Back to the analyzer

Privacy in plain English

Your original request is not kept. Your result is yours to manage.

This page explains the paid beta's current data practices. It is practical product information, not a promise that every infrastructure backup disappears immediately or a claim of regulatory compliance.

The original source is not retained

A pasted message, image, or PDF is held only long enough to validate and analyze it. SecondLook does not save the original source to your account or Supabase Storage.

The structured result is saved privately

For signed-in users, the validated analysis result, including extracted details and short evidence excerpts when present, plus a sanitized source label are saved to Supabase until the user deletes them.

You control your saved history

You can delete one result, all analysis history, or the whole SecondLook account. Account deletion ends all active subscriptions associated with the trusted Stripe Customer before deleting application data and signing you out.

Stripe hosts payment and billing management

Stripe processes subscription payments, stores payment methods, and hosts invoices and cancellation controls. SecondLook does not receive or store complete card details.

Bounded usage metadata protects service costs

SecondLook stores analysis counts, source type, input byte count, model name, and numeric token totals. Usage accounting never stores the complete source or complete model result.

No action is taken for you

SecondLook does not open links, call a number, contact a sender, send money, or follow instructions found in submitted content.

What happens during a live analysis

  1. You sign in, then submit one pasted message or supported file to SecondLook's server.
  2. The server verifies your session and checks the source's length, file type, size, PDF page count, or image pixel count.
  3. The server atomically reserves one trusted plan allowance. A denied reservation is not sent to OpenAI.
  4. The source is sent to OpenAI once for AI analysis with response storage disabled using store: false.
  5. The server validates and safety-checks the structured response before displaying it.
  6. The structured result is saved privately to your Supabase-backed account. The complete original file or message is discarded after request processing and is not reproduced in history, though the structured result may retain extracted fields and short evidence excerpts.

A saved record can include the risk level, summary, extracted details, warning signs, safe next steps, confidence, limitations, short quoted evidence excerpts, analysis status, model name, date, and a sanitized label such as a filename. It does not include complete pasted text, uploaded file bytes, full document text, account credentials, or authentication tokens.

A separate usage row records the allowance period, source type, input byte count, status, model name, and numeric input/output/total token counts when supplied. It does not contain the complete source, OCR text, or complete model response.

Service providers and request metadata

OpenAI processes source content to produce the analysis. Supabase provides authentication, private result storage, subscription state, and atomic usage accounting. Stripe processes subscriptions and billing and hosts Checkout and the Customer Portal. Hosting and infrastructure providers may process technical request metadata needed to operate and secure the service.

store: falseprevents OpenAI response-state storage for the request, but it is not the same as Zero Data Retention. Under OpenAI's default API controls, abuse-monitoring logs may include customer content and are generally retained for up to 30 days, subject to approved controls and limited safety or legal exceptions. Review OpenAI's current API data controls for current details.

SecondLook stores trusted Stripe Customer, subscription, Price, and Product identifiers, subscription status, billing-period dates, cancellation state, and bounded webhook processing metadata. It does not store complete card numbers, card security codes, payment-method details, complete invoices, or complete webhook payloads. Stripe and other billing providers may retain transaction records according to their legal and operational requirements.

Billing management and account deletion

Payment methods, invoices, billing history, and cancellation are managed through Stripe's hosted Customer Portal. SecondLook does not build or host a card-entry form.

Deleting a SecondLook account first asks Stripe to delete the trusted Customer mapping, which immediately ends active subscriptions associated with that Customer. Only after that deletion is confirmed does SecondLook delete the application account and its saved results, local billing mappings, and usage rows. If Stripe cannot confirm deletion, the application account remains so the user is not unknowingly left subscribed. Account deletion does not automatically issue a refund or erase financial records Stripe must retain.

Your choices and important limits

  • Delete an individual result from its saved-analysis page.
  • Delete all saved analysis history while keeping the account active.
  • Delete the account and its saved analysis history.
  • Manage payment methods, invoices, and subscription cancellation in Stripe's hosted portal.
  • Use built-in fictional demos without signing in; demo results are deterministic and are not saved.

Results are guidance, not a guarantee that a sender, organization, contact detail, or payment request is legitimate or safe. For consequential requests, pause and verify using contact information you found independently through a source you already trust.