Privacy Policy

Last updated: June 9, 2026

This Privacy Policy describes how Qawaid (“we”, “our”, or “us”) collects, uses, and shares information about you when you use our unified platform for document intelligence (Lucid AI) and business-rule evaluation (Smart Rules).

Information We Collect

  • Account data: Name, email address, and organization name provided during registration.
  • Documents uploaded: Files you upload to the platform for processing (invoices, contracts, forms, and other documents).
  • Rules and decision logic: The rules, conditions, and decision tables you author in Smart Rules, along with the inputs you evaluate against them.
  • Usage data: API calls, document processing counts, validation results, and feature usage metrics.
  • Payment information: Billing details are handled directly by the configured payment provider. We do not store raw card data.

How We Use Your Information

  • Processing: To classify, extract data from, and validate the documents you upload.
  • Service improvement: Aggregate usage metrics to improve extraction accuracy and platform reliability.
  • Billing: To manage your subscription and usage charges through the configured payment provider.
  • Communication: To send you service-related notices (e.g., billing receipts, account alerts).

Data Processing

Documents you upload are processed by AI language models to perform classification and data extraction. Depending on your configuration, documents may be sent to an LLM provider selected by the platform's model-routing configuration. Supported providers can include:

  • Groq (groq.com) — for fast inference
  • OpenAI (openai.com) — for GPT-class models
  • Anthropic or other LiteLLM-supported providers — when enabled in the deployment configuration

Each provider has its own privacy policy governing how they handle data. We use LiteLLM as a routing proxy to abstract provider selection.

Third-Party Services

  • Clerk — Authentication and organization identity.
  • Stripe or LemonSqueezy — Payment processing, depending on the active billing configuration.
  • Resend — Transactional service emails when email delivery is configured.
  • LLM providers — Document content is transmitted to the active LLM provider for AI inference.

Data Storage and Security

Your data is stored in PostgreSQL 16 with Row-Level Security (RLS) enforcing strict tenant isolation — your organization's data is separated from other organizations. File uploads are stored on persistent volume storage at our hosting provider. Security and backup controls depend on the active deployment configuration.

Cookies

We use Clerk session cookies to maintain your authenticated state. We do not use advertising pixels or cookies for behavioral advertising.

Data Retention

Documents and extracted data are retained while your organization uses the Service and until they are deleted through available product controls or an approved deletion request. Some records may be retained where required for security, billing, audit, or legal obligations.

Your Rights

You have the right to:

  • Access: Request a copy of your personal data.
  • Correction: Request correction of inaccurate information.
  • Deletion: Request deletion of your account and associated data.
  • Export: Download your extracted data in JSON format.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date.

Contact Us

If you have questions about this Privacy Policy, please contact us.