Legal Document

Privacy Policy

Drafted: 27 August 2026 · Not yet in force · MossMoor Ltd

Draft — pending legal review

This document has been drafted to describe how ClausesGuard actually works, but it has not yet been reviewed by a qualified lawyer and is not yet in force. Do not rely on it. It must be reviewed and approved before the Service accepts paying customers.

The short version. Your uploaded file never leaves your browser — we only receive the text extracted from it. We send that text to our AI provider to produce your analysis, and we do not keep the text afterwards. We do keep the analysis it produced (the risk score, summary and clause breakdown) and any draft agreements, so you can find them again. Nothing you submit is used to train AI models.
01

Who is responsible for your data

MossMoor Ltd, registered in Nigeria under the Companies and Allied Matters Act and trading as ClausesGuard, is the data controller for the personal data described here.

Contact for privacy matters: privacy@clausesguard.com.

02

What we collect

CategoryWhat it includesWhere it comes from
AccountName, email address, authentication identifierYou, via Clerk sign-up
Plan and usagePlan tier, plan status, number of analyses and drafts used this period, period start date, billing currencyGenerated as you use the Service
PaymentPaystack customer and subscription references, transaction reference, amount, currency, status, payment datePaystack. We never receive your card number
Contract textThe text you paste, or text extracted in your browser from a file you uploadYou
Analysis resultsDocument name you gave it, risk score, risk level, plain-English summary, clause breakdown with explanations and suggestionsGenerated by our AI provider from your Input
DraftsDocument name, full agreement text, language, jurisdiction, template typeGenerated for you, plus any edits you make
WaitlistEmail address and optional name, if you use the sign-up form on our home pageYou
TechnicalIP address, browser type, request logs, error reportsAutomatically, via our hosting provider

We do not ask for and do not want special category data (health, biometric, political, religious and similar). Please do not upload documents containing it.

03

Your contract text — exactly what happens

This section corrects an earlier, less precise description. Please read it rather than assume.
  • If you upload a PDF or Word file, it is parsed inside your own browser. The file itself is never transmitted to us or stored on our servers.
  • The extracted text — or text you paste directly — is sent to our servers, then to OpenRouter, which routes it to the AI model provider that generates your analysis or draft. Both are listed as processors in section 06.
  • We do not store the contract text itself after the request completes. It is not written to our database.
  • We DO store what the AI produced from it: the document name, risk score, risk level, plain-English summary, and the full clause breakdown including explanations and negotiation suggestions. This is substantive content derived from your contract, not merely metadata.
  • For drafting, we store the complete text of the agreement generated for you, including any edits you save.
  • Long documents are reviewed in sections rather than truncated. Each section is a separate request to our AI provider. The number of sections is capped by your plan, and the Service reports how much of the document was reviewed.
  • Nothing you submit is used to train AI models — ours or our providers’. This is a contractual requirement on our AI provider, not just our own policy.

You can delete any individual analysis or draft from the Documents area at any time, which removes it from our database.

04

Why we process it, and our lawful basis

For users in the EU, UK and other jurisdictions applying a lawful-basis requirement:

PurposeLawful basis
Creating and running your account; producing the analyses and drafts you ask forPerformance of a contract (GDPR Art. 6(1)(b))
Taking payment, invoicing, handling refunds and chargebacksPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Enforcing usage limits and preventing abuse of the free planLegitimate interests (Art. 6(1)(f))
Security monitoring, error logging and fraud preventionLegitimate interests (Art. 6(1)(f))
Keeping accounting and tax recordsLegal obligation (Art. 6(1)(c))
Adding you to the waitlist, and service emails about your accountConsent for the waitlist (Art. 6(1)(a)); contract for service emails

Where we rely on consent you may withdraw it at any time. Where we rely on legitimate interests you may object, and we will stop unless we have overriding grounds.

05

Automated processing and AI

The analysis, risk score and drafts are produced by an AI model without human review. This is the core function of the Service and is what you are asking us to do.

We do not use this processing to make any decision that has a legal effect on you or similarly significantly affects you within the meaning of Article 22 GDPR — the Output is information for you to act on, and every decision about your contracts remains yours. We do not use automated profiling for credit, employment, insurance or eligibility decisions.

06

Who we share it with

We do not sell personal data and we do not share it for advertising. We use the following processors, each under a written data processing agreement:

ProviderRoleWhat it receives
OpenRouterAI routingYour contract text or drafting instructions, for the duration of the request, passed on to a model provider below
GoogleAI processing (via OpenRouter)Your contract text or drafting instructions, for the duration of the request
AnthropicAI processing (via OpenRouter), used as a fallbackYour contract text or drafting instructions, for the duration of the request
ClerkAuthenticationName, email, authentication and session data
PaystackPaymentsEmail address and transaction data. Card details go directly to Paystack
SupabaseDatabase hostingAll stored account, usage, analysis, draft and payment records
VercelApplication hosting and logsRequest data, IP address, error reports

We may also disclose data where legally required, to establish or defend legal claims, or to a successor entity on a merger or sale of the business (in which case we will tell you).

07

Where your data is stored and international transfers

Our database is hosted in the European Union (Ireland, eu-west-1). Application hosting and AI processing may take place in the United States and other countries.

This means personal data is transferred out of Nigeria, and out of the EEA and UK, to countries that may not have been assessed as providing an equivalent level of protection. For transfers from the EEA and UK we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, plus supplementary technical measures including encryption in transit and at rest.

You can request a copy of the transfer mechanism we rely on for any given provider.

08

How long we keep it

DataRetention
Contract text you submitNot retained. Discarded once the request completes
Analyses and draftsUntil you delete them, or 12 months after your account is closed
Account and profileFor the life of the account, then 30 days after a deletion request
Payment and transaction records7 years from the transaction, to meet accounting and tax obligations
Waitlist entries24 months, or until you ask to be removed
Security and error logs90 days
BackupsUp to 30 days after deletion from the live database

Where we must keep a record for accounting reasons we keep only what is necessary for that purpose and stop using it for anything else.

09

Security

  • Encryption in transit (TLS) and at rest for stored records.
  • Authentication and session management delegated to a specialist provider (Clerk); we never store passwords.
  • Card data never touches our systems — payments are handled entirely by Paystack.
  • Uploaded files are parsed in your browser, so the original document is never stored on our infrastructure.
  • Access to production data is limited to personnel who need it, and payment webhooks are cryptographically signature-verified.

No system is perfectly secure. We cannot guarantee absolute security, and you share information with us on that understanding.

10

If something goes wrong — breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it. Where the risk to you is high we will notify you directly and without undue delay, and tell you what happened, what data was involved and what to do.

11

Your rights

Depending on where you live, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted, subject to records we must keep by law.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time.
  • Human review — ask a person to look at anything you believe the Service got wrong.
  • Complain — to your data protection authority (see clause 13).

These rights arise under the Nigeria Data Protection Act and, where they apply to you, the EU GDPR and UK GDPR.

12

How to exercise your rights

You can do some of this yourself, immediately:

  • Delete an individual analysis or draft — from the Documents area of your dashboard.
  • Correct your name or email — through your account settings.
  • Stop future billing — cancel from Billing in your dashboard.

For anything else — a full copy of your data, deletion of your whole account, restriction, or objection — email privacy@clausesguard.com. We will acknowledge within 7 days and respond substantively within 30 days. We may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

13

Complaints

Please raise it with us first — we would rather fix it. You also have the right to complain to a supervisory authority:

  • Nigeria — Nigeria Data Protection Commission (ndpc.gov.ng).
  • United Kingdom — Information Commissioner’s Office (ico.org.uk).
  • EEA — the data protection authority of your country of residence or workplace.
14

Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.

15

Cookies

See our Cookie Policy. In short: we set only the cookies strictly necessary to keep you signed in, and we run no advertising or analytics trackers.

16

Changes to this policy

We may update this policy. For changes that materially affect how we use your data we will give at least 30 days’ notice by email or in-app notice. The version and its date always appear at the top of this page.

MossMoor Ltd (trading as ClausesGuard)

Registered in Nigeria under the Companies and Allied Matters Act

⚖️ privacy@clausesguard.com

📧 hello@clausesguard.com