Legal
Privacy Policy
Effective date: August 3, 2026 · TermsWatchdog by Barbieri Technology Group · © 2026 TermsWatchdog
1. Who We Are
TermsWatchdog is an independent AI transparency service operated by Barbieri Technology Group. We analyze publicly available terms of service, privacy policies, and data agreements for AI tools and present the results as plain-English transparency reports. We are not a law firm and do not provide legal advice.
Questions about this policy can be directed to barbieri.biz.
2. Information We Collect
2a. Information you provide voluntarily
- Email address — collected only if you choose to subscribe to notifications about a specific AI tool’s transparency report. This is entirely optional. You may skip this step at any time.
- Payment information — if you make a voluntary donation, payment is processed entirely by Stripe, Inc. We never see, store, or have access to your card number, billing address, or any other payment credentials. Stripe’s privacy policy governs that data.
2b. Information collected automatically
- IP address — recorded transiently in our rate-limiting system (Upstash Redis) to enforce a limit of 10 new analyses per IP address per hour. IP addresses are used solely for this purpose and are not stored in our primary database or linked to any profile.
- Standard server logs — our hosting provider (Vercel) collects standard HTTP request logs (URL, timestamp, response code, IP). These logs are retained per Vercel’s own data retention policies.
2c. What we do NOT collect
- We do not retain the files you upload. Documents submitted for analysis are parsed in memory, their text is sent to Anthropic for analysis, and both the file and the extracted text are discarded when the request completes. We never write uploaded files to disk or object storage. Only the resulting analysis and file metadata (filename, size, page count) are stored.
- No sensitive personal information. We do not collect or ask for any special-category data: no health or medical information, no biometric data, no government identification numbers, no financial account details, no precise geolocation, and nothing about your race, ethnicity, religion, political opinions, sexual orientation, or immigration status. We have no feature that would use it.
- No payment details. Card numbers and payment credentials go directly to Stripe and never reach our systems. We can see that a subscription exists and what it costs; we cannot see how you paid for it.
- No advertising, no profiling. We use no advertising trackers, no remarketing pixels, and no ad personalisation. We do not build behavioural profiles and we do not sell, rent, or trade personal data to any party.
- No content of uploaded documents. As above, uploaded files are discarded once analysed. Whatever personal or confidential information a document contains is not retained by us.
We do use one third-party analytics script — Google Analytics — to measure aggregate traffic. It is listed in section 4 alongside every other provider. It is configured for traffic measurement only and not for advertising, remarketing, or ad personalisation.
Accounts are optional for browsing public transparency cards, but are required for saved reports, team features, and document upload. Account holders are subject to the same data-handling practices as everyone else.
3. How We Use Your Information
- Email address: Used only to send you notifications when the transparency report for a specific AI tool you subscribed to is updated. We do not send marketing emails, newsletters, or share your address with third parties for any purpose.
- IP address: Used only to enforce hourly rate limits on new analyses. Not used for tracking, profiling, or any other purpose.
- Donation data: We retain a record of the transaction amount and date for internal accounting. No payment credentials are retained.
You keep ownership of what you submit. You retain all right, title, and interest in the search terms you enter and the documents you upload. Using this service does not transfer ownership of your content to us and does not affect any copyright or other right you hold in it.
We do not train AI models on your data. We do not use your search terms, your uploaded documents, or the text extracted from them to train, fine-tune, or improve any artificial intelligence or machine-learning model — our own or a third party’s. Anthropic, which provides the model that performs the analysis, states in its commercial API terms that it does not train on data submitted through the API; that commitment is Anthropic’s own, and we describe it here because we rely on it rather than because we can guarantee another company’s conduct.
We never sell or rent your personal data. We do not sell, rent, or trade personal data to anyone, and we do not share it with advertisers, data brokers, or for any advertising or profiling purpose. The providers listed in section 4 receive only what each needs to perform its function for us.
No one reads your uploaded documents. There is no human review step in the analysis pipeline, and because uploaded files are never written to storage there is no copy for anyone to open. Diagnostic error logs record the file name and any search term entered when a request fails, so faults can be investigated; those logs are deleted after 30 days and never contain document contents.
4. Third-Party Services
Operating this service requires us to share certain data with the following third-party providers. Each provider’s own privacy policy governs their handling of your data.
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude API) | AI analysis of policy text | Scraped public policy text, plus the text of any document you upload. Uploaded documents may contain personal or confidential data you choose to submit; do not upload material you are not permitted to share. |
| Firecrawl | Web scraping of public policy pages | Public URLs only — no personal data |
| Supabase | Database (transparency cards, accounts, reports) | Email addresses, account details, analysis results and uploaded-document metadata — never the uploaded files themselves |
| Upstash | Rate limiting | IP addresses (transient, not persisted to main DB) |
| Resend | Transactional email delivery | Email addresses |
| Stripe | Subscription and payment processing | Payment data, handled entirely by Stripe — card numbers never reach our systems |
| Vercel | Application hosting | Standard server request logs |
| Sentry | Error monitoring and diagnostics | Error messages and stack traces, the page being viewed, browser and device type, and IP address. Where a request fails during analysis, the search term entered or the file name of an upload — never the contents of an uploaded document. |
| Google Analytics | Aggregate traffic measurement | Pages viewed, referring site, approximate location derived from IP, browser and device type. Used to understand overall traffic patterns; not used for advertising, remarketing, or ad personalisation. |
5. Cookies and Local Storage
We do not use advertising or remarketing cookies, and we do not sell or share cookie data for advertising. The cookies we do set are these:
- Authentication cookies. If you create an account and sign in, our authentication provider sets cookies that keep you signed in. They are set only once you sign in, and are cleared when you sign out.
- Administrator session cookie. A short-lived, server-only cookie used exclusively for the password-protected administrator dashboard. It is never set for regular visitors and expires after 24 hours.
- Analytics cookies. Google Analytics sets cookies used to measure aggregate traffic, as described in the table above.
We also use your browser’s local storage to remember your risk-profile settings so the Service can apply them without an account. That data stays in your browser and is not transmitted to us unless you sign in and choose to save a profile.
6. Data Retention
- Email addresses: Retained until you request deletion.
- Transparency cards: Retained indefinitely as they are based on publicly available information. Cards are updated periodically as tool policies change.
- Uploaded documents: The files themselves are never stored. The analysis generated from them is retained for 365 days and then automatically deleted. You can delete any document report yourself at any time from your account.
- Error logs: Automatically deleted after 30 days.
- Rate-limit data (IP): Automatically expires within 1 hour.
- View analytics and feedback: Automatically deleted after 24 months.
These deletions run automatically on a daily schedule. They are not triggered by anyone logging in or opening a page.
Deletion on request. You can delete any uploaded-document report yourself at any time from your account. To delete your account and everything associated with it, email us: we will complete the deletion within 30 days and confirm when it is done.
7. Your Rights and Choices
- Unsubscribe / delete email: You may request removal of your email address from our subscriber list at any time by contacting us through barbieri.biz.
- Access / correction: You may request a copy of any personal data we hold about you or request correction of inaccurate information.
- Opt-out of notification emails: Each notification email includes an unsubscribe mechanism.
If you are a resident of the European Economic Area (EEA), United Kingdom, or California, additional rights may apply to you under the GDPR, UK GDPR, or CCPA respectively. Please contact us to exercise these rights.
8. Children’s Privacy
TermsWatchdog is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has submitted information to us, please contact us immediately.
9. Security
The technical safeguards in place include:
- Encryption in transit. All connections use HTTPS, with HTTP Strict Transport Security enforced.
- Encryption at rest. Our database provider encrypts stored data at rest.
- Row-level access control. Database access rules restrict each record to the account that owns it, enforced by the database itself rather than only by application code.
- Administrative access control. The admin dashboard is password-protected with constant-time credential comparison and rate-limited sign-in attempts.
- Abuse limits. Rate limiting on analysis, email, and sign-in endpoints, which fail closed — if the limiter is unavailable, the request is refused rather than allowed through unchecked.
- Browser hardening. A Content Security Policy, clickjacking protection, and MIME-sniffing protection are set on every page.
- Data minimisation as a control. The most reliable protection for an uploaded document is that we never store it.
What we do not have. We hold no third-party security certification — no SOC 2, ISO 27001, or ISO 42001 — and none is currently in progress. We do not run a bug bounty or commission regular third-party penetration tests. Our infrastructure providers maintain their own certifications, but that is their attestation and not ours, and we will not present it as though it were. We would rather tell you this plainly than describe our controls as audited when they are not.
Where your data is held. The service is hosted in the United States. Our database is provisioned in the AWS US East (N. Virginia) region, and the application runs on Vercel’s US infrastructure. Analysis requests are sent to Anthropic and Firecrawl, both US-based. If you are in the EEA or the UK, using the service involves a transfer of data to the United States; for Team and Enterprise customers those transfers are covered by the Standard Contractual Clauses in the Data Processing Agreement described in section 11.
If there is a breach. No system is perfectly secure. If we confirm a breach affecting your personal information, we will notify affected users within 72 hours of confirming it, and tell you what happened, what data was involved, and what we are doing about it — alongside any notification applicable law separately requires. To report a vulnerability, email hello@contact.termswatchdog.com.
10. Government and Legal Requests
We have never received a government or law enforcement request for user data. If we receive one, we will require valid legal process, disclose only the narrow set of data the request actually compels, and refuse requests that are overbroad or improperly served. Where we are lawfully permitted to tell you, we will notify you before disclosing your data so that you have an opportunity to object.
We hold very little that could be produced. Uploaded documents are never stored, so they cannot be disclosed to anyone. What exists is limited to account email addresses, the analyses generated for an account, and short-lived diagnostic logs.
11. Enterprise Customers and Data Processing Agreements
A Data Processing Agreement is available on request to customers on Team and Enterprise plans. It covers processing roles, the sub-processors listed in section 4, international transfer terms, security obligations, and breach notification timelines. Email hello@contact.termswatchdog.com to request one.
The data-handling practices described in this policy are the same for every plan. Paid plans unlock features — saved reports, team sharing, watchlists, document upload — but no plan grants us broader rights over your data, and no plan is subject to weaker protections. A free user’s uploads are handled exactly as an enterprise user’s are.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect the most recent revision. Continued use of the service after a change constitutes acceptance of the updated policy. For significant changes, we will make reasonable efforts to notify subscribers by email.
13. Contact
For privacy-related questions or requests, please contact Barbieri Technology Group through barbieri.biz.