Trust

Privacy & Security Statement

Last updated September 4, 2026. This statement explains how OfferLens MD handles account information, uploaded documents, saved offers, generated reports, optional benchmark contribution, attorney listing interactions, billing, account controls, and security posture.

Review an Offer

Scope of this statement

This statement applies to OfferLens MD websites, application pages, account features, document analysis workflows, saved offer workspaces, benchmark features, attorney listing interactions, and billing-related product flows.

Account information

Account creation is disabled in the current free-access release. If account features are re-enabled later, OfferLens MD may store email, authentication, verification, plan, and account-timestamp records needed to operate those features.

Offer and report data

In the current accountless workflow, manually entered terms, applied extracted terms, projections, flags, questions, and report text remain in the browser for the active page session and are not saved as an OfferLens MD account workspace.

Uploaded documents

Uploaded contracts, offer letters, compensation exhibits, pro formas, and similar materials are processed in memory to extract text, source snippets, and structured terms. In the current free-access release, the uploaded file, filename, extracted text, and document-analysis result are not saved to an OfferLens MD account or document database.

Optional AI explanations

When this feature is configured, you may separately opt in to AI explanations for each upload. Only after that opt-in, OfferLens MD sends extracted contract text to OpenAI's API. The text may include names, signatures represented as text, employer identifiers, compensation, and other confidential terms. Remove information you do not want processed before uploading. Document-only review does not use this external AI service. Requests use store=false, but this does not mean zero provider retention; OpenAI's applicable API data controls and abuse-monitoring policies apply. See https://developers.openai.com/api/docs/guides/your-data for current provider details. AI explanations are returned to your active review and are not saved to our document database.

Review exports

Your browser holds the review and a signed, unencrypted export token in page memory. The token contains the review text and is returned to our server only when you request a PDF; it expires after four hours. Do not share it. Notes and answer markers are sent with a PDF request so they can be included in your report. Downloaded reports remain on your device until you delete them. The current review does not use browser local storage to retain contract contents.

No patient information

OfferLens MD is built for physician employment offer review, not patient care or clinical documentation. Users should not upload patient records, protected health information, medical charts, or other patient-identifying information.

How information is used

Information submitted during a review is used to perform document extraction and return the requested analysis and report. Limited product events may record the file type, number of mapped terms, page path, and workflow actions for reliability and product improvement; those events do not include the uploaded file, filename, raw text, or report text.

Benchmark contribution

Benchmark contribution is disabled in the current accountless free-review workflow. If it is re-enabled, contribution will remain optional and will use only a de-identified structured snapshot of selected terms after affirmative user consent.

What benchmarks exclude

Uploaded files, filenames, raw contract text, source snippets, generated report text, account details, email addresses, payment information, and attorney contact activity are not included in the anonymized benchmark dataset.

Attorney listings and sharing

OfferLens MD may display sponsored attorney listings. No uploaded contract, saved offer, generated report, account detail, or contact information is sent to an attorney unless the user chooses to contact or share information with that attorney outside the app.

Payment information

The current public demo does not process payments or collect payment method details. If paid access is re-enabled later, card and payment method details should be handled by the configured payment provider rather than stored directly by OfferLens MD.

Email and service messages

OfferLens MD may use the account email address to send account verification, password reset, billing, support, security, and service-related messages. These messages are part of operating the service and are separate from optional marketing communications.

Security and access

OfferLens MD uses standard web application protections such as authenticated sessions, secure cookies in production, CSRF protections, host validation, transport security, and access controls intended to limit account data to the signed-in user.

Retention and deletion

The current free workflow does not create stored document analyses or saved offer workspaces. The active analysis remains in the browser until it is cleared, replaced, or the page is closed or refreshed. Limited operational logs and non-content product events may be retained for security, reliability, abuse prevention, and legal obligations.

Support requests

If a user contacts support, OfferLens MD may use the information provided in that message to investigate, respond, and maintain a record of the support interaction. Users should avoid sending sensitive contract language by email unless they intend to do so.

Changes and contact

This statement may be updated as the service changes. Questions about privacy, data controls, account deletion, billing records, or attorney listing disclosures can be sent to support@offerlensmd.com.

Sensitive document posture

Offer letters, contracts, compensation exhibits, and pro formas can contain sensitive career and financial information. The current free workflow processes each document for the immediate response without placing it in an account or saved-document workspace.

Production controls

The production app uses common web application protections such as authenticated sessions, CSRF protections, host validation, secure cookies in production, transport security, and managed database infrastructure.

User verification

Users should verify extracted terms, source snippets, assumptions, and report language before relying on the analysis or sending anything to counsel.