering, or certification.
  • Payment information — transaction details processed through our payment gateway (Cashfree). We do not store full card or bank account numbers on our servers.
  • Communications — messages exchanged between clients and lawyers through the Service, and any correspondence with our support team.
  • Usage and device data — analytics about how you interact with the Service, collected through our analytics provider (PostHog), and standard technical data such as IP address, browser type, and pages visited.

2. How we use your information

  • To provide, operate, and improve the Service, including generating, reviewing, and certifying contracts;
  • To facilitate communication between clients and reviewing lawyers;
  • To process payments and maintain records of transactions;
  • To authenticate users and secure accounts;
  • To understand usage and improve our features, performance, and reliability;
  • To communicate with you about your account, matters, and service-related updates; and
  • To comply with legal obligations and enforce our Terms of Use.

3. AI processing of your content

To generate drafts, analyses, recommendations, and counter-drafts, the contracts and descriptions you submit are sent to third-party AI providers for processing — currently via OpenRouter, using Google’s Gemini models. This processing occurs on their infrastructure. We select providers on the basis that submitted content is used to generate your output and is not used to train their foundation models, but you should avoid submitting information you do not wish to share with these processors. AI output may be inaccurate and should be treated as a draft until certified by a lawyer.

4. How we share information

We share information only as described below:

  • With reviewing lawyers — when you submit a matter for review, the relevant lawyer accesses your contract, documents, and related context in order to review and certify it.
  • With service providers (sub-processors) — who process data on our behalf to operate the Service, under contractual confidentiality and security obligations.
  • For legal reasons — where required by law, court order, or governmental authority, or to protect the rights, safety, and security of Safe Clause, our users, or the public.
  • In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell your personal data.

5. Service providers we use

  • Clerk — authentication and account management;
  • Neon — managed PostgreSQL database hosting;
  • EdgeStore — document and file storage;
  • Cashfree — payment processing;
  • OpenRouter and Google (Gemini) — AI processing;
  • PostHog — product analytics;
  • Vercel — application hosting and delivery.

6. Data storage and security

We use reasonable technical and organisational measures designed to protect your information, including encryption in transit, access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

7. Data retention

We retain your information for as long as your account is active and as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your data as described below; some information may be retained where required by law or for legitimate business records.

8. Your rights

Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access and obtain a summary of the personal data we hold about you;
  • Request correction or updating of inaccurate or incomplete data;
  • Request erasure of your personal data, subject to legal retention requirements;
  • Withdraw consent where processing is based on consent; and
  • Raise a grievance regarding our handling of your data.

To exercise these rights, contact us using the details below. We may need to verify your identity before acting on a request.

9. Cookies and analytics

We and our providers use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Service is used. You can control cookies through your browser settings, though disabling them may affect functionality.

10. International data transfers

Some of our service providers process and store data outside India. Where we transfer personal data internationally, we take steps intended to ensure it remains protected consistent with this Policy and applicable law.

11. Children

The Service is not directed to individuals under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.

13. Contact and grievances

For questions about this Policy, or to exercise your rights or raise a grievance regarding your personal data, contact our grievance contact at navis@deltaxy.ai. We will respond within the timelines required by applicable law.