Privacy Policy

Last updated: August 17, 2026

1. Our privacy posture, in one sentence

We do not store the original text or images of the documents you analyze. Once an analysis finishes, the source content is dropped from our servers and only the AI-generated plain-language summary is retained — and only if you choose to save it to your account history.

2. Information we collect

Document content you submit (transient). The text and images you paste or upload are sent to our AI provider for analysis. We hold them in memory only long enough to generate the analysis, then discard them. We do not write the original text or image bytes to our database or any log.

AI-generated summary (optional, opt-out per analysis). If you are signed in and leave “Save this to my history” checked, we store the AI’s output — purpose, key points, risks, deadlines, suggested actions and questions — so you can revisit it later. Uncheck the box to receive the analysis and have nothing about it written to our database. Signed-out users never have anything saved to history.

Account & billing information. If you create an account we store your email address and a hashed password. If you subscribe, we store a Paddle customer ID and subscription state. Payment card details are handled exclusively by Paddle and never touch our servers.

Usage events. We log basic usage events (analysis count, timestamps, error events, page paths) to enforce quotas, debug issues, and understand product use. These events do not contain document content.

Session cookies. A single first-party cookie keeps you signed in. We do not use third-party advertising or tracking cookies.

3. How we use your information

  • To generate document analyses and respond to your follow-up questions.
  • To enforce free-tier limits and manage paid subscriptions.
  • To monitor service health, detect abuse, and improve reliability.
  • To communicate with you about your account, billing, or service updates.

We do not sell your personal information, and we do not use the content of your documents to train AI models — ours or anyone else’s.

4. Third-party sub-processors

We share information only with the providers below, each used for a specific purpose necessary to run Understood. Document content you submit is sent only to our AI provider and is not retained. Other providers receive only the account, billing, or technical data needed for their role.

  • Lovable AI GatewayOur artificial-intelligence provider. The text and images you submit are sent to it to generate the plain-language analysis and to answer your follow-up questions. The AI provider processes the content to produce the response and does not retain it for training.
  • Lovable Cloud (Supabase)Our database and authentication provider. Hosts your account, saved analyses, and subscription state, and sends sign-in, verification, and password-reset emails. Card numbers are never stored here.
  • CloudflareOur hosting and edge-runtime provider. Serves the website and runs our application code close to you for speed and availability.
  • PaddleOur Merchant of Record for payments. Handles checkout, card processing, invoicing, tax compliance, and subscription management. We never see or store your full card number.

We may also share information with professional advisers such as accountants and lawyers, and with authorities where the law requires it. We do not sell your information.

5. Retention

  • Original document text and images: not retained. Dropped at the end of the request.
  • AI-generated summaries: retained only when you opt in. You can delete any individual summary from your history at any time, or delete your entire account to remove all of them at once.
  • Account & billing data: retained while your account is active. Removed when you delete your account, subject to short retention for legal, tax, and fraud-prevention obligations on Paddle’s side.
  • Usage events: retained for up to 12 months for operational analytics, then aggregated or deleted.

6. Data security

All traffic is encrypted in transit (HTTPS/TLS). Passwords are hashed by our authentication provider. Production databases are operated by Lovable Cloud (Supabase) with encryption at rest. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your rights

You may at any time:

  • Delete individual analyses from your history.
  • Delete your entire account from the account menu — this cascades to remove your saved analyses and authentication tokens.
  • Cancel your subscription via the Paddle Customer Portal.
  • Request a copy of the data we hold about you by emailing us.
  • Object to processing or request restriction of processing.

Residents of the EU/UK (GDPR) and California (CCPA/CPRA) have additional statutory rights under their respective laws, including the right to lodge a complaint with a supervisory authority.

8. Children’s privacy

Understood is not directed to children under 13 and we do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will delete it.

9. International transfers

Our infrastructure is operated primarily in the United States. By using the Service from outside the United States, you consent to the transfer of your information to the United States and other jurisdictions where our sub-processors operate.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice or email, and the “Last updated” date above will reflect the revision.

11. Contact

SBK Publishing LLC, which operates Understood, is the data controller for the information described here. Privacy questions, data requests, or deletion requests? support@getunderstood.app.