OnRecord.

Privacy

last updated 27 September 2026

OnRecord handles the details of deals between two people, and sends parts of them to an AI model. So what happens to that data is the central question, not a footnote. This page answers it specifically.

1. Who is responsible

OnRecord is operated by Shamil Bedru, trading as OnRecord, who decides how and why this data is used and is the data controller. Privacy questions and requests: shamil.bedru.hassen@gmail.com.

2. What we collect

  • Owner accounts. Your email address, your credit balance, and Paddle’s customer ID once you buy credits. No password: sign-in links are stored only as a hash and expire after 15 minutes.
  • Agreements. The title, the counterparty’s name and email address, any transcript you paste, the commitment lines, confirmations and disputes (with any comment), amendments, verdict questions and answers, and a timestamped log of every action on the record.
  • Counterparties. If someone sent you an agreement, we hold the name and email they entered for you, and what you do on the agreement page: which lines you confirmed or disputed, when, and any comment you wrote. You never need an account.
  • Payments. Paddle’s transaction ID, the pack you bought, and the amount. Your card details go to Paddle and never reach us.
  • Technical. Our host’s request logs and our error logs, used only to keep the service running and fix faults.

There is no analytics or advertising code on OnRecord, we don’t send marketing email, and we don’t sell, rent, or trade your data.

3. Why we use it

To run the service you and the other party are using: creating, confirming, and locking agreements, emailing links, PDFs, and verdicts to both parties, and charging for credits. That is performance of our contract with you. Keeping the service secure and free of abuse is our legitimate interest. For counterparties, processing your details is our legitimate interest in letting someone who works with you put your agreement on record; you can ignore the emails and nothing is recorded as confirmed.

4. Who else processes it

  • Moonshot AI (Kimi) turns pasted transcripts into commitment lines, and writes verdicts. It receives the transcript for extraction; for a verdict, only the confirmed lines, the timestamps of actions on the record, and the question asked. Never your email address or payment details.
  • Neon hosts our database, so it stores everything in section 2.
  • Resend delivers our emails, so it receives the recipient’s address and the email’s content, including attached PDFs.
  • Paddle takes payment as our merchant of record and handles your payment details under its own responsibility and privacy policy.
  • Vercel serves the site and sees the request metadata any web host sees, such as your IP address and browser.

These providers operate internationally, so your data may be processed outside the country you are in. We don’t train AI models on your content; what providers do under their own terms is governed by those terms. We’ll update this list before adding a provider that receives your content.

5. Cookies

One cookie, set by us, strictly necessary: it keeps owners signed in for up to 30 days. It is HttpOnly, SameSite=Lax, and Secure. Counterparties get no cookie at all. Paddle’s checkout sets its own cookies when you buy credits, under Paddle’s policy. Fonts are bundled with the site, so loading a page tells no one else that you did. That’s why there’s no cookie banner.

6. How long we keep it

Accounts and agreements are kept while the owner’s account exists: a record is only useful if it’s still there when a dispute comes up. Sign-in links are useless after 15 minutes and agreement links after 14 days. Payment records are kept as long as tax and payment rules require.

7. Your rights

You can ask for a copy of what we hold about you, ask us to correct it, object to processing, or ask us to delete your account and its agreements, which we’ll complete within 30 days of confirming the request. A locked record belongs to two people, and PDFs already emailed to the other party stay with them; we can’t recall those. Email shamil.bedru.hassen@gmail.com from the address you use with OnRecord; we may ask you to confirm it’s you, because acting on a forged request would be worse than the delay. You can also complain to the data protection authority where you live.

8. Security

All traffic is encrypted in transit. Sign-in and agreement links are random 32-byte tokens stored only as hashes. Every action on a record is written to a hash-chained log and locked records are fingerprinted, so tampering is detectable. No system is perfect: if a breach affects your data, we’ll tell you what we know promptly.

9. Age

OnRecord is for adults, 18 and over. We don’t knowingly collect data from anyone younger.

10. Changes

When this policy changes materially, we’ll email owners before it takes effect. The date at the top always reflects the current version. The Terms cover the rest of the agreement.