Last updated 15 September 2026
This is a founder-drafted policy describing how DealSafe actually handles data today, written to match the real system rather than boilerplate. It is not a substitute for review by a qualified solicitor before DealSafe accepts real users, and it should be kept in sync as the product changes.
XLR8 operates DealSafe and is the data controller for the personal data described here, under UK GDPR and the Data Protection Act 2018.
We do not automatically keep a permanent store of your uploaded contracts — the default for every Contract Check is analyse-then-delete (Section 4). The only exception is your own explicit, per-deal choice to keep a contract in your Deal History (Section 4a); we never make that choice for you. We do not sell personal data, and we do not use your contract or deal content to train AI models without your explicit, separate opt-in.
When you upload or paste a contract, we run rule-based checks and send the extracted text to a third-party AI provider for structured analysis. By default, the original file and any extracted text are:
Where our AI provider processes your text, that processing follows their API data-handling terms. We do not promise our provider deletes data on the same 5-minute timeline as our own systems — we use the retention and no-training controls available to us and will update this policy if that changes.
After a Contract Check, you can choose “Keep the original contract in my Deal History” for that specific deal. If you do, we store the file itself — encrypted with application-level AES-256-GCM before it is written to our database, in addition to our hosting provider’s disk-level encryption — and it is retained until you remove it from that deal (available at any time from the deal’s page) or delete your account. This never happens without you actively choosing it, deal by deal; the 5-minute deletion in Section 4 remains the default for everything else, including any deal where you don’t make this choice.
Only the processors needed to run the service:
We don’t share your data with any other third party for marketing purposes, and never sell it.
Under UK GDPR you can ask us to:
We keep account and deal-ledger data for as long as your account is active, plus a reasonable period afterward for legal/accounting reasons unless you request earlier deletion. Contract-check source text follows the 5-minute rule in Section 4 regardless of your account status, unless you opted to keep that specific contract in your Deal History (Section 4a), in which case it’s kept until you remove it or delete your account.
We use a single essential session cookie to keep you signed in. We don’t use third-party advertising or tracking cookies.
DealSafe is for creators 18 and over. We don’t knowingly collect data from anyone younger.
If this policy changes materially, we’ll notify active users by email before the change takes effect.
Questions or data requests: privacy@dealsafe.app (placeholder — update before launch).