1. Scope
This Privacy Policy explains how Greenhouse Ventures, LLC ("Greenhouse Ventures," "we," "our," or "us") handles information when you use Privy AI ("Privy"), including the Privy Chrome extension, extension dashboard, Privy API, or this website. Privy is operated under the Greenhouse Labs brand.
Privy helps consumers understand Terms of Service, privacy policies, EULAs, subscription terms, and similar legal documents. Privy provides informational analysis, not legal advice.
2. Data flow at a glance
- The extension can inspect the active page locally to identify likely legal content and related policy links.
- Local detection does not require sending the complete document text to Privy or OpenAI.
- Document text is transmitted only after you explicitly start an analysis.
- The selected page text, pasted text, right-click selection, or text extracted locally from an imported document is sent through the Privy API to OpenAI for analysis.
- Every successfully completed new analysis is saved as a structured report in the authenticated user's Privy account in Firestore. A reusable result copy may also be cached locally in Chrome.
3. Account information
Privy uses Firebase Authentication. Depending on your sign-in method, Firebase and Privy may process your Firebase user identifier, email address, display name, profile image, authentication provider, and sign-in metadata. Authentication credentials are handled by Firebase; Privy does not receive your third-party account password.
Privy also stores account-level information needed to show and enforce your analysis-credit balance and feature access. Existing account records may contain legacy subscription identifiers, but those fields do not grant access or analyses in the current product.
4. Information handled locally in Chrome
Before analysis, the extension can read text, headings, page title, URL, and link labels from the active webpage. It uses that information locally to determine whether the page is likely to contain a legal document and to discover related legal links on the same or a related hostname.
When you choose a TXT, Markdown, PDF, or DOCX file up to 20 MB, Privy extracts its text locally in the extension. Privy does not scan installers or executable files.
The extension stores structured cached report results, evidence excerpts, cache keys, report identifiers, source URLs, cache timestamps, cache preferences, and theme preferences in Chrome local storage. Separately, right-click selected text and associated page details are held temporarily in Chrome session storage, consumed once, or erased after 15 minutes.
The local result cache contains the structured report, not the complete raw source document text. You can clear current-page cache or all local cached reports from Privy settings.
5. Information sent for analysis
When you explicitly start an analysis, Privy sends the active-page text, pasted text, selected text, or locally extracted document text you chose; page title and URL when applicable; a document-type hint; and request metadata needed for authentication, analysis-credit controls, duplicate prevention, and delivery.
The Privy API sends the selected document text and related metadata to OpenAI through the Responses API using structured outputs. OpenAI processes that material to produce the requested analysis. Privy does not claim that document text remains entirely on your device.
6. Saved reports and operational metadata
For authenticated users, each successfully completed new analysis is saved as a structured report in Firestore. A report can include document title, type, URL, timestamp, source-text hash, summary, risk level and rationale, takeaways, actions, flagged clauses, favorable terms, and exact evidence excerpts. Account credit-balance information is stored to authorize and record successful new analyses. When production checkout is enabled, purchase-attempt and fulfillment metadata is stored to grant an analysis pack once and prevent duplicate fulfillment.
The complete raw source document text is not included in the saved report record. Exact excerpts that support findings are part of the structured report.
Privy's application logging records operational metadata such as request IDs, source type, character counts, durations, error details, and report identifiers. Application logging is designed not to include raw document content. Standard operational and security logs may include IP addresses, request times, user agents, endpoints, and response status codes.
7. How we use information
- Authenticate users and protect account access.
- Perform analyses the user requests.
- Generate, save, retrieve, search, filter, export, and delete reports.
- Reuse matching saved or cached reports without consuming another analysis.
- Show and enforce the analysis-credit balance.
- Create and fulfill a one-time analysis-pack purchase when production checkout is enabled.
- Diagnose failures, secure the service, prevent abuse, and respond to support requests.
We do not use local detection to trigger remote analysis without your action. Privy does not sell personal information, build advertising profiles, or perform keystroke, mouse, or session-replay tracking.
8. Service providers
- Firebase Authentication and Firestore / Google Cloud: authentication, account data, structured history, and backend infrastructure.
- OpenAI: processing user-requested document text to generate structured analyses. Privy sends Responses API requests with
store: false. Privy does not claim Zero Data Retention. By default, OpenAI abuse-monitoring logs may be retained for up to 30 days, subject to OpenAI's stated legal and safety exceptions. - Google Chrome: extension distribution and Chrome local and session storage APIs.
- Stripe: hosted payment processing for the one-time analysis pack when production checkout is enabled. Stripe handles payment-card details; Privy receives checkout and fulfillment metadata, not card numbers.
These providers process information under their own terms and policies. Production Stripe checkout has not completed live verification and is not currently available through this website.
9. Retention and deletion
- Local cache: Matching structured report results may remain in Chrome local storage according to your cache settings. You can view cache status, remove current-page entries, or clear all local cached reports.
- Saved reports: Saved account reports remain until you delete the report or permanently delete your account.
- Account deletion: Privy's permanent account-deletion control deletes saved reports, profile/account data, and Firebase authentication. A hashed deletion tombstone used to prevent unsafe account recreation is purged after 30 days.
- OpenAI processing: Responses API requests use
store: false, and Privy does not claim Zero Data Retention. By default, OpenAI abuse-monitoring logs may be retained for up to 30 days, subject to OpenAI's stated legal and safety exceptions. - Operational records: Standard infrastructure and security records are retained according to provider settings and legitimate operational, security, and legal needs.
- Billing records: When production checkout is enabled, purchase and fulfillment records may be retained as needed to prevent duplicate credit grants, process refunds, protect the credit ledger, and meet accounting or legal obligations.
Contact support@getprivy.net with a deletion, access, or privacy request.
10. Your controls and choices
- Choose whether and when to start an analysis.
- Review local detection without sending the complete document text.
- Clear local result cache entries and change cache settings.
- Review your remaining analysis balance.
- Delete saved reports from your account history.
- Export individual reports as Markdown.
- Permanently delete your account, saved reports, profile data, and authentication.
- Contact us about account information or deletion.
Removing the extension may clear extension-local data according to Chrome behavior, but it does not by itself delete Firestore account history.
11. Security
Privy uses access controls, authenticated API requests, HTTPS transport, and provider security features intended to protect information. No system is completely secure, and we do not guarantee that unauthorized access or loss can never occur.
12. Children
Privy is a general-audience consumer tool for people who are at least 18 years old and is not directed to children. If you believe a child has provided account information, contact support@getprivy.net.
13. Privacy rights and international use
Privacy rights vary by location and may include rights to request access, correction, deletion, or a copy of certain personal information. Privy does not claim formal certification or verified compliance with a specific privacy regime in this policy. We will evaluate valid requests under applicable law.
Using Privy may involve processing in countries where our service providers operate, which may have different data-protection rules.
14. Chrome Web Store Limited Use
Privy's use and transfer of information received from Google APIs will comply with the Chrome Web Store User Data Policy, including the Limited Use requirements. Privy requests broad webpage access for local legal-document detection and user-initiated analysis; it does not use that access for passive advertising profiles or automatic remote analysis.
15. Changes and contact
We may update this policy as the product, providers, or legal requirements change. We will update the effective date and provide additional notice when appropriate.
Questions, support, or privacy requests: support@getprivy.net
General inquiries: contact@getprivy.net
Website: getprivy.net