The original source is not retained
A pasted message, image, or PDF is held only long enough to validate and analyze it. SecondLook does not save the original source to your account or Supabase Storage.
Privacy in plain English
This page explains the paid beta's current data practices. It is practical product information, not a promise that every infrastructure backup disappears immediately or a claim of regulatory compliance.
A pasted message, image, or PDF is held only long enough to validate and analyze it. SecondLook does not save the original source to your account or Supabase Storage.
For signed-in users, the validated analysis result, including extracted details and short evidence excerpts when present, plus a sanitized source label are saved to Supabase until the user deletes them.
You can delete one result, all analysis history, or the whole SecondLook account. Account deletion ends all active subscriptions associated with the trusted Stripe Customer before deleting application data and signing you out.
Stripe processes subscription payments, stores payment methods, and hosts invoices and cancellation controls. SecondLook does not receive or store complete card details.
SecondLook stores analysis counts, source type, input byte count, model name, and numeric token totals. Usage accounting never stores the complete source or complete model result.
SecondLook does not open links, call a number, contact a sender, send money, or follow instructions found in submitted content.
store: false.A saved record can include the risk level, summary, extracted details, warning signs, safe next steps, confidence, limitations, short quoted evidence excerpts, analysis status, model name, date, and a sanitized label such as a filename. It does not include complete pasted text, uploaded file bytes, full document text, account credentials, or authentication tokens.
A separate usage row records the allowance period, source type, input byte count, status, model name, and numeric input/output/total token counts when supplied. It does not contain the complete source, OCR text, or complete model response.
OpenAI processes source content to produce the analysis. Supabase provides authentication, private result storage, subscription state, and atomic usage accounting. Stripe processes subscriptions and billing and hosts Checkout and the Customer Portal. Hosting and infrastructure providers may process technical request metadata needed to operate and secure the service.
store: falseprevents OpenAI response-state storage for the request, but it is not the same as Zero Data Retention. Under OpenAI's default API controls, abuse-monitoring logs may include customer content and are generally retained for up to 30 days, subject to approved controls and limited safety or legal exceptions. Review OpenAI's current API data controls for current details.
SecondLook stores trusted Stripe Customer, subscription, Price, and Product identifiers, subscription status, billing-period dates, cancellation state, and bounded webhook processing metadata. It does not store complete card numbers, card security codes, payment-method details, complete invoices, or complete webhook payloads. Stripe and other billing providers may retain transaction records according to their legal and operational requirements.
Payment methods, invoices, billing history, and cancellation are managed through Stripe's hosted Customer Portal. SecondLook does not build or host a card-entry form.
Deleting a SecondLook account first asks Stripe to delete the trusted Customer mapping, which immediately ends active subscriptions associated with that Customer. Only after that deletion is confirmed does SecondLook delete the application account and its saved results, local billing mappings, and usage rows. If Stripe cannot confirm deletion, the application account remains so the user is not unknowingly left subscribed. Account deletion does not automatically issue a refund or erase financial records Stripe must retain.
Results are guidance, not a guarantee that a sender, organization, contact detail, or payment request is legitimate or safe. For consequential requests, pause and verify using contact information you found independently through a source you already trust.