Privacy Notice
Effective January 1, 2026
1. Who we are
This Privacy Notice describes how Second Look AI (“Second Look AI,” “we,” “us,” or “our”) collects and uses personal data in connection with the Second Look AI service (the “Service”). Second Look AI is the data controller for personal data processed through the Service. Our payment processor, Stripe, acts as a separate data controller for cardholder data (see Section 4).
2. Personal data we collect
- Account data: name, email address, hashed login credentials.
- Customer content: case information, documents, and other records you upload.
- Support communications: messages you send us.
- Usage and device data: pages viewed, actions taken, IP address, browser and device identifiers, log and telemetry data.
- Payment metadata: subscription status and a customer identifier returned by our payment processor. Full card details are handled by Stripe and never touch our servers.
3. How and why we use personal data
- Create and secure your account and authenticate you (legal basis: contract).
- Provide the Service, including generating AI-powered analyses, timelines, and drafts from your uploaded records (contract).
- Prevent fraud, abuse, and security incidents, and enforce our Terms (legitimate interests).
- Provide customer support (contract / legitimate interests).
- Improve the Service, including debugging and product analytics (legitimate interests).
- Comply with legal obligations, including tax, accounting, and lawful requests (legal obligation).
4. Who we share personal data with
We share personal data only with the following categories of recipients:
- Payment processor — Stripe. Stripe, Inc. processes payments, subscription billing, and refunds, and provides the customer billing portal. Stripe is a separate data controller for cardholder data. See Stripe’s Privacy Policy.
- Cloud infrastructure and storage providers that host the Service, its database, authentication, and encrypted document storage.
- AI model providers used to generate case analyses, timelines, and drafts from your uploaded records.
- Error monitoring and analytics providers used to keep the Service secure and reliable.
- Professional advisers (legal, accounting) where reasonably necessary.
- Authorities where required by law, subpoena, or valid legal process.
We do not sell personal data, and we do not share it with third parties for their own marketing.
5. Retention
We retain personal data only for as long as we need it for the purposes above. Account and case data are retained while your account is active and for a reasonable period after closure to comply with legal obligations and resolve disputes. Payment records handled by Stripe are retained per Stripe’s policies. Aggregated or de-identified data may be retained indefinitely.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict our use of your personal data, and to object to certain processing or withdraw consent. You can also request deletion of your account from your account settings, or by contacting us through our contact page. Users in the UK/EEA also have the right to lodge a complaint with their local supervisory authority.
7. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest for uploaded documents, access controls, and row-level security on user data. No system is perfectly secure, and we cannot guarantee absolute security.
8. International transfers
Personal data may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
9. Cookies
We use strictly necessary cookies and local storage to keep you signed in and to run the Service. We do not use advertising cookies.
10. Changes and contact
We may update this Privacy Notice from time to time. For questions or to exercise your rights, reach us through our contact page.