Privacy Policy

Last updated: August 1, 2026

ContractIQ (“we”, “us”) is operated by Synesthesia. This policy explains what we collect when you use ContractIQ, why we collect it, how long we keep it, and the choices you have. It applies to our website, our mobile application, and our API.

Information we collect

  • Account information. Your email address, and a password hash if you sign up with a password. If you sign in with Google, we receive your email address, name, and profile image from Google.
  • Contracts and documents you upload. The text of employment, locums, travel, or other agreements you submit for analysis, along with any metadata you provide (profession, state, contract type, compensation details).
  • Analysis output. The reports, risk scores, and negotiation guidance we generate from your documents, plus any annotations or comments you add.
  • Payment information. Payments are processed by Stripe. We store a Stripe customer identifier, subscription status, and payment records. We never receive or store your full card number.
  • Usage and security logs. Audit records of significant actions (uploads, analyses, deletions), rate-limiting counters, and coarse technical data such as IP address, used to operate and secure the service.

How we use your information

We use your information to analyze the contracts you submit, deliver and improve the service, process payments, send transactional messages you have asked for (analysis complete, contract expiry reminders, receipts), enforce plan limits, and protect the service against abuse. We do not sell your personal information, and we do not use your contracts for advertising.

AI processing and subprocessors

Contract analysis is performed using the Anthropic Claude API. When you request an analysis, the text of your document is transmitted to Anthropic for processing and the result is returned to us. We also rely on the following providers:

  • Anthropic — AI analysis of submitted contract text.
  • Vercel — application hosting and temporary file storage.
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Google — optional sign-in, if you choose it.

These providers process data on our behalf under their own terms and security commitments.

Security

Data is transmitted over HTTPS. Stored contract text is encrypted at rest using AES-256-GCM with a unique initialization vector per record, in addition to the storage encryption provided by our hosting and database providers. Access to production systems is restricted. No system can be guaranteed perfectly secure, and you should not upload documents containing information you are not permitted to share.

Retention and deletion

  • Uploaded documents and their analyses are automatically deleted 30 days after upload. We email you before a document is removed.
  • You can delete any individual document, or all of your documents, at any time from Settings.
  • You can permanently delete your entire account from Settings. Doing so removes your documents, reports, preferences, and profile, and cancels any active subscription. Limited payment and accounting records are retained where required by law.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. The deletion and export controls in Settings cover most of these requests directly. For anything else, contact us at support@contractiq360.com.

Children

ContractIQ is intended for practicing and training healthcare professionals and is not directed to anyone under 18. We do not knowingly collect information from children.

Changes to this policy

If we make material changes we will update the date above and, where appropriate, notify you in the app or by email.

Contact

Questions about this policy or your data: support@contractiq360.com.