Your documents are the product's input, not ours.
Sidecar works because you trust it with real contracts and real numbers. This page says plainly what we collect, where it goes, how long we keep it, and how to make us delete it.
Last updated: August 12, 2026
Who we are
Sidecar is a product and service owned and operated by Built By Signal LLC, Ohio limited liability company. Throughout this policy, “we” and “us” mean Built By Signal LLC — that is the entity responsible for the information described below, and the one you can hold to the commitments on this page.
Reach us about privacy at privacy@sidecarpartner.com.
What we collect
Sidecar collects three kinds of information:
- →Account information. Your name, work email, organization name, and role — provided when you sign up or submit one of our forms.
- →Documents you upload. Contracts, invoices, renewal notices, reports, and other files you choose to send us, along with the text we extract from them to run the analysis.
- →Analyses we produce. Risk scores, findings, deadlines, and reports generated from your documents. These belong to your workspace.
If you arrive through our marketing site, we may also record basic context about how you found us (for example, a campaign tag in the link you clicked and the referring page).
Where your documents go
- →Storage. Uploaded files and extracted text are stored in Google Firebase services (Cloud Storage and Firestore), scoped to your organization.
- →Analysis. Document text is sent to the Anthropic API to generate your analysis. Your documents are not used to train AI models — not by us, and not by our AI provider under the API terms we operate under.
- →Scanned documents. If a PDF has no selectable text, or you upload an image, we send the page images to the same provider to read the text off them. It's the only way to analyze a scan, and it's covered by the same no-training terms.
- →Human review. Before a review is released to you, an authorized Sidecar reviewer reads the document and the draft analysis. That check is the point of the product — it also means a person at Sidecar sees what you upload.
- →Anonymized clause statistics. When a review is completed we keep one record of the agreement's structure — type, term length, auto-renewal, notice window, how price increases and liability were handled, and the number of findings. It contains no organization, no vendor or counterparty name, no amounts, no dates, and no text from your document. We use it to tell customers whether a term is unusual for its kind of agreement. It cannot be traced back to you.
- →Nothing else. We do not sell your data, and we do not share your documents with third parties beyond the infrastructure providers above.
Who else touches your data
These are the companies involved in running Sidecar. We use them for the purpose listed and nothing else, and none of them gets your data to use for their own ends.
- →Google Cloud / Firebase — hosting, the database, file storage, sign-in, and scheduled jobs. This is where your documents and analyses live.
- →Anthropic — the AI that produces the analysis, including reading scanned pages. Not used for training.
- →Google Workspace — sends our notification and account email. (We keep Resend configured as a backup sender.)
- →Stripe — card payment, where it's offered. Card details go to Stripe, never to us.
- →Google Analytics — visitor measurement on the marketing site only, not inside the product.
If you connect an outside account yourself — a file store, a chat tool — data moves between it and Sidecar as you've scoped it, and that provider's own privacy policy applies to their side. Disconnect it and that stops. When this list changes, this page changes.
Isolation and access
Every document, analysis, and vendor record belongs to exactly one organization. Access rules are enforced at the data layer: members of your organization can read your workspace; nobody else can. Files are never publicly readable — every file read goes through our servers after an organization-membership check. Within your workspace, role-based permissions control who can upload, analyze, and delete.
A small number of authorized Sidecar staff may access your workspace when needed to provide support or operate the service. Every such access is recorded in a tamper-evident audit log, and while it is active you'll see a banner in the app.
Retention and deletion
Documents and analyses persist until you delete them. When you delete an agreement, its analyses are deleted with it — and if the file was uploaded through agreement intake, the stored file is deleted too. Files that live in your shared Upload Center and are merely referenced by an agreement stay until you delete them from the Upload Center directly.
To request deletion of your account or anything you can't remove yourself, email privacy@sidecarpartner.com or use the contact form. We'll confirm when it's done.
You can take your data with you at any time: the workspace export produces a single file containing your agreements, analyses, vendors, reports, and deadlines. It leaves out the credentials for any outside account you've connected — those are secrets that shouldn't travel in an export file.
Two record types outlive the content they describe. Workspace activity records — who did what, and when — are kept for about 400 days so you and we can reconstruct a change. Our internal administrative audit log, which records staff access and platform-level actions, is kept indefinitely and is tamper-evident by design; that is the record that lets us prove who looked at what.
Email we send you
Most of our email is operational: your review is ready, a notice deadline is coming up, someone invited you to a workspace, an invoice needs attention. Those come with the account, and turning them off is done per type in your notification settings.
We also send a small amount of non-essential mail — a follow-up after you sign up, an occasional digest. Every one of those carries a one-click unsubscribe link that works without signing in, and unsubscribing never affects the operational email your account depends on.
Cookies and analytics
The application uses a session cookie to keep you signed in. We don't run third-party advertising trackers on the product, and we don't sell or share your information for advertising.
Our public marketing site uses Google Analytics to measure visits, plus a first-party cookie that keeps you seeing a consistent version of a page while we test wording. If you asked us for something through a form, we may record how you found us — a campaign tag, the referring page. None of that reaches inside your workspace.
What we do with what we find
This policy covers how your documents are handled. What the resulting analysis is — and is not — is covered in the Terms of Service: Sidecar is business decision support, not legal advice and not financial, tax, or accounting advice.
Changes
If this policy changes in a way that affects how your documents are handled, we'll update this page and note the date at the top. Questions? Ask us — we answer.
