Privacy Policy
Last updated September 23, 2026
CampusClause is an AI-assisted contract review and contract management service for colleges and universities. This policy explains what information CampusClause (“we,” “us”) collects when you use our website and the CampusClause application (the “Service”), how we use it, and the choices you have.
We built this service to hold vendors to a high standard on data privacy, so we have tried to write the policy we would want a vendor to hand us: plain language, no secondary use of your data, and a named list of the companies that help us run the Service.
1. Our role and your institution's role
The Service is sold to institutions (“Customers”). The contracts, reviews, comments, vendor records, and other content an institution puts into the Service are Customer Data. The institution controls Customer Data and decides who can see it. We process Customer Data only on the institution's behalf and under its instructions, as a service provider. Where the Family Educational Rights and Privacy Act (FERPA) applies, we act as a “school official” with a legitimate educational interest, under the institution's direct control, and we do not redisclose education records except as the institution directs or the law requires.
If your institution has a signed agreement or data protection addendum with us, that agreement controls where it differs from this policy. Questions about how your institution uses the Service should go to your institution first.
This policy also covers the smaller set of information we control ourselves, such as account details, demo requests, and website visits.
2. Information we collect
Information you give us
- Account information: your name, work email address, password (stored only as a secure hash by our authentication provider), institution, and role.
- Sign-in with Google or Microsoft: if you choose it, we receive your name, email address, and a unique account identifier from that provider. We do not receive your password and we do not access your mailbox, files, or calendar.
- Customer Data: contracts and amendments you upload, text extracted from them, AI review results, redlines, notes, comments, tasks, vendor and renewal information, and your institution profile.
- Demo requests and messages: the name, email, institution, and message you send us.
- Guest invitations: when an institution invites outside counsel or a vendor contact, we store the guest's name and email address to deliver and verify the invitation.
Information collected automatically
- Activity records: an audit log of actions in the Service (for example, who uploaded, reviewed, approved, or exported a contract), which institutions rely on for accountability.
- Technical data: IP address, browser type, and timestamps in server and security logs kept by us and our hosting providers.
- Cookies: we use only the cookies needed to keep you signed in and remember which institution you are working in. Your light or dark theme choice is stored in your browser. We do not use advertising cookies or third-party tracking pixels.
3. How we use information
- To provide the Service: store your contracts, run AI reviews, show findings and redlines, send renewal and mention alerts, and produce memos and exports.
- To secure the Service: authenticate users, enforce each institution's access controls, detect abuse, and investigate incidents.
- To support you: answer questions, respond to demo requests, and send service and billing notices.
- To improve the Service: understand, in aggregate, which features are used and where errors occur.
- To meet legal obligations and enforce our agreements.
We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use Customer Data to build profiles of individuals or for marketing.
4. How AI review works with your documents
When you run a review, the contract and your institution's rule set are sent to our AI provider (Anthropic) through its commercial API. The response is returned to the Service and stored with your contract.
- Your documents are processed only to produce your review. We do not use Customer Data to train AI models, and our AI provider's commercial terms do not permit it to train its models on content we send through the API.
- AI output can be wrong or incomplete. Findings are decision support for your staff and counsel, not legal advice.
6. Student information
The Service is built to review contracts, not to hold student records. Contracts sometimes contain personal information incidentally, such as a name in a signature block or an example in an exhibit. We treat all of it as Customer Data under the institution's control. The Service is not directed to students or to children, and we do not knowingly collect personal information from children under 13.
7. Retention and deletion
- We keep Customer Data for as long as the institution's subscription is active, or until the institution deletes it.
- When a user deletes a contract, its file, extracted text, and reviews are deleted with it.
- When a subscription ends, the institution can export its data for 30 days. We then delete Customer Data from the live Service within 60 days. Encrypted backups are overwritten on their normal rotation schedule.
- We keep account, billing, and audit records as long as needed for legal, tax, and security purposes.
8. Security
We protect information with encryption in transit and at rest, database-level row security that separates each institution's data, a private file store, role-based permissions, and audit logging. Access by our own staff is limited to what is needed to operate and support the Service.
No system is perfectly secure. If we learn of a security incident affecting Customer Data, we will notify the affected institution without undue delay and within the time its agreement or applicable law requires, and we will cooperate with its response.
9. Your choices and rights
- You can update your name and email in the Service and ask to delete your account.
- If you are a user at a Customer institution, requests to access, correct, or delete Customer Data should normally go to your institution, and we will help it respond.
- Depending on where you live, you may have rights under state privacy laws to access, correct, delete, or get a copy of your personal information, and to appeal a decision about your request. We will not discriminate against you for exercising them.
- You can unsubscribe from marketing email at any time. Service messages, such as security notices, are not optional while you have an account.
To make a request, contact us at the contact form on our home page. We will verify your request before acting on it.
10. Where data is stored
The Service is operated from the United States, and our providers store data primarily in the United States. If you access the Service from elsewhere, your information will be transferred to and processed in the United States.
11. Changes to this policy
If we make a material change, we will update the date above and notify account administrators by email or in the Service before the change takes effect. We will not use Customer Data in a materially different way without the institution's agreement.
12. Contact us
Questions about this policy or our data practices: the contact form on our home page. See also our Terms of Service.