Pactlog

Privacy

Last updated 19 September 2026

Pactlog is deal-operations software for creators. This page describes exactly what we store, what a connected mailbox is used for, and how to get your data out or delete it. It describes how the product actually works today, during our private pilot.

What we store

Only what the product needs to keep your deal records straight:

  • Account details: your name, email address, optional business name and currency.
  • Deal records: brands, campaign details, amounts, dates, terms, obligations, deliverables, approvals, payment status and renewal dates that you or your sources provide.
  • Sources: emails you paste or that Pactlog ingests from a connected mailbox, plus files you upload.
  • Change history: proposed changes to your deal terms, their source, and how you resolved them.
  • Product usage events: which workflows are used, so we can tell whether Pactlog is genuinely useful. These record the action, not the content of your deals or messages.

Passwords are stored only as a salted scrypt hash. We never store card numbers, bank credentials, or government identifiers — Pactlog does not process payments.

Connected email (Gmail)

Connecting a mailbox is optional. Pactlog works fully without it — you can paste emails, upload briefs, or enter deals by hand.

If you do connect Gmail:

  • Pactlog requests read-only access. It cannot send, delete, or modify any message.
  • Pactlog does not read your whole mailbox. It searches only for messages matching the brands, contacts and campaigns already on your deals — if you have no deals, it runs no search at all.
  • Messages that match are stored as sources on the relevant deal so the record shows where a term came from.
  • Spam, trash and drafts are excluded.
  • Your Google tokens are encrypted at rest and are only ever used server-side. They are never sent to your browser.
  • You can disconnect at any time in Settings. Disconnecting revokes Pactlog's access with Google immediately.

Pactlog is not an email client and does not replace your inbox. Email is only an input for keeping deal records current.

AI processing

Pactlog uses an AI model to read a source and suggest structured deal terms — an amount, a posting date, payment terms, and so on. The text of that source is sent to the model provider for this purpose and for nothing else. When no AI provider is configured, Pactlog falls back to a built-in parser and the product still works.

The provider currently processing that text is Groq. Pactlog can also be configured to use Anthropic’s Claude. Whichever is active is named on your Settings page, so you can always see where your text is going rather than having to take this page’s word for it.

Under our agreement with them, the provider may not use what we send to train or fine-tune any model. They do not retain inference requests by default, though they may hold them briefly — up to 30 days — to keep the service reliable and detect abuse.

AI output is always a suggestion. It never becomes your confirmed deal terms on its own, never accepts a change, and never sends anything on your behalf. You confirm what the record says.

Google user data

Pactlog’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, data obtained from your Gmail account is never:

  • Sold, or transferred to anyone except as needed to provide the features described on this page.
  • Used to serve you advertising of any kind.
  • Read by a human at Pactlog, except where you explicitly ask us to look at something, where security requires it, or where the law compels it.
  • Used to train generalised AI or machine-learning models.

Files you upload

Briefs, contracts and other documents are stored in private storage outside the public web root. They are served only through an authenticated route that checks you own the file first. There is no public link to a private document.

Who can see your data

Your deals are scoped to your account. No other Pactlog user can read them. During the pilot, the Pactlog team can access production data when necessary to operate the service or investigate a problem you report.

We do not sell your data, and we do not use your deal contents or messages to advertise to you.

Export and deletion

Settings has a data export that returns your account, sponsors, deals, terms, obligations, deliverables, approvals, payment records, renewals and change history as JSON.

Settings also has account deletion. Deleting your account removes your user record and everything attached to it — deals, sources, uploaded files and any connected-mailbox credentials — and revokes Pactlog’s Google access if a mailbox was connected. Product usage events are retained in aggregate without your deal contents.

Retention

We keep your data while your account exists. Because Pactlog is in private pilot, we may contact you about your experience with the product; you can ask us to stop at any time.

Contact

Questions about your data, or want it removed? Email privacy@pactlog.online.