In shortPolicy Pal receives only the document you ask it to analyze. It never receives your browsing history, and there is no account attached to you.
We read fine print for a living. Ours should be easy to check.
What we collect
When you choose Analyze this policy, we receive the page URL and the text of that policy. We do not receive your browsing history, pages you did not submit, passwords, or browser credentials.
Who you are to us
There is no Policy Pal account. On your first analysis, our server creates a random installation token and stores it in your browser. We keep only a one-way hash of the token. A subscription can link that installation to an opaque Stripe customer identifier.
Where policy text goes
Our server sends the policy text to one configured analysis provider and may try one fallback if the first provider fails or cannot ground the report. The current configuration may use OpenAI or Google Gemini. Provider retention settings are configured for the selected API account.
What we keep
We cache reports for published policies by document content. This lets another reader of the same public document get an instant result. The cached report contains the policy’s own text and analysis, not your identity.
Email and payment
We receive an email only if you subscribe. Stripe provides it, and we use it only to let you restore the subscription in another browser. We store only a keyed hash of the normalized address. Amazon SES delivers the six-digit restore code. Stripe processes payment details. Policy Pal does not receive your full card number.
Website and extension analytics
The Policy Pal website uses cookieless Google Analytics to count page visits, understand which campaigns bring people to the site, and measure clicks through to the browser store. Analytics storage, advertising storage, Google Signals, and ad personalisation are disabled. We send the page path and permitted campaign tags, but not policy text, email addresses, checkout details, or the pages you ask the extension to analyze.
The extension does not load third-party product analytics code. Its server reports first activation, successful analysis, checkout started, retained purchase, and subscription restored to a separate Google Analytics property. A random installation identifier groups repeat use. The event fields are limited to plan, cache status, currency, published price, and an irreversible transaction deduplication value. We do not send policy text, evidence, page titles, visited URLs, email, restore codes, installation tokens, Stripe identifiers, or model requests and responses.
Operational logs
We keep short-lived operational logs for request status, timing, provider category, and quote-verification rate. The logs do not contain policy text, URLs, evidence quotes, email addresses, restore codes, installation tokens, Stripe payloads, or model responses.
Sentry receives production error reports from the website, extension, and server. We remove page and request URLs, user fields, breadcrumbs, arbitrary context, local variables, and error messages before delivery. Reports retain the error type, code location, app release, browser target, and a bounded request reference where available. Firefox asks separately whether to allow this optional technical and interaction data; declining does not limit the extension.
Delete everything
The primary route is in the Policy Pal panel footer. Choose Delete everything and confirm. Policy Pal expires open checkouts, cancels incomplete subscriptions immediately, schedules every other live subscription to end after its paid period, then clears the installation token, usage, email hash, restore state, subscription link, and locally saved reports. Server-cached reports for published documents remain because they contain no personal data.
You can also email [email protected]. If a subscription is involved, we will verify you through the restore-code flow before acting.
Security and processors
Cloudflare provides server functions and the D1 database. Stripe provides billing. Amazon SES delivers restore mail. Google provides cookieless website analytics and the bounded extension events described above. Sentry provides privacy-filtered error monitoring. OpenAI or Google may provide an analysis.
Questions
Email [email protected]. We will update the date above when this policy changes.