On Your Terms
Home / Legal

Privacy Policy

Last updated June 30, 2026

1. Who we are

On Your Terms, Inc. ("On Your Terms", "we", "us", "our") provides AI-assisted legal infrastructure for websites and digital products. Our service scans your site, generates draft privacy policies, terms, and related legal documents, and monitors for policy drift.

We are the data controller for personal information we collect about visitors to onyourterms.app and account holders of the On Your Terms platform.

Contact: legal@onyourterms.app EU/UK Representative: appointed when applicable — contact us for current details.

2. What this policy covers

This Privacy Policy applies to personal information processed through:

  • our marketing website and product pages;
  • our authenticated platform (the "Service");
  • email and support communications with us.

It does not apply to third-party services you connect to On Your Terms, or to legal documents you generate for your own users (you control those).

3. Personal information we collect

CategoryExamplesSource
Account dataname, email, password hash, organizationyou, when you sign up
Authentication dataOAuth identifiers from Google sign-inGoogle (if you choose Google sign-in)
Site & scan datadomains you register, scan results, detected third-party scripts, generated policy textyou, plus public-facing HTML of sites you authorize us to scan
AI prompts & outputsthe business context you submit, the drafts our model returnsyou and our AI provider
Usage datapages viewed, features used, API calls, error logs, IP, user-agent, approximate location derived from IPautomatic
Cookies & devicesession and security cookies, device identifiers — see our Cookie Policyautomatic
Support & commsmessages you send to support, survey responsesyou
Payment data (when applicable)last 4 digits, billing zip, processor token — full card details are handled by StripeStripe (we do not see full card numbers)

We do not knowingly collect special-category personal data (health, biometric, etc.) and ask you not to submit it.

4. How we use personal information and our legal bases (GDPR)

PurposeLegal basis
Create and operate your account; provide the ServiceContract (Art. 6(1)(b))
Run site scans you initiateContract
Generate policy drafts with AIContract
Detect abuse, secure the Service, prevent fraudLegitimate interests (Art. 6(1)(f)) — keeping the Service safe
Send service emails (security, billing, important changes)Contract / legal obligation
Send product updates and marketingConsent (you can opt out at any time)
Comply with law, respond to lawful requestsLegal obligation (Art. 6(1)(c))
Improve the Service through aggregated analyticsLegitimate interests
Defend, exercise or establish legal claimsLegitimate interests / legal obligation

We do not use your prompts or generated documents to train base AI models.

5. Automated decision-making

The Service uses AI to generate drafts and surface alerts. These are advisory — humans (you and your counsel) make the final decision. We do not make decisions with legal or similarly significant effects on you solely by automated means.

6. Who we share personal information with

We share personal information only with:

  • Sub-processors acting on our instructions under written agreements:
    • Lovable Cloud (managed Supabase) — application database, authentication, file storage, hosting infrastructure.
    • Lovable AI Gateway routing to Google Gemini — AI generation of policy drafts.
    • Email delivery, payment, and analytics providers — added as we adopt them; see our current sub-processor list.
  • Professional advisors — lawyers, auditors, accountants under confidentiality.
  • Authorities — when required by law, court order, or to defend our legal rights.
  • Successors — in a merger, acquisition, or asset sale, with prior notice where required.

We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

7. International data transfers

We are based in the United States. Where we transfer personal information from the EEA, UK, or Switzerland to the US or another country, we rely on:

  • the European Commission's Standard Contractual Clauses (2021/914);
  • the UK International Data Transfer Addendum;
  • the EU–US Data Privacy Framework where our sub-processors are certified;
  • supplementary measures (encryption in transit and at rest, access controls, vendor due-diligence).

A copy of the SCCs is available on request.

8. How long we keep personal information

CategoryRetention
Active account & profilefor the life of the account
Site scans & generated draftsfor the life of the account, or until you delete them
Audit logs24 months from event
Support communications24 months from last contact
Billing & tax records7 years (legal obligation)
Backupsrolling 30 days, then overwritten

When you delete your account, we delete personal information within 30 days, except where law requires retention.

9. Security

We use technical and organizational measures including TLS in transit, encryption at rest, role-based access, principle-of-least-privilege, multi-factor authentication for staff, regular dependency and infrastructure patching, audit logging, and incident response procedures. No method of transmission or storage is 100% secure.

If we become aware of a personal data breach affecting you, we will notify you and competent authorities as required by applicable law (within 72 hours under GDPR Art. 33).

10. Your rights

EEA / UK / Switzerland (GDPR / UK GDPR / FADP). You have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection (including to direct marketing), withdraw consent at any time, and lodge a complaint with a supervisory authority (e.g. your national DPA, or the UK ICO at ico.org.uk).

California (CCPA/CPRA). You have the right to know, delete, correct, and limit use of sensitive personal information, to opt out of "sale" or "sharing" (we do neither), and to be free from discrimination for exercising your rights. Authorized agents may submit requests on your behalf with proof of authorization.

Other jurisdictions. Where local law grants similar rights (e.g. Brazil LGPD, Canada PIPEDA, Australia Privacy Act, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA), we honor them.

To exercise any right, email legal@onyourterms.app or use the tools in your account. We will respond within the timeframe required by the applicable law (generally 30 days under GDPR; 45 days under CCPA, extendable by 45). We may need to verify your identity.

11. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Cookies and similar technologies

See our separate Cookie Policy for a description of cookies we use, their purpose, duration, and how to manage your preferences.

13. Do Not Track and Global Privacy Control

We honor the Global Privacy Control (GPC) signal as an opt-out request under California law. Most browsers do not implement DNT consistently, and we do not change behavior based on DNT signals alone.

14. Changes to this Privacy Policy

We may update this policy from time to time. Material changes will be notified by email and by a prominent notice on the Service at least 7 days before they take effect. The "Last updated" date at the top reflects the most recent change.

15. How to contact us

Important Notice

This document was drafted with care for On Your Terms' own service. It is not legal advice for your business. If you operate a website or digital product, generate your own Privacy Policy in the On Your Terms platform and have qualified counsel review it before publishing.