Privacy Policy

Effective date: July 28, 2026 · Last updated: August 6, 2026

This Privacy Policy explains what information Pishik ("we," "us," or "our") collects, how we use it, and the choices you have. By using Pishik (the "Service"), you agree to this Policy. It is incorporated into our Terms of Service. If the beta acknowledgment step is active at sign-up, the Beta Program Agreement also applies — new accounts acknowledge it as part of creating an account.

The short version. We collect the minimum needed to run the Service. Your documents stay in your own storage — we keep share links and workflow state, not your files. We don't sell or share your data with anyone. We don't read your mailbox. We don't log your IP address. And this website makes no requests to third-party servers — no trackers, no analytics, no external anything. If you're here for the California disclosures, they're in Section 5 and Section 11.

1. Information we collect

  • Account information — your name, email address, password, company name, and role, together with an optional profile photo, your personal preferences (a reply-to address, view defaults, and your reminder schedule), and the timestamps recording when you joined, when you last signed in, and when you accepted our legal terms. Passwords are never stored in plain text.
  • Two-factor authentication data — every account uses two-factor authentication, so we store the secret that pairs your authenticator app with your account, your enrollment timestamp, and your backup codes (kept only as one-way hashes — like passwords, the codes themselves are never stored).
  • Workspace data — contract titles and types, document links (not the documents themselves), reviewer names and email addresses, review stages, decisions, comments and @mentions, notes and to-dos, reminders, and activity-history entries you create.
  • Sent email and its delivery record — when the Service sends a review or notification email, we record the recipient, the subject line, timestamps, the delivery status, and the message we generated and sent, so your team can prove what went out and resend it if a channel fails. What we never hold is the other direction: we do not read, sync, or store your mailbox, and replies from reviewers go to your team, not to us. (Section 3 explains how sending works.)
  • Technical data — error diagnostics from the running Service. We do not log IP addresses. Your IP address is read while a request is in flight and held briefly in memory to rate-limit sign-in and form submissions; it is never written to our database, and we keep no web access log tying an address to a person. We store no device fingerprint and no location data.
  • Messages you send us — when you use our contact form, we receive the name, email address, company, topic, subject, and message you submit, plus a referral code if you arrived through a link that carries one. We store the submission as a support ticket, send you an acknowledgement, and use it to respond to you.
  • Blog subscriptions — if you ask for email alerts from our blog or The Prof's Corner, we store the email address you entered, which of the two lists you asked for, whether you confirmed it, and the timestamps of each. Nothing is sent until you click the confirmation link we email you, and every alert carries a link to leave that list. Unsubscribing keeps a record of the address so we can honor the request. No account or workspace is created, and this address is not used for anything else.
  • Billing information — paid plans are processed by Stripe on Stripe-hosted pages. Card numbers, invoices, amounts, and billing addresses go to Stripe and never touch our servers. What Pishik keeps is the entitlement record: your workspace’s plan tier and seat count, a coarse subscription status, Stripe’s reference identifiers, any negotiated price agreed with us, and a dated timeline of subscription events (for example “plan changed” or “invoice paid”) with no amounts attached. Stripe’s handling is governed by its own privacy policy.
  • Trial codes — if you redeem a trial code at sign-up, we record the code you used and its issuance and redemption timestamps, along with the trial’s duration and seat count. No payment details are involved in a trial.

What we do not collect. Pishik does not collect Social Security numbers, driver’s licence or other government identification numbers, payment card numbers, financial account numbers, health or insurance information, biometric or genetic data, precise geolocation, or information about race, religion, union membership, sexual orientation, or any other protected characteristic. We do not ask for them and we have no field for them — please don’t enter them into contract notes, comments, or support messages. Free-text boxes such as comments, notes, and the message you send us hold whatever you choose to write in them, so please keep sensitive details out.

2. How we use information

  • To provide, maintain, secure, and improve the Service;
  • To authenticate you and protect against fraud, abuse, and unauthorized access;
  • To send transactional messages you initiate (review requests, reminders, status updates, invitations, and password resets);
  • To respond to support requests;
  • To send blog alerts to addresses that confirmed a subscription, and only for the list they confirmed; and
  • To comply with legal obligations and enforce our Terms.

We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising. Pishik has no AI features: we do not use artificial intelligence to review, analyse, summarise, or decide anything about your contracts, and we do not use your Customer Data, workflow metadata, or reviewer information to train, fine-tune, or evaluate any machine-learning model — ours or anyone else's. Nor do we send it to any third-party AI service.

3. How email is sent

Review and notification emails are sent automatically by the Service through a single delivery channel that we operate and configure. On the hosted Service that channel is Azure Communication Services, named as a subprocessor in Annex III of our Data Processing Addendum. Messages leave from a Pishik sending address, carry your company name and logo, and direct replies to your team. Every send is recorded as described in Section 1 — who it went to, what it said, and whether it arrived.

Replies from reviewers go to your team's reply-to address — yours, or a company-wide one your admin sets — not to us. When you use a third-party storage provider (for example, SharePoint, OneDrive, or Google Drive), your use of that provider is governed by its own privacy policy.

4. Cookies, analytics & tracking

The Service sets exactly one cookie: pishik_sid, a strictly necessary session cookie that keeps you signed in. It is HttpOnly (script on the page cannot read it), it is sent over HTTPS, it expires after 30 days, and it holds nothing but an opaque session reference. We do not use advertising cookies, third-party tracking cookies, or analytics services of any kind.

This website is fully self-hosted: its pages, styles, scripts, images, and fonts are all served from our own domain. Visiting it makes zero requests to third-party servers — no analytics beacons, no tracking pixels, no social-media embeds, no external fonts or CDNs. This is enforced, not merely intended: our Content Security Policy blocks off-origin scripts, styles, frames, and images, and an automated test in our release pipeline fails the build if any page ever references a third-party host.

5. How we respond to Do Not Track signals

Pishik does not track you across other websites or online services. We do not collect personally identifiable information about your online activities over time or across third-party websites, and we do not allow anyone else to do so through our website or application.

Because we do not engage in that collection, a Do Not Track (DNT) signal from your browser does not change what we collect. We treat every visitor identically whether or not the signal is present — nobody is tracked, with it or without it. We do not participate in any third-party choice program or protocol for online tracking, because we conduct no online tracking to opt out of.

Other parties on our site

No other party collects personally identifiable information about your online activities over time or across different websites when you use the Pishik website or application. There are no third-party analytics tools, advertising networks, tag managers, session-replay tools, social-media embeds, chat widgets, content delivery networks, or externally hosted fonts on any page we serve. The single session cookie described in Section 4 is ours, is not used for advertising or profiling, and is not readable by anyone else.

6. Service providers & hosting

We do not sell or share personal information, and we disclose it to no one for advertising or marketing. We do share it with the small set of vendors that operate the Service on our behalf, each bound by contract to use it only to provide services to us and to maintain reasonable security. Those categories, with the vendors currently in each:

  • Cloud hosting and infrastructure — an established enterprise cloud provider, in the United States. This is where the Service runs and where your workspace data rests. We name the provider, along with every other subprocessor, in Annex III of our Data Processing Addendum.
  • Payment processingStripe, Inc. When an administrator starts checkout, their email address, your workspace name, and its identifier go to Stripe so it can issue receipts and run the subscription. Nothing else about your workspace is sent, and card details are collected by Stripe directly (Section 1).
  • Email deliveryMicrosoft Corporation (Azure Communication Services), the channel through which the Service sends every review request, reminder, and notification, as well as blog-subscription confirmations and alerts. It receives the recipient address, subject, and message content of that mail, and nothing else about your workspace.

That is the complete list. We disclose personal information to no advertisers, no data brokers, no analytics providers, and no marketing partners. Your Documents remain in your own storage (for example, SharePoint, OneDrive, or Google Drive) and are not transmitted to or stored by us. Our current vendors are listed in Annex III of our Data Processing Addendum, which we update before any change takes effect.

7. Data retention

Pishik is built so that your workspace records — contracts, reviewers, decisions, comments and their history — do not disappear on a timer; an audit trail you cannot rely on is worth very little. The things that do go on their own are short-lived security records, and the audit trail is capped by volume rather than by age. That is also the honest answer to how long we keep things, so here it is by category rather than as a single period.

WhatHow long we keep it
Workspace data — contracts, share links, reviewers, decisions, comments, @mentions, delegations, notes, and the sent-email recordFor as long as your workspace exists, until your administrator removes the item or you ask us to erase the workspace. There is no automatic expiry.
Account records — profile, preferences, credentials, two-factor materialFor the life of the account. Offboarding a teammate archives their account rather than erasing it, so it can be restored; erasure is a separate request.
Workspace audit trailCapped per workspace — we keep the most recent entries and age out the oldest. Billing, membership, role, and ownership events sit on a separate allowance ten times larger than the one covering routine activity, and data exports have an allowance of their own.
Sign-in sessions30 days at most, and deleted as soon as they expire, you sign out, or you change your password.
Email verification codesMinutes. Deleted on use and swept continuously.
Support tickets and their conversationKept as our record of the request and our answer, including after a workspace closes. Settled tickets are filed away automatically; erasure is by request.
Billing and trial records — subscription event timeline, trial codes and the address that redeemed themKept as our financial and entitlement record, including after a workspace closes, for as long as tax, accounting, and audit obligations require.
Blog subscriptions — the address entered on the blog or The Prof’s Corner, which lists it holds, and the confirmation timestampsAn address that never confirms is deleted automatically after 30 days. A confirmed address is kept until you unsubscribe or we remove it. Unsubscribing records the address on a do-not-email list so we can honour the request — that record is the opt-out itself, and it is kept.

You can export your data at any time and may ask us to erase a contract record or an entire workspace. Following cancellation or termination of a paid subscription, Customer Data remains available for export for at least forty-five (45) days.

What erasing a workspace does and does not do. When we erase a workspace we permanently remove its accounts, sign-in sessions, contracts and share links, reviewers and their decisions, comments and their edit history, @mentions, delegations, reassignments, notifications, and audit history. We deliberately keep a small set of records that are ours rather than yours: support tickets and their messages, our internal account notes, trial-code redemption records, and the subscription event timeline, together with a single log entry recording that the erasure happened. We keep these because they are our own business, tax, and support records — but if you want them erased too, say so in your request and we will tell you what we can remove and what the law requires us to keep.

8. Security

We maintain reasonable security procedures and practices appropriate to the nature of the information we hold, as California law requires. In practice that means: encryption in transit and at rest; mandatory two-factor authentication on every account, which nobody can switch off; passwords and backup codes stored only as one-way hashes; server-enforced session expiry and optional idle sign-out; strict per-workspace isolation, so one customer’s records are never reachable from another’s; role-based access; an audit trail that records who did what; and single-use, expiring reviewer links. The strongest control is architectural — because your contract files never enter our systems at all, there is far less to lose if anything goes wrong.

No method of transmission over the Internet or method of electronic storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for keeping your account credentials confidential and for maintaining your own backups of important data. If a security incident ever affects your personal information, we maintain a documented response process and will notify you and, where the information belongs to one of our customers, that customer — without undue delay and within the periods the law requires. For a plain-language description of how the Service is built, see Security & privacy in our Support Center.

9. Reviewers who receive our email

If an organization that uses Pishik asks you to review a contract, you do not need an account, and we keep only what the review itself requires: your name and email address (plus any title, department, or note the organization adds to its reviewer list), the decision you record — approve or reject, with any note you type on the decision page — and timestamps showing when review emails were sent to you and when your decision was recorded. Pishik stores this information on behalf of the organization that contacted you. Your review link is personal and single-use, it expires, and nothing is recorded until you confirm your decision.

To have your contact details removed, start with the organization that contacted you — the records belong to their workspace. You can also reach us through our support contact form and we will help coordinate. Privacy for reviewers has the details.

10. Your rights & choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. We honour these requests for everyone, wherever you are — see Section 11 for how that commitment works and how to make a request. If you are a reviewer rather than an account holder, see Section 9 first: those records belong to the organization that contacted you.

Reviewing and correcting your information yourself

Most of it you can change without asking us:

  • Your profile and preferences — open Settings in the app to edit your name, photo, reply-to address, and reminder schedule.
  • Your email address — also in Settings. Because it is your sign-in identity, changing it takes proof that you hold the new mailbox as well as proof that you are you: you type the new address and press Send code, we email a 6-digit code to that new address, and you enter that code together with your current password and a code from your authenticator app (or one of your backup codes). An address that already has a Pishik account cannot be used. Changing it resets your two-factor enrollment and signs you out everywhere, and we send a notice to your previous address.
  • Your password and two-factor setup — in Settings, under Security.
  • A copy of your data — any member can export their own contracts and history from Settings → My data; an administrator can export the entire workspace, including the server-kept records. See Export and restore your data.
  • Workspace content — contracts, reviewers, and workflow settings are edited by your team in the app. If a reviewer’s details are wrong, your workspace administrator can correct them directly.

For anything the app itself cannot do — including erasure — contact us and we will handle it.

11. Your California privacy rights

Pishik Labs is based in California, and we publish the disclosures below for everyone who uses the Service, whether or not any particular privacy law applies to us. Sections 1 and 6 above already set out, in the detail California law asks for, what we collect, where it comes from, why we hold it, who it goes to, and how long we keep it.

We do not sell or share your personal information — not for money, not for anything else of value, and not for cross-context behavioural advertising. We never have. There is nothing to opt out of, which is why you will not find a “Do Not Sell or Share My Personal Information” link on this site: we would have nothing to put behind it.

What you can ask us for

Whether or not the law obliges us in your case, we will honour these requests from anyone whose personal information we hold:

  • To know what personal information we hold about you, where we got it, why we have it, and who we have disclosed it to.
  • To get a copy of it in a portable format — the export described in Section 10, or a file we prepare for you.
  • To correct anything inaccurate.
  • To delete it, subject to the records we must keep for legal, tax, security, and accounting reasons (Section 7 says exactly which those are).
  • Not to be treated differently for asking. We will not deny you service, change your price, or degrade your experience because you exercised a privacy right.

How to make a request

Send it through the contact form in our Support Center and choose the Privacy & data topic — that is our designated channel for privacy requests, and it reaches the team that runs Pishik directly. Tell us what you want and the email address your information is under.

Verifying it is you. We will ask you to confirm the request from the email address on the account, and for anything beyond a simple copy we may ask you to confirm details we already hold. We will not ask you for a government ID, and we will never ask for your password. We only use what you send us to verify the request, and we delete it afterwards.

Someone acting for you. An authorized agent may submit a request on your behalf. We will ask for written permission signed by you, and we may confirm directly with you before we act.

How quickly. We aim to acknowledge within 10 days and to answer substantively within 45 days. If a request is complex we may take up to another 45 days, and we will tell you before we do. There is no charge.

Shine the Light

California’s “Shine the Light” law (Civil Code § 1798.83) lets California residents ask whether a business disclosed their personal information to third parties for those third parties’ own direct marketing during the previous calendar year. Pishik has never disclosed personal information for third-party direct marketing, so we have no such disclosure to report. The vendors in Section 6 receive information only to perform services for us, which is not disclosure for direct marketing. If you would like that confirmed in writing, ask us through the contact form and we will send it at no charge.

If you are a reviewer, or your details came from your employer

When one of our customers loads reviewer details into their workspace, that organization decides what to collect and why; we hold it on their behalf and use it for nothing else. Requests about that information should go to the organization that contacted you, which can correct or remove the record directly. Reach us anyway if that is difficult — we will help coordinate, and we assist our customers in answering these requests as a matter of contract (see our Data Processing Addendum). What we will not do is quietly change or delete a customer’s records on a stranger’s say-so.

12. International users

The Service is operated from the United States, and your information is processed there. By using the Service, you consent to that transfer and processing, in a country whose data-protection laws may differ from your own. Where we process personal information on behalf of a customer subject to the GDPR or UK GDPR, we do so as a processor under the terms of our Data Processing Addendum, which sets out the safeguards that apply to those transfers.

13. Children

Pishik is a business service intended solely for organizations and their authorized personnel. It is not directed to children, and accounts require you to be at least 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. Every change is reflected in the effective date at the top of this page, and we record material changes to our legal documents in our release notes, which is the canonical log. For a material change to how we use or disclose personal information, we will additionally give at least 30 days’ notice before it takes effect — by email to each workspace owner and by notice inside the app. We review this Policy at least once a year even when nothing has changed. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

15. Contact

Questions or requests regarding privacy — including access, export, correction, or deletion requests? Reach us through the contact form in our Support Center, choosing the Privacy & data topic. It goes straight to the team that runs Pishik. Our postal address is available on request through the same form.