Skip to content

01Who we are

Data controller

FixMyContract is operated by Yağmur Yaman, Malazgirt mahallesi yaşar Kemal caddesi Levent Sitesi 45/22 Sincan/Ankara.

Privacy & data-protection contact: privacy@fixmycontract.com.

02Data we collect

  • Account — your email address and name.
  • How you found us — if you join the waitlist or create an account, we record the channel that brought you (from a link's src or utm_source tag, matched against a fixed list — anything we don't recognize is simply recorded as "other"), the campaign name if the link carried one, the domain of the site that referred you, and the page you landed on. We deliberately don't record the full web address you arrived from or landed on — it can carry someone else's information in its query string — and we don't record advertising-click identifiers, since we don't run paid ads. We keep this for as long as the record it's attached to exists: see If you join the waitlist for a waitlist entry, or for as long as your account exists otherwise. If you sign up through an invite link, we record which account invited you so we can credit that account — and if someone signs up through your invite link, you see only a running count of credits you've earned, never their name or email. We use this, together with reasonable limits on repeat or self-referral, as part of the same legitimate interest in protecting the free allowance from abuse described above.
  • The contracts you upload — these can be sensitive documents.
  • The role you select — before an analysis, you tell us which perspective to read the contract from (for example tenant, freelancer, employer, employee, or General). We use this only to shape the analysis. It is an ordinary preference, not a special category of personal data, and we do not use it for advertising or profiling.
  • Analyses we generate and your document-chat messages (these include excerpts from your contracts).
  • Technical — an authentication session cookie, coarse usage counters, and cookie-free traffic and performance measurements (the page visited, the referring site, an approximate country, the device type, and a daily identifier derived from your IP address and browser). We do not use these for advertising or profiling.
  • Product-analytics events — when you upload a document, an analysis finishes, you open a finding, send a document-chat message, or download a PDF, we record that this happened, when, and — if you are signed in — an account identifier. If you are not signed in, the event carries no account reference. We use this only to understand how people move through the product and to improve it, and not for advertising or profiling.
  • Subscription and payment records — if you buy a subscription: which plan, how many seats, its status and dates, the amounts charged or refunded, and the identifiers the payment carries at our payment provider. We never receive or store your card details.
  • Security and account events — the fact that you signed in from an unusual place, changed plan, exported your data or deleted your account, together with the time and an account identifier; and, if you buy a subscription, the exact wording you agreed to at checkout.
  • Negotiation outcomes — if you used “Request this change”, we may email you once, about a week later, to ask whether the other side agreed. If you answer, we store your answer (agreed, partly, or declined) and the type of clause you asked about, never the wording of your contract or of your request. We use the answers only in aggregate, to show how often a type of request is accepted, and we publish a figure only once enough people have answered that no one answer can be picked out. The legal basis is our legitimate interest in improving the service (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). You can turn these emails off from any of them, and your answers are erased when you delete your account.

03If you join the waitlist

Before checkout opens, you can ask us to tell you when it does. When you do, we store your email address, the plan you were looking at when you asked — Pro, Expert, Business, or a single analysis — if the link you used carried one, the page you joined from, and the date. That is the whole entry. There is no account behind it, and we add nothing else to it.

We use it for one thing: to email you when the plans you asked about go live. The legal basis is your consent, which you give by submitting the form (GDPR Art. 6(1)(a) / KVKK explicit consent). You can withdraw it at any time — write to privacy@fixmycontract.com and we delete the entry. We do not use waitlist addresses for advertising or profiling, we do not sell them, and if you later create an account we do not merge the two records.

To stop the form from being submitted in bulk automatically, we count recent submissions against a one-way hash of the sender's IP address, on the basis of our legitimate interest in protecting the service (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). We never store the address itself, the counter holds nothing else about you, and it is not linked to your entry. That counter is automatically deleted after 30 days.

How long we keep it. Until we have told you that the plans you asked about are open, and at most 90 days after that message — or 12 months after you joined, if they have not opened by then. After that the entry is deleted. You can ask us to delete it sooner at any time, at the same address.

The channel and referrer information described in How you found us is included in your entry and follows the same retention as the rest of it.

04If you try it without an account

This section, and the trial cookie described in Cookies & sessions, apply from 23 September 2026, the day the trial opened; the rest of this version of the policy takes effect on 30 September 2026.

You can run one analysis without signing in. To do that we store the file you upload, the text we read out of it, the analysis, the file's name and type, and a hash of your network address, together with a signed cookie (fmc_anon) that lets this browser find the result again. You see only a summary of the result until you sign in.

If you do not sign in within 24 hours, the file, the text, the analysis and the hash are deleted automatically. If you do sign in, they move into your account and from then on follow “How long we keep it”, like anything you upload there; nothing is left behind in the trial record.

We process this to give you the result you asked for before you decide to create an account (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)), and use the network hash to limit how many free trials one network can run, on the basis of our legitimate interest in protecting the service from abuse (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)).

05Why we process it & legal basis

We process your data to provide the service — analyzing the contracts you submit. Two laws are named throughout this policy: the EU General Data Protection Regulation (“GDPR”) and the Turkish Personal Data Protection Law No. 6698 (“KVKK”). Our legal basis is performance of a contract (GDPR Art. 6(1)(b) / KVKK Art. 5) and, where needed, your consent (GDPR Art. 6(1)(a) / KVKK explicit consent). The role you select is processed on the basis of performance of our contract with you (GDPR Art. 6(1)(b) / KVKK Art. 5), because the analysis you asked for is produced from that perspective.

We also process a small amount of data to protect the free allowance from abuse, on the basis of our legitimate interest in defending the service against fraud and cost abuse (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). When an account is deleted we keep a keyed, one-way hash of its email address together with the number of free analyses that address had already used, for 180 days. The hash is computed with a secret key held outside the database, so it cannot be turned back into an address and does not directly identify you — it only lets us recognize that a returning address has already had its free allowance. It is never used for marketing, profiling or any other purpose, and paid plans are not affected. You can object to this processing at privacy@fixmycontract.com.

We also keep a security and compliance log of significant account events, and — if you buy a subscription — the record of the consent you gave, on the basis of our legitimate interest in securing the service and in establishing, exercising or defending legal claims (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)) and, where a law requires the record, of compliance with a legal obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(a)).

The cookie-free traffic and performance measurements described in Data we collect rest on the same basis: our legitimate interest in knowing that the service is reachable and fast (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). They are not used to build a profile of you, and you can object to them at the same address.

The product-analytics events described in Data we collect rest on the same basis: our legitimate interest in understanding how the product is used and improving it (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). They are not used to build an advertising profile, and you can object to them at the same address.

We use how-you-found-us information, described above, to understand which channels bring people to FixMyContract — on the basis of our legitimate interest in growing the service efficiently (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)). It is not used for advertising or profiling, and we do not share it with the channels or sites it names.

06How long we keep it

The document you upload — the original file and the text we read out of it — is automatically deleted 30 days after you upload it. Your analysis report stays until you delete it, so that the thing you came for is still there when you come back; you can delete any report yourself at any time, and we delete it when you do. Deleting your account erases your documents, analyses, chats, product-analytics events tied to your account, outcome answers, and account record (see Your rights). We keep your account email only while your account exists.

We keep a report for as long as your account exists because reading it back is the service you signed up for. We do not keep it for any other purpose, and we do not keep the document it was made from.

Documents uploaded before 30 September 2026 keep their original 30-day deletion, report included. We do not extend a deletion you were already promised.

If you joined the waitlist without an account, that entry has its own retention — see If you join the waitlist.

Some records outlive your account, and none of them contains your documents, your analyses or your chats.

  • The abuse-prevention record described in Why we process it & legal basis: a keyed hash of your email address and a free-usage count, kept for 180 days and then deleted automatically.
  • Product-analytics events from visitors who are not signed in carry no account reference and are kept for at most 180 days, then deleted automatically. Events tied to your account are not part of this 180-day period — they are erased immediately when you delete your account, together with your documents, analyses and chats (see above).
  • A security and compliance log of significant account events — sign-in anomalies, plan changes, administrator access, data exports and the account deletion itself. It records what happened, when, and an account identifier. We keep it to show that we handled your data lawfully and to defend legal claims (GDPR Art. 17(3)(b) and (e); KVKK Art. 28). Security events are kept for 90 days, administrator access for 12 months, and billing, export and erasure events for 24 months, after which they are deleted automatically.
  • If you buy a subscription, the consent you gave at checkout — the exact wording shown to you, the plan and the price. It is the proof that you agreed to what you were charged for, so deleting it early would remove your evidence as well as ours. It is kept for three years from the day you gave it, or one year after the contract ends, whichever is later.
  • Subscription and payment records — the plan, the number of seats, the status and dates, the amounts charged or refunded, and the identifiers the payment carries at our payment provider. We keep these while your subscription runs, and afterwards for as long as tax and commercial law require us to keep the records of a sale — up to ten years from the end of the year the transaction falls in. They contain no card details, because we never receive any. What Polar keeps, and for how long, is decided by Polar under its own policy, not by us.

07Who we share it with

We use trusted processors to run the service: Anthropic (AI analysis), Supabase (database, authentication and storage), Vercel (hosting, and privacy-friendly, cookie-free traffic and performance measurement), Sentry (error monitoring, which receives technical error reports stripped of your documents, your account details and your request data), and Resend (email delivery). Each acts as a data processor on our behalf. We never sell your data.

Where email is concerned, this is what that means. When we send a message about your account — for example the copy of a withdrawal you submit that goes to our own team, so that a person can cancel and refund it — Resend carries that message and therefore receives the address it is going to and what it says. For a withdrawal that is your email address, your plan and the amount to be refunded. Resend is operated from the United States by Plus Five Five, Inc., under a data-processing agreement that incorporates the Standard Contractual Clauses. It keeps the delivery record while our account with it is open and deletes it within 90 days of that account closing.

Polar is not on that list, and the reason matters to you rather than to us. When checkout opens, Polar Software Inc. is our merchant of record: it is the party that sells you the subscription, takes the payment and accounts for the tax on it. For that it is not acting on our behalf — it decides how your payment data is handled and is a data controller in its own right, under its own privacy policy. You enter your card details on Polar's own page, so we never receive or store them. We send Polar what it needs to open a checkout — your email address, an account identifier of ours, and the plan and number of seats you chose — and what comes back to us is the outcome: the plan, the status, the dates and the amounts. Polar is operated from the United States (Dover, Delaware) and relies on the Standard Contractual Clauses for transfers out of the EEA and the UK.

08International data transfers

Our processors — and, for payments, Polar — may handle data outside your country (including the United States). Such transfers rely on appropriate safeguards (for example, Standard Contractual Clauses) under GDPR Chapter V and KVKK Art. 9.

09AI processing

Your documents are analyzed using the Anthropic Claude API. Anthropic does not train its models on your data. Anthropic deletes the text we send it, and the analysis it returns, within 30 days at most — see Anthropic's published retention policy. In two situations it keeps them longer: if a request is flagged under Anthropic's Usage Policy it may be kept for up to 2 years, and the related safety-classification scores for up to 7 years.

This is separate from our own retention: we delete the document you uploaded 30 days after upload, and anything you delete yourself when you delete it (see How long we keep it).

10How we protect it

Your data is encrypted in transit (TLS) and at rest. Access is scoped to your own account, so other users can never see your documents or analyses.

11Your rights

You can access, correct, delete, port, or object to the processing of your data (KVKK Art. 11 / GDPR Art. 15–22). To exercise them:

  • Delete everything yourself — go to Settings → Delete my account (permanent and immediate).
  • Other requests — email privacy@fixmycontract.com. We respond within 30 days (GDPR one month / KVKK 30 days).

12Complaints

You have the right to complain to a supervisory authority — the Personal Data Protection Authority (KVKK Kurumu) in Türkiye, or your local data-protection authority in the EU.

13Cookies & sessions

We use three cookies, all of them necessary for the site to work the way you left it: an authentication session cookie (via Supabase) that keeps you signed in, a theme preference cookie (theme, light or dark, kept for a year) so the page you come back to looks the way you set it, and, only if you try an analysis without an account, a trial cookie (fmc_anon) that lets this browser find that result for 24 hours. None of them is used to track you across other sites, and we don't use third-party advertising or tracking cookies.

14Children

FixMyContract is not directed to anyone under 18.

15Changes to this policy

We may update this policy from time to time; the version and “last updated” date appear at the top, and we'll note any material changes.

16Not legal advice

FixMyContract provides informational analysis only and is not legal advice. Consult a qualified attorney for decisions about your contracts.

Back to top

Frequently asked questions

What happens to my files after 30 days?

Uploaded files are deleted after 30 days. From 30 September 2026, your report stays in your account until you delete it. You can also delete any report — or your entire account — at any time from your settings.