Privacy Policy

Plain English, not small print. Here's what Agreemnt actually collects, and what happens to it. Last updated: 18 September 2026.

The short version

Agreemnt reads the contracts you give it (uploaded, forwarded by email, or imported from a connected app) and uses AI to extract key dates and terms, so it can alert you before something needs action. We don't sell your data, we don't use tracking or advertising cookies, and we don't use your contract content to train anyone's AI models. Your contracts are only ever visible to people on your own team.

1. Who we are

Agreemnt (agreemnt.com, app.agreemnt.com) is operated by Agreemnt Ltd (company number 17439867), registered office at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. For any privacy question or to exercise your rights, contact privacy@agreemnt.com.

2. What we collect

Account and organisation data - name, work email address, and password (handled by our authentication provider, Supabase - we never see it in plain text) when you sign up; your organisation's name and the team members you invite.

Contract content - the documents you upload directly, forward by email to your organisation's inbound address, or import from a connected app; the structured data our AI extracts from them (parties, value, dates, notice periods, renewal terms, risk flags); and anything you type into the AI Q&A feature to ask questions about your contracts.

Billing data - if you're on a paid plan, your billing contact details and subscription status. Card details go straight to Stripe, our payment processor - we don't handle or store them ourselves.

Integration data - if you connect a document source (Google Drive, Gmail, Outlook, OneDrive, SharePoint, Box, or Dropbox), an access token that lets Agreemnt read the mailbox, files, or folders you've authorised - always read-only. If you connect an accounting system (Xero, QuickBooks, FreeAgent, or Sage) or a CRM (Pipedrive, HubSpot, or Zoho), an access token used only to read the specific records needed for reconciliation or context, again read-only. If you connect Juro, the API key you paste in yourself - rather than an access token from a consent screen - used only to read the contracts you already have there, again read-only; we never write anything back into your Juro account. These credentials are encrypted before storage and only decrypted, server-side, at the moment they're needed.

Data you choose to send elsewhere - if you generate an API key, configure an outbound webhook or chat alert, or approve an external AI assistant's connection to Agreemnt, contract data will flow to the destination or assistant you've configured, at the access level you choose. That's data you're directing outward yourself, not something we share on our own initiative - you're responsible for the destinations and assistants you choose to trust with it, and can revoke any of these at any time from Settings.

Technical data - standard web and application logs (such as IP address and browser type), kept only as long as needed for security and reliability.

We don't currently use any analytics or advertising tracking - see Cookies, below.

3. How your contract content gets processed

Whichever way a contract reaches Agreemnt, its content is sent to Anthropic's Claude API to extract the structured details you see in the app. Anthropic doesn't use data submitted through its API to train its models by default. If you ask the AI Q&A feature a question, that question (and the contract content needed to answer it) is likewise sent to Claude to generate a response.

Google API Limited Use disclosure: where content originates from a connected Google Workspace API (Drive or Gmail), Agreemnt's use and transfer of that data adheres to the Google API Services User Data Policy, including the Limited Use requirements. It's used only to power Agreemnt's own user-facing features - contract extraction and AI Q&A - is never used to develop, improve, or train Anthropic's or any other AI/ML model beyond generating your own requested response, and is never transferred to a third party for that purpose.

If you connect a document source, access is strictly read-only - Agreemnt only lists and downloads what you've chosen to share, and never modifies or deletes anything there. Disconnecting at any time (from Settings) stops all further access immediately; contracts already imported stay put.

Our Clause Checker and Contract Audit tools (app.agreemnt.com/clause-checker and /contract-audit) work the same way for anyone, account or not - whatever you paste or upload is sent to Claude to generate an assessment, but we don't store the content itself afterwards; we only log aggregate usage (not what you submitted) to monitor cost.

4. Why we process it (our lawful basis)

We process your account and contract data to perform our contract with you - i.e., to actually provide the service you've signed up for. Where we rely on legitimate interests instead (for example, security logging, or improving how extraction performs), we've weighed that against your rights and only do so where it doesn't override them. If we ever email you for marketing purposes, that will be based on your consent, and you can opt out at any time.

5. Who we share it with

We don't sell or rent your data. Within Agreemnt itself, only staff who need it to help with support - for example, investigating why a contract's extraction came out wrong - can see a summary of an organisation's contracts (titles, counterparties, values, and status, not the underlying files) through a separate, read-only internal tool. Every such access is logged. We don't read your contract content, or the files themselves, for any other reason.

We use the following sub-processors to run Agreemnt, each bound by a data processing agreement and only permitted to use your data on our instructions. This list covers services we use to run Agreemnt itself - not the destinations you might separately choose to send data to via API keys, webhooks, or an AI assistant connection (see “Data you choose to send elsewhere” in section 2 above), which are your own choice, not ours:

  • Supabase - our database, authentication, and file storage provider (hosted in London, UK).
  • Anthropic - processes contract content and Q&A questions to power AI extraction and answers (see section 3).
  • Stripe - processes subscription payments and stores your billing/card details.
  • Resend - sends transactional email (alerts, digests, account emails) and receives contracts forwarded to your inbound address.
  • Google - if you connect Drive or Gmail, to read the mailbox, files, or folders you've authorised.
  • Microsoft - if you connect Outlook, OneDrive, or SharePoint, to read the mailbox, files, or site you've authorised.
  • Box and Dropbox - if you connect either, to read the files you've authorised.
  • Xero, QuickBooks, FreeAgent, and Sage - if you connect one, to read payment records for reconciliation.
  • Pipedrive, HubSpot, and Zoho CRM - if you connect one, to read deal or company records for context on a contract.
  • Juro - if you connect it, to read the contracts you already have there and keep their details up to date on our side.
  • Vercel - hosts the application itself.

6. International transfers

Some of the providers above may process data outside the UK/EEA. Where that happens, we put an appropriate safeguard in place first - such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or the provider's own participation in a recognised transfer framework - before any data is transferred.

7. Cookies

Today, Agreemnt only sets cookies that are strictly necessary: one to keep you securely logged in (via Supabase Auth), and one that remembers your cookie preferences. We don't currently use advertising or analytics cookies. Necessary cookies like these don't legally require consent under UK rules - but the choice is there anyway: see “Cookie preferences” in Settings → Privacy, or the link in the footer of any page you're not signed in to see exactly what's set and why. If we ever add analytics or advertising cookies, you'll see a banner asking for your consent first, categorised the same way.

8. How long we keep it

We keep your account and contract data for as long as your account is active. If a contract is deleted, it's held briefly in case that was a mistake before being permanently removed. You can export a full copy of your organisation's data, or permanently delete your account and everything in it, at any time from Settings → Privacy (account owners only) - deletion cancels any subscription and removes your organisation's data immediately, except: a temporary recovery copy is kept for 30 days, accessible only to a company founder and solely to recover from an accidental deletion, then automatically and permanently removed; and billing records, which UK tax law requires providers to retain for six years.

9. Security

Every organisation's data is isolated at the database level (row-level security), original files are stored in access-controlled per-organisation storage, everything travels over HTTPS, and stored secrets like Drive tokens are encrypted at rest. See the Security page for the full detail.

10. Your rights

You can export your organisation's data or delete your account directly from Settings → Privacy at any time - see “How long we keep it”, above, for detail. For the deletion option if you're not the account owner, or for anything else below, email privacy@agreemnt.com. Under UK GDPR, you have the right to:

  • Ask what personal data we hold about you, and get a copy of it
  • Ask us to correct inaccurate data
  • Ask us to delete your data, or restrict or object to our processing it
  • Get your data in a portable format
  • Withdraw consent at any time, where we're relying on it
  • Complain to the Information Commissioner's Office (ICO) if you think we've got something wrong

To exercise any of these, email privacy@agreemnt.com.

11. Automated decisions

Our AI extracts details and flags things for your attention, but it doesn't make any decision about you or your organisation that has a legal or similarly significant effect without a person on your team reviewing it - Agreemnt surfaces information, you (or your team) decide what to do with it.

12. Children

Agreemnt is a business tool and isn't directed at, or intended for use by, anyone under 18.

13. Changes to this policy

We'll update this page as the product develops, and update the date at the top when we do. For a significant change, we'll also tell you directly.

14. Contact

Questions about this policy: privacy@agreemnt.com.