This Privacy Policy explains what happens to your information when you use Ziny Contract to analyze a contract. We've kept the service deliberately simple — no accounts, no subscriptions — and this policy is written to match that: short, specific, and focused on what actually happens to your data.
Ziny Contract ("Ziny", "we", "us") is an online service that uses AI to produce a plain-language risk analysis of a contract you upload. It is operated by an individual sole trader based in Egypt, not by a registered company.
Because there is no separate legal entity, any reference to "we" or "us" in this policy and in our Terms of Service means the individual operator of Ziny Contract.
For any privacy question, request, or concern, contact us at fullstackragab@gmail.com. We handle privacy requests personally, as we're a small, single-operator service.
When you upload a PDF, its text is extracted in your browser session and sent to our backend, which forwards the relevant text to an AI provider (see "Who else processes your data" below) to generate your risk analysis. We do not save the contract file, its extracted text, or the generated report to a database — once your session ends or you close the tab, we no longer hold a copy on our side.
Scanned documents: if your file is a scanned or photographed contract with no extractable text layer, we use Amazon Textract (see sub-processors below) to read it via optical character recognition (OCR). This requires briefly holding the uploaded file in secure temporary storage while OCR runs. That copy is deleted automatically as soon as OCR completes — whether it succeeds or fails — and always before your report is generated. This is the only case in which your uploaded file itself, rather than just its extracted text, is held anywhere other than your own browser session, and it is never kept for longer than the OCR step requires.
The free preview and the full report you see on screen exist only in your browser's memory for that session (and briefly in your browser's sessionStorage during the Stripe checkout round-trip, so your report survives the redirect to and from payment). If you want to keep your report, download or print it before you leave the page.
We do not use your contract's content for any purpose other than generating your analysis, and we do not use it to train any AI model that we control.
Payment for the full report ($29.99, one-time, no subscription) is handled entirely by Stripe. When you choose to unlock a report, you are redirected to Stripe's own hosted checkout page — we never see or handle your card number, expiry date, or CVC.
Stripe shares limited information back with us to confirm your payment went through (such as a payment/session status and identifier). We use that only to unlock your report and, if needed, to help resolve a support request about a specific payment.
Stripe processes your payment details under its own privacy policy and is itself responsible for that data as an independent controller. You can review Stripe's privacy policy at stripe.com/privacy.
If you contact us through the support form, we collect the name, email address, and message you choose to provide, so we can read and reply to your request. We keep that information only for as long as needed to resolve your request and for a reasonable period afterward in case you follow up, then delete it.
We do not add you to a mailing list or use your support message for marketing.
Ziny Contract does not use tracking cookies or third-party analytics or advertising trackers today. If that changes in the future, we will update this policy and add a cookie consent banner wherever it's legally required before any non-essential cookie is set.
Our hosting and infrastructure providers automatically generate standard connection logs (such as IP address, browser type, and request timestamps) for security, abuse prevention, and reliability — the same way almost any website works. These logs are not linked to your contract content.
Your selected display language is stored only in your browser's local storage, on your own device — it is never sent to us or to any third party.
We share data with a small number of service providers ("sub-processors") strictly to run Ziny Contract:
Each of these providers may process data outside your own country, including in the United States. We only share the minimum data each provider needs to do its job, and we do not sell your data to anyone.
Where data protection laws such as the EU/UK GDPR apply to you, we process your data on these bases: to perform the contract with you (generating and delivering the report you're paying for), for our legitimate interests (running, securing, and improving the service, and handling support requests), and, where required, with your consent (for example, before any future non-essential cookie).
Because our AI and payment sub-processors operate internationally, your contract text and related data may be transmitted to and processed in countries outside your own, including the United States, which may have different data protection laws than your country. We rely on our sub-processors' own safeguards for these transfers (such as their standard contractual clauses or equivalent mechanisms).
Depending on where you live, you may have the right to ask us to: confirm what personal data we hold about you, access or receive a copy of it, correct inaccurate data, delete it, restrict or object to certain processing, or receive it in a portable format. Because we don't maintain accounts or a customer database, in most cases the only personal data we hold about you at any given time is what you sent us through the support form, or what Stripe holds on our behalf.
To exercise any of these rights, email fullstackragab@gmail.com. We'll respond as quickly as we reasonably can.
If you're in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority. We don't sell personal data, so there is nothing to opt out of under laws such as the CCPA/CPRA in that respect.
Ziny Contract is not directed at, and is not intended for use by, children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We use reasonable technical and organizational measures to protect the data we handle, including encrypted connections (HTTPS) and, by design, avoiding long-term storage of your contract content in the first place — the less we keep, the less there is to protect. The one narrow exception is the brief, automatically-deleted temporary storage used to OCR scanned documents (see "Scanned documents" above). That said, no method of transmission or storage is completely secure, and we can't guarantee absolute security.
We may update this Privacy Policy from time to time, for example as the service grows or laws change. We'll update the effective date above when we do, and for material changes we'll take reasonable steps to make that visible on the site.
Questions about this policy, or about how it applies to your situation, can be sent to fullstackragab@gmail.com.