Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how Lens (“we”, “us”) processes personal data when you use our document intelligence platform. Lens is designed for confidential finance and legal work; data protection is a product requirement, not an afterthought.

Who we are

Lens is the data controller for account and billing data, and the data processor for the documents and content you upload. For processor terms, see our Data Processing Agreement.

What we collect

Account data: name, work email, organization, role, and authentication records. Billing data: plan, subscription status, and payment metadata (card details are handled by Stripe; we never store them). Content: the documents, analyses, chats, and theses you create. Usage data: product events and audit logs used for security and to operate the service.

Where your data lives

Application hosting, database, and document storage are located in the European Union. Data is encrypted in transit (TLS) and at rest.

AI processing

Analysis is powered by Anthropic’s Claude API under commercial terms that prohibit training on your data. Document content is sent for processing only when you run an analysis, and only the excerpts required to answer.

Connected cloud storage

You can connect Dropbox, Box, OneDrive, or SharePoint so that documents already held there can be analysed in Lens without being re-uploaded by hand. A connection is made by you, per workspace, and can be revoked at any time from Settings → Integrations. Revoking a connection stops all further access immediately.

Dropbox. When you connect Dropbox, Lens requests read-only access and uses exactly three permissions: files.metadata.read to list the folders you choose and see file names, sizes, and modification dates so it can tell what is new; files.content.read to download the contents of the files in those folders so their text can be extracted, indexed, and cited in your analyses; and account_info.read to read the account name and email, which is shown as the label on the connection so you can tell several connected accounts apart.

Lens never writes to, modifies, renames, moves, or deletes anything in your Dropbox. The integration requests no write permission of any kind, so it is not technically capable of changing your Dropbox contents. Data flows one way only, from Dropbox into your Lens workspace. Only the folders you explicitly select are read, never your whole account. Files copied into Lens are stored encrypted in the European Union and are deleted when you delete them in Lens or close your account. Deleting a file in Lens does not affect the original in Dropbox.

The same read-only principle applies to Box, OneDrive, and SharePoint: Lens requests read and offline-access permissions only, never write or delete.

Your rights (GDPR)

You may access, export, correct, or delete your personal data. Workspace owners can export and delete organization data from Settings → Compliance. To exercise any right, email contact@getlens.xyz. We respond to verified requests within the timeframes required by applicable law.

Retention

We retain content for the life of your account. On deletion, content is removed from production systems and ages out of backups on a fixed schedule.

Subprocessors

These are the providers that may process your data on our behalf, and what each one does:

  • Vercel, application hosting.
  • Supabase, database, authentication, and document storage, EU region.
  • Anthropic, AI analysis of document excerpts, under terms that prohibit training on your data.
  • Voyage AI, text embeddings for semantic search across your documents.
  • Stripe, subscription payments. Card details go directly to Stripe and are never stored by us.
  • Resend, transactional email such as invitations and notifications.
  • Upstash, rate limiting. Processes request metadata, not document content.
  • PostHog, product analytics, EU region. Records which screens and features are used, associated with your account, so we can see what is working. It does not receive document content.
  • Sentry, error monitoring. Receives technical diagnostics when something fails — the route, the error and the account it happened on — so faults can be traced. It does not receive document content.
  • WorkOS, enterprise single sign-on, for organisations that enable it. Processes the identity data your identity provider returns (name, email, directory identifiers). Not used unless you configure SSO.

Connected cloud storage providers are not subprocessors: they are your own accounts, which you choose to read from. This list accompanies the DPA and is updated when it changes.

Some features query public reference sources — a company registry, or public macroeconomic series — when you ask for them. Those requests carry the search term you entered, never your documents, and the providers act as independent controllers of their own public data rather than as our processors.

Contact

Privacy questions and data requests: contact@getlens.xyz.