RedFlag
← Back to Home

Privacy Policy

Effective: April 17, 2026

RedFlag ("we", "us", "our") operates the website rfdocs.net and associated mobile applications. This Privacy Policy explains how we collect, use, and protect your information when you use our services.

1. Information We Collect

Account information: When you create an account, we collect your email address and an encrypted password. We do not collect your name, phone number, or physical address unless you voluntarily provide it.

Contract text and photos: When you scan a contract, you submit text (pasted, uploaded, or photographed) to our servers for analysis. We process this content to return your analysis results.

Payment information: If you subscribe to Pro, payment is processed by Stripe. We do not store your credit card number, bank account, or full payment details on our servers. Stripe handles all payment data under their own privacy policy.

Usage data: We collect basic analytics (pages visited, features used, scan count) to improve the product. We do not use third-party ad trackers.

2. How We Use Your Information

  • To analyze contracts you submit and return results
  • To cache analysis results so identical contracts return faster results
  • To maintain your account and subscription
  • To improve RedFlag's analysis quality and user experience
  • To send transactional emails (account confirmation, password reset, subscription receipts)

3. How We Handle Contract Text

Contract text you submit is sent to Anthropic's Claude AI for analysis. The text is used solely to generate your analysis and is not used to train AI models. Analyzed contracts are cached using a one-way hash (SHA-256) of the normalized text so that identical contracts return identical results without re-analysis. The cached results contain the analysis output, not your original contract text.

Photo-based scans are processed the same way: your photos are sent to the AI for reading and analysis, then discarded after the analysis is returned. Photos are not stored on our servers.

4. Data Storage and Security

Your account data and scan history are stored in Supabase (hosted on AWS). All data is encrypted in transit (TLS) and at rest. We use Row Level Security to ensure users can only access their own data.

We retain your scan history for as long as your account is active. Pro users can view their last 15 scans. If you delete your account, your scan history is deleted.

5. What We Never Do

  • We never sell your data to third parties
  • We never share your contract text with advertisers
  • We never use your contract text for AI training
  • We never display ads in our product
  • We never contact you with marketing emails unless you opt in

6. Third-Party Services

We use the following third-party services that may process your data under their own privacy policies:

  • Anthropic (Claude AI) — contract analysis
  • Supabase — authentication and data storage
  • Stripe — payment processing
  • Netlify — website hosting and serverless functions
  • Google Analytics — anonymous usage analytics

7. Your Rights

You can request a copy of your data, request deletion of your account and all associated data, or update your email address at any time by contacting us at david@prospectpages.college.

8. Children's Privacy

RedFlag is not intended for use by anyone under the age of 13. We do not knowingly collect information from children under 13.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of RedFlag after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy, contact us at david@prospectpages.college.

RedFlag
Know before you sign
Privacy Policy Terms of Service About Contact
Built by David Medina · © 2026 RedFlag. All rights reserved.

RedFlag provides informational analysis only, not legal advice. Consult a licensed attorney for legal guidance.