Privacy Policy
You send us contracts. That deserves a clear answer about what happens to them. This policy explains what we collect, why, who processes it, how long we keep it, and how to get it deleted.
1. Introduction
Plural AI, Inc., a Delaware corporation ("Plural AI", "Company", "we", "us", or "our") operates ReCounsel. ReCounsel is a Plural.Studio venture. This Privacy Policy explains how we collect, use, share, and protect information when you use the Service.
For users in the European Union or the United Kingdom, Plural AI, Inc. is the data controller for personal data processed through the Service. This Policy is intended to satisfy our obligations under the General Data Protection Regulation (GDPR) and the UK GDPR, which apply to our processing regardless of where the Company is incorporated (GDPR Art. 3(2)).
One point worth stating up front: we do not use the contracts you submit to train third-party AI models, and we do not sell personal information.
2. Information We Collect
Account and intake information
When you request a review or create an account, we collect:
- Your email address.
- Your company name, and team size where you give it.
- The type of contract, the country whose law applies, and how urgent the review is.
- Any notes you write about what you are worried about in the contract.
Contract content you submit
To produce a report we process the document you submit and its contents. Contracts are commercially sensitive by nature, and they often contain personal data about other people, such as names, job titles, signatures, and contact details of counterparties and signatories. We treat this category with corresponding care.
Where your document contains personal data about other people, you remain responsible for having a lawful basis to share it with us, and we process it on your behalf and on your instructions for the purpose of producing your report.
Usage and technical information
- Browser and device information, and the user agent string.
- IP address, which also gives an approximate location.
- The page or source that referred you to us.
- Records of reports requested and delivered, and support correspondence.
Payment information
Payments are processed by Stripe. Stripe collects and processes your card details directly. We never receive or store your full card number. We receive payment metadata such as the transaction outcome, the amount, the currency, the last four digits of the card, and the billing email, so that we can allocate credits, issue receipts, and handle refunds.
3. How We Use Information
We use information to run the Service, and for very little else. Specifically:
- To produce, deliver, and store your contract review report.
- To create and administer your account and allocate purchased credits.
- To process payments, issue receipts, and handle refunds.
- To send transactional email, such as report delivery, account notices, and receipts.
- To answer support requests and follow-up questions about a report.
- To keep the Service secure, prevent abuse and fraud, and debug faults.
- To improve the Service, including our benchmark library, using aggregated or anonymised information that does not identify you, your counterparty, or your document.
- To meet legal, tax, and accounting obligations.
What we do not do. We do not use your contracts to train third-party AI models, and our agreements with model providers do not permit them to train on your content. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not publish or disclose your documents to other customers.
4. Legal Basis for Processing (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Producing and delivering your report, managing your account and credits | Performance of a contract (Art. 6(1)(b)) |
| Taking payment, issuing receipts, handling refunds | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse and fraud prevention, debugging, service improvement using aggregated data | Legitimate interests (Art. 6(1)(f)) |
| Support correspondence | Performance of a contract, or legitimate interests |
| Non-essential cookies and analytics, if and when we enable them | Consent (Art. 6(1)(a)), collected before they run |
| Marketing email, where you have asked for it | Consent, or the soft opt-in for existing customers |
| Keeping records for tax, accounting, and legal claims | Legal obligation (Art. 6(1)(c)) and legitimate interests |
Where we rely on legitimate interests, we have considered your rights and interests and have limited the processing accordingly. You can object to that processing at any time. See Section 7.
6. Data Retention and Security
How long we keep things
- Contract documents you submit: kept for as long as we need them to produce your report, plus the period during which you can access the report in your account, plus a short backup window after that. Backups roll off within 30 days.
- Reports: kept so you can return to them while your account is active.
- Account and intake information: kept while your account is active, and for a reasonable period afterwards in case you come back.
- Payment and transaction records: kept for as long as tax and accounting law requires, typically six to seven years. These records do not contain your full card number.
- Support correspondence: kept while it is useful for supporting you and for a reasonable period afterwards.
You can ask us to delete a document or your whole account at any time. Email hello@re-counsel.com and we will delete it from live systems promptly, with backup copies rolling off within 30 days. We will keep only what we are legally required to keep, such as transaction records.
Security
We use appropriate technical and organisational measures to protect your information, including encryption in transit, encryption at rest for stored documents, access controls limiting who can see documents, and separation of payment handling into Stripe so we never hold card data. No system is perfectly secure, and no method of transmission over the internet is completely safe.
If a breach affects your personal data and creates a risk to you, we will notify you and the relevant supervisory authority as the law requires, without undue delay and within 72 hours of becoming aware where GDPR applies.
7. Your Rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you, and get a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data, including documents you have submitted.
- Portability: receive your data in a portable format, or have it sent to another provider.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent where we relied on consent, without affecting processing already carried out.
- Complain to a data protection authority. For EU and UK users that is the supervisory authority where you live, where you work, or where the issue arose. In the UK it is the Information Commissioner's Office, in Ireland the Data Protection Commission, and in the Netherlands the Autoriteit Persoonsgegevens.
If you are in California or another US state with comparable law, you have rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information for cross-context behavioural advertising, and we honour these requests regardless of whether the relevant thresholds apply to us.
How to exercise your rights: email hello@re-counsel.com from the address on your account, or leave a voicemail at +1 702-483-0484. We reply within one business day and complete requests within 30 days. We will not charge you for a request or treat you differently for making one. We may need to verify your identity first.
9. Children
ReCounsel is a business tool intended for people aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email hello@re-counsel.com and we will delete it.
10. International Transfers
Plural AI, Inc. is based in the United States, and most of our service providers process data in the United States. If you use ReCounsel from the EU, the UK, or elsewhere outside the US, your information will be transferred to and processed in the United States.
Where we transfer personal data out of the EU or the UK, we rely on appropriate safeguards, which in practice means Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum where relevant, or an adequacy decision where one covers the transfer. We also assess whether additional measures such as encryption are needed for a given transfer.
You can request a copy of the safeguards that apply to a specific transfer by emailing hello@re-counsel.com.
11. Changes to This Policy
We may update this Policy as the Service develops, as our subprocessor list changes, or as the law changes. When we do, we will post the updated version on this page and change the effective date at the top.
Where a change materially affects how we handle your personal data, we will notify you by email to the address on your account before it takes effect.
12. Contact Us
If you have questions about this Privacy Policy, or you want to exercise any of your rights, contact us:
Email: hello@re-counsel.com
Phone (US, voicemail): +1 702-483-0484
Company: Plural AI, Inc.
For legal and entity notices, write to legal@pluralstudio.ai. Our registered agent is Northwest Registered Agent Service, 8 The Green, Suite B, Dover, DE 19901, USA.
ReCounsel is operated by Plural AI, Inc. and is a Plural.Studio venture. See also our Terms of Service.