Your vendor contracts contain sensitive commercial terms. This page explains how Renewly authenticates you, controls who can reach that information, and records every access. Where the data physically lives, and which sub-processors touch it, is on the trust page.
Passwordless by default, hardware keys supported
Renewly uses passwordless authentication. Instead of a password, you receive a magic link by email. There is no stored password to leak or guess. Rate limits apply per intent: 20 login requests per 15 minutes, 5 for signup, and 3 for account recovery. Recovery sends a magic link, not a password reset.
You can also register a passkey - Touch ID, Face ID, or a hardware security key (YubiKey, Titan Key). Passkeys use the WebAuthn standard and are bound to your device. You can register multiple passkeys and name or revoke them individually from your account settings.
Two-factor authentication (TOTP) is available as an additional layer. Disabling TOTP requires completing a second authentication step (AAL2) - a session-hijacked attacker at a lower assurance level cannot turn off your 2FA.
Magic links are tied to a trusted origin allowlist. Links generated for one domain cannot be redirected to an external host.
In transit and at rest
All data sent between your browser and Renewly is encrypted with TLS 1.3. Contract files and extracted data stored in our database are encrypted at rest using AES-256.
We never store payment card information. All billing is handled directly by Stripe.
Where your data lives
Renewly is a dual-region service. You choose EU or US at signup and your data stays there for the life of the workspace. See the trust page for the full residency map.
Who can see what
Every database query is enforced by row-level security (RLS). Access is checked at the database layer, not just in application code. A user can only query contracts that belong to them or to their organization.
Once a user joins an organization, they see only that organization's contracts. Personal data stays out of the organization view, and organization analytics are scoped to the contracts in that workspace.
Workspace switching is handled server-side with membership validation. Switching to an organization you are not a member of is rejected at the server, not just the client.
What happened and when
Renewly writes an audit log entry for every significant user action: authentication events (login, logout, MFA changes, passkey registration and revocation), contract operations (upload, download, delete, version upload), billing events (subscription created, cancelled), team events (invitations, role changes), and account changes (profile update, data export, deletion request).
Audit logs are retained for 3 years for security and compliance purposes. Your own audit log is included in any data export you request.
You control when data is removed
You can delete any individual contract at any time. Deleted contracts and their associated files are permanently removed.
If you delete your account, all your data is removed after a 30-day grace period. You can export your data before deletion. Backups are purged after 30 days.
Organization workspaces can configure a data retention policy to automatically purge records older than a set threshold. This runs on a scheduled basis and writes an audit entry for every purge event.
Audit logs are retained for 3 years for security and compliance purposes.
Your rights under data protection law
Non-essential trackers (analytics and session recording) are blocked until you give explicit consent. The consent prompt appears on first visit. You can revisit your choice at any time from Settings → Account → Cookie Preferences.
Essential services (Crisp live chat for support) are not consent-gated because they are functional rather than marketing tools. All other third-party tracking is off until you accept.
Under GDPR Article 15, you can export all personal data Renewly holds about you. The export covers your profile, contracts and extracted data, tags, notifications, audit logs, inbox aliases, vendor alerts, session records, calendar integrations, and webhook endpoints. Credential material (OAuth tokens, webhook secrets) is redacted from the export.
EU and EEA users have full rights to access, correct, delete, and export their personal data. We have a signed DPA with Supabase.
Not by our LLM extraction providers: Gemini (via Google Vertex) and Claude (via AWS Bedrock) do not train on your data, and contract text is not retained after processing, per Google Vertex terms and AWS Bedrock data protection terms.
Production access is restricted to a single named administrator, and every access event is logged. Contract content is not accessed in normal operation. Access for support purposes requires your explicit consent first.
Your data remains accessible. If you downgrade to the free tier and exceed 5 contracts, you can still view all your contracts but cannot add new ones until you are within the limit.
Not yet. Renewly currently supports passwordless email authentication (magic links), passkeys (Touch ID, Face ID, hardware keys), and optional TOTP two-factor authentication. SSO is on our roadmap.
Yes. Under GDPR Article 15, you can request a full export of your personal data from Settings. The export covers your profile, contracts, extracted data, tags, notifications, audit logs, inbox aliases, vendor alerts, session records, calendar integrations, and webhook endpoints (with credentials redacted). Your original uploaded PDF files are also downloadable at any time.
Go to Settings → Account → Cookie Preferences. You can accept or reject non-essential trackers (analytics and session recording) at any time. Changes take effect immediately.
If you have questions about how we handle your data, or if you need to report a security concern, contact us directly.
security@renewly.gg