Private by default
The original document stays in your private PactCue workspace. PactCue uses signed URLs for time-limited access instead of making the files public.
Contract files are stored privately, access is limited to your workspace and AI analysis only receives temporary access to the document. Important information is reviewed before it can be used for automated reminders.
Contract PDFs are stored in private Supabase Storage. Only PDF files are accepted and uploads have a size limit.
Database and storage access use Row Level Security so authenticated users can only access resources in their own organization.
For analysis, PactCue creates a time-limited signed URL to the private PDF and sends it to the OpenAI API. OpenAI states that API data is not used for model training by default.
AI suggestions are not automatically treated as verified facts. Important dates can be reviewed and automated reminders only use verified information.
PactCue sends analysis requests with store:false. OpenAI states that API data is not used for model training by default, but default abuse-monitoring logs may contain customer content and can be retained for up to 30 days.
The original document stays in your private PactCue workspace. PactCue uses signed URLs for time-limited access instead of making the files public.
PactCue uses Supabase for authentication, database and file storage, the OpenAI API for contract analysis, Vercel for application hosting, Resend for transactional email and Stripe for billing.
PactCue does not claim that all data stays in the EU when that has not been technically verified. Information about data location and cross-border processing is based on the actual provider configuration.
When you delete a contract, its contract data and stored PDF are removed from the workspace. Linked events and reminder records are removed with the contract.
Have a security question or want to report a vulnerability? Contact us at the address above.