Your information, our practices.
Plain English up top. Formal sections below. If anything here is unclear, ask us: privacy@renegotiateanything.com.
- We collect what you tell us about your negotiation, your account info, and basic usage data. We don't collect more than we need.
- We use it to generate your brief, run the service, and improve the product. We never sell it.
- Your brief content is processed by Anthropic (the maker of Claude). Anthropic does not use it to train AI models. Details below.
- You can access, correct, export, or delete your data anytime. Email privacy@renegotiateanything.com.
- We don't allow accounts for anyone under 18.
The summary above is provided for convenience. The formal sections below are the binding statement.
On this page
Who we are
RenegotiateAnything is operated by NegotiateAI, Inc. (“we,” “us,” or “RenegotiateAnything”). This Privacy Policy explains how we collect, use, share, and protect information when you use our website at renegotiateanything.com, our mobile applications, and any related services (together, the “Service”).
We are not a lawyer, financial advisor, broker, or agent. We provide AI-generated starting points for negotiations. This Privacy Policy applies regardless of how you use the Service.
What we collect
We collect five kinds of information.
1. Account information.
When you sign up, we collect your email address and a display name. You may optionally add a profile photo. If you sign in with a third-party identity provider (such as Google or Apple), we receive a unique identifier and your email address from that provider; we do not receive your password.
2. Brief content.
This is the description of the situation you’re negotiating (a bill, a lease, an offer, etc.), the clarifying answers you give, and any documents you upload. We need this to generate your brief. We treat it as confidential and we do not use it to improve our product without your separate, explicit consent.
3. Outcome information.
When you log the outcome of a negotiation, we collect the outcome you report (won, partial, lost, etc.), the amount you report saving, and any free-text notes you include. Outcome information is what powers our public Track Record stats; it is aggregated and anonymized before display, and we only show aggregated counts once at least 50 outcomes have been logged in a category.
4. Payment information.
When you complete an outcome that triggers a charge, our payment processor (Stripe) collects your card details directly. We never see, store, or transmit your full card number. We receive only the last four digits, the card brand, and a token used to charge your card on future wins.
5. Usage and technical data.
We collect basic information about how you use the Service: the pages you visit, the actions you take (clicked “generate brief,” logged an outcome, etc.), the device and browser you’re using, your approximate location based on your IP address, and error reports if something goes wrong. We use a product analytics tool (PostHog) and an error monitoring tool (Sentry) for this purpose.
We do not collect: your full credit card number, biometric data, precise GPS location, or any of the categories of “sensitive personal information” defined by California’s CPRA unless you voluntarily include them in a brief description.
How we use it
We use the information we collect for these purposes only:
- To generate your brief. Your situation description is sent to our AI provider to produce a customized negotiation playbook.
- To run the Service. Authenticate you, save your briefs, deliver email reminders if you opt in, process payments on wins.
- To support you. Respond to your questions, investigate issues you report, recover your account.
- To improve the Service. Aggregate usage patterns to understand which features work. We do not use the content of your briefs to train or fine-tune AI models without your separate, explicit consent.
- To keep the Service safe. Detect fraud, abuse, and security incidents.
- To meet legal obligations. Respond to lawful requests, comply with tax and accounting law, enforce our Terms.
We do not sell your personal information. We do not share it with advertisers. We do not use it for targeted advertising on other sites.
Who processes your data
To run the Service, we share information with a small number of vendors (sometimes called “sub-processors”). Each vendor is bound by contract to use the data only to provide their service to us.
Our current sub-processors:
We do not share your data with any other party, except: (a) with your direct consent, (b) to comply with a lawful legal request, or (c) in connection with a sale, merger, or acquisition of NegotiateAI, in which case the acquirer will be bound by this Privacy Policy until they post a new one with at least 30 days notice.
How long we keep it
- Account information: for as long as your account is open, plus 90 days after you delete your account (to allow recovery if deleted by mistake), then permanently deleted.
- Brief content: until you delete the brief or delete your account. After deletion, removed from our active database within 24 hours and from backups within 35 days.
- Outcome information: kept indefinitely in anonymized form (no link to your account) so that our Track Record stats remain accurate. Personally-identifiable details (your free-text notes) are deleted with your account.
- Payment information: held by Stripe under their terms. We keep transaction records for 7 years as required by US tax law.
- Usage and technical data: 90 days in PostHog and Sentry under default settings, then aggregated or deleted.
Your rights
You have the right to:
- Know what we’ve collected about you and why.
- Access a copy of your personal information in a portable format.
- Correct any inaccurate personal information.
- Delete your account and your personal information.
- Limit how we use it (e.g. opt out of analytics).
- Not be discriminated against for exercising any of these rights.
California residents have these rights under the CCPA/CPRA. Residents of other US states with privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others) have similar rights. We honor all of these rights for every user in the United States, regardless of which state you live in.
We do not use your data for automated decision-making with significant legal effects on you (such as credit scoring or employment screening).
How to exercise your rights
Email privacy@renegotiateanything.com from the email address on your account. Tell us what right you want to exercise. We will respond within 30 days.
You may also do most of these directly from your account settings: download your data, change your email, or delete your account.
If you’re acting on behalf of someone else (a parent for a minor, an executor for a deceased person, or an authorized agent), we will verify your authority before acting on the request.
Children
The Service is intended for adults age 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child under 18 has provided us with information, please email privacy@renegotiateanything.com and we will delete it.
Our age limit (18) is higher than the federal COPPA threshold (13) because the Service involves financial and legal-adjacent decisions for which younger users would not have legal capacity to act.
International users
The Service is currently available only to residents of the United States. Our servers are located in the United States, and our sub-processors are US-based or operate under US data protection arrangements.
If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. We don’t currently offer GDPR-specific transfer mechanisms (such as Standard Contractual Clauses) because we don’t market or operate the Service in the European Economic Area, the UK, or Switzerland.
We may expand availability in the future. If we do, we’ll update this Privacy Policy to reflect the new arrangements and notify affected users before any change takes effect.
How we protect your data
We use industry-standard security practices: encryption in transit (TLS 1.2+) and at rest, role-based access controls inside our company, multi-factor authentication for all employees with production access, and regular review of our vendors’ security practices.
No system is perfectly secure. If we ever experience a data breach that affects you, we will notify you within 72 hours of becoming aware of it, by email and a notice on the Service. We will tell you what happened, what data was involved, and what we’re doing about it.
Changes to this policy
We may update this Privacy Policy. When we do, we will:
- Bump the version stamp at the top of this page.
- For material changes, email everyone with an active account at least 30 days before the change takes effect.
- Keep an archive of prior versions. You can request a prior version by emailing privacy@renegotiateanything.com.
Continued use of the Service after a change means you accept the updated policy. If you don’t accept it, you can delete your account.
Contact us
For privacy questions or requests: privacy@renegotiateanything.com
For everything else: see our contact page.
NegotiateAI, Inc. — physical address to be added before launch.