AI Contract Manager

Privacy Policy

Last updated: September 9, 2026

This policy describes how AppFabrik AI processes personal data when the AI Contract Manager mobile app is used. The general Privacy Policy applies to the AppFabrik AI website.

Controller and contact

Controller: Wasiliy Strecker, AppFabrik AI, Ludwigstrasse 23, 86152 Augsburg, Germany.

Privacy and legal contact: contact@appfabrik-ai.de. User support: support@appfabrik-ai.de.

Local app data

Contract fields, documents, attachments, reminders, notes, purchase balance and settings are generally stored locally on the device. Encrypted backups are placed only in a location selected by the user. AppFabrik AI cannot access local documents or backups unless the user sends them to support or starts a cloud feature.

On-device text recognition with Google ML Kit

The app uses Google ML Kit for document scanning and text recognition. Document images, recognized text and recognition results are processed on the device and are not sent to Google by ML Kit.

The ML Kit SDK may send technical diagnostics and usage data to Google. This includes device and app information, a per-installation identifier, performance metrics, image format and resolution, input and output sizes, feature versions, event types and error codes. Google uses this data for diagnostics, maintenance, improvement and abuse detection, and encrypts it in transit. See the ML Kit privacy information and ML Kit data disclosure.

AI analysis and online provider checks

Cloud features start only after an explicit user action. For AI analysis, the app sends recognized OCR text, OCR confidence, text-block metadata, source type, page count, and schema and prompt identifiers through api.appfabrik-ai.de to OpenAI API. For an online provider check, provider name, contract title, country, contract category and contact fields required for contact suggestions are processed. The OpenAI web search tool may be used.

Original PDFs and image files are not sent to OpenAI by default. The AppFabrik AI gateway does not permanently store OCR text, contract content or AI results. Status and usage metadata such as time, path, status, duration, model, page count, character count and token usage may be stored for up to 14 days.

Under the current API data controls, OpenAI does not use API data to train or improve its models unless AppFabrik AI explicitly opts in. AppFabrik AI requests use store: false. OpenAI may still retain abuse-monitoring logs containing prompts, responses and metadata for up to 30 days by default, and longer in required exceptional cases. See the OpenAI API data documentation.

No special-category data in cloud features

AI analysis and online provider checks must not be used for information about health, genetic or biometric characteristics, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life or sexual orientation. Before each cloud request, the user confirms that the submitted information does not contain such data. Contracts may still be managed locally.

Google Play purchase verification

For a Google Play purchase, the app sends platform, product identifier, purchase identifier, local and server verification data, verification source, package identifier and a random purchase claim to the AppFabrik AI gateway. The Google purchase token is sent to the Google Play Developer API to confirm the purchase and is processed only for that verification.

To grant balance and prevent duplicate credits, the gateway stores only cryptographic hashes of the transaction and purchase claim, product identifier, granted balance types, processing status and timestamps. The raw Google purchase token and raw claim are not stored in the purchase ledger. Pseudonymized ledger data is retained for up to three years after the most recent processing status. Google processes billing and account data under the terms of the Google Play account used for the purchase.

Purposes and legal bases

The legitimate interests are the secure, stable and abuse-resistant operation of the app and its interfaces.

Recipients and international transfers

Recipients may include the gateway hosting provider, OpenAI Ireland Limited and its subprocessors, Google for ML Kit and Google Play, and storage providers selected by the user. For OpenAI transfers from the EEA, the applicable OpenAI data processing addendum uses adequacy decisions or EU Standard Contractual Clauses. Google describes its use of adequacy decisions, the EU-US Data Privacy Framework and Standard Contractual Clauses where required in its data transfer information.

Retention and deletion

Users must delete local data and external backups at their respective storage locations. Requests concerning server-side data may be submitted through Data deletion or by email. Because purchase-ledger data is pseudonymized, suitable purchase evidence may be required to locate a record.

Withdraw consent

Consent for AI analyses and online provider checks can be withdrawn separately in the app under “Options > Legal & privacy”. The app will then ask again before a future transfer. Withdrawal applies to future processing and does not affect the lawfulness of earlier processing. A deletion request may also be submitted using the contact details above.

Rights and complaints

Subject to the GDPR, data subjects have rights including access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Data subjects may also lodge a complaint with a data protection authority.

No legal advice

AI Contract Manager is an organization tool and does not provide legal advice. Detected deadlines, contact details, cancellation information and withdrawal information must be checked before use.