Privacy PolicyTerms of Service

Privacy Policy

Last updated: April 27, 2026Version 1.0

This Privacy Policy describes how PolicyPen (“we,” “us,” or “our”) collects, uses, and shares information about you when you visit policypen.io and use our AI-powered policy generation service (the “Service”). By using the Service you agree to the practices described in this policy.

1. Who We Are

PolicyPen is an independent SaaS product. For questions about this policy, contact us at hello@policypen.io.

2. Information We Collect

Account information

We use Clerk for authentication. When you sign up, Clerk collects your email address, name, and (if you use OAuth) your Google or GitHub profile. We receive and store your Clerk user ID, email address, and display name in our database to identify your account.

Policy and product data

We store the information you provide when creating products and generating policies — including product names, website URLs, business descriptions, jurisdiction selections, and the questionnaire answers you submit. Generated policy content (HTML text) is stored in our database linked to your account.

Payment information

We use Dodo Payments to process subscriptions. Your payment card details are collected and stored by Dodo Payments — we never see or store your full card number. We receive billing events (subscription created, renewed, cancelled) and store your Dodo customer and subscription IDs for plan management.

Usage data

We track token usage per month (to enforce free plan limits) and count policy generations and products created. We do not sell this data or use it for advertising.

Log and technical data

Our infrastructure (Vercel) automatically collects standard web server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for security, debugging, and performance monitoring and is retained according to Vercel’s data retention policies.

3. How We Use Your Information

  • Provide and operate the Service (generate policies, host policy pages, manage your account)
  • Process payments and manage your subscription
  • Send transactional emails (sign-up confirmation, payment receipts, law update notifications)
  • Enforce free plan usage limits
  • Diagnose bugs and improve performance
  • Comply with legal obligations

We do not use your policy content to train AI models. Prompts and content are sent to Anthropic’s Claude API solely to generate your requested documents; Anthropic’s data usage policies apply to that processing.

4. Third-Party Services

We share data with the following sub-processors to operate the Service:

  • Clerk (clerk.com) — authentication and session management
  • Supabase (supabase.com) — database and file storage
  • Anthropic (anthropic.com) — AI policy generation via the Claude API
  • Dodo Payments (dodopayments.com) — subscription billing
  • Vercel (vercel.com) — hosting, edge network, serverless functions
  • Resend (resend.com) — transactional email delivery

Each of these providers has their own privacy policy governing their use of data. We encourage you to review them. We do not share your personal data with any advertising networks or data brokers.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data and policy content within 30 days, except where retention is required by law (for example, billing records may be retained for up to 7 years for tax purposes).

You may request deletion of your data at any time by emailing hello@policypen.io.

6. Cookies

We use cookies solely for authentication (Clerk session cookies) and to remember your preferences. We do not use advertising or third-party tracking cookies. Your browser can be configured to reject cookies, though this will prevent you from staying signed in.

7. Your Rights

Regardless of where you are located, you may contact us at any time to:

  • Access the personal data we hold about you
  • Correct inaccurate information
  • Request deletion of your account and data
  • Export your policy content (available via the dashboard export feature)
  • Opt out of marketing emails (unsubscribe link in every email)

EU and UK users (GDPR / UK GDPR)

Our lawful basis for processing is performance of a contract (operating the Service for you) and legitimate interests (security, abuse prevention). For marketing emails, we rely on your consent. You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK).

California residents (CCPA / CPRA)

We do not sell or share your personal information with third parties for advertising purposes. You have the right to know, access, correct, and delete your personal information. To exercise these rights, email hello@policypen.io.

8. Security

We use industry-standard measures to protect your data: TLS encryption in transit, encrypted database storage via Supabase, Row Level Security (RLS) policies ensuring each user can only access their own data, and Clerk’s battle-tested authentication infrastructure. No method of internet transmission is 100% secure, and we cannot guarantee absolute security.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a minor has created an account, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the change takes effect. The “Last updated” date at the top of this page will always reflect the most recent revision.

11. Contact

Questions or concerns about this policy? Email us at hello@policypen.io. We respond within 5 business days.

PolicyPen — AI-powered legal policies for indie makers.