Privacy Policy
Last updated: August 2, 2026
1. Overview
Framework Advisory Firm LLC ("Framework Advisory," "we," "us") operates Gray, a contract analysis service. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service.
We built Gray for federal contractors who handle sensitive business information. Data security is not an afterthought — it is a core design principle.
2. Information We Collect
Account Information
- Email address (for account creation and communication)
- Password (stored as a bcrypt hash; we never store plaintext passwords)
Contract Documents
- Documents you upload for analysis (PDF, DOCX)
- Parsed text extracted from those documents
- Analysis results (Blueprint Reports) generated from your documents
Payment Information
- Payments are processed by Stripe, Inc. We do not store credit card numbers, CVVs, or full payment details on our systems. We receive only a payment confirmation and customer identifier from Stripe.
Usage Data
- Request logs (timestamps, endpoints accessed, error codes)
- No cookies, no tracking pixels, no advertising identifiers
3. How We Use Your Information
- Contract analysis: Your uploaded documents are processed by our AI system to generate Blueprint Reports. This is the sole purpose of document collection.
- Account management: Email is used for login, password reset, and service communications.
- Service improvement: Aggregated, anonymized usage metrics (e.g., average document length, error rates) may be used to improve the Service. Individual contract content is never used for this purpose.
4. What We Do NOT Do
- We do not train AI models on your contract data
- We do not share your documents with other customers
- We do not sell, rent, or disclose your data to third parties for marketing
- We do not use your data for advertising
- We do not retain your data after deletion
5. Data Isolation
Each customer's contract data is stored in an isolated storage path. One customer's documents, analysis results, and conversation history are never accessible to another customer. This isolation is enforced at the infrastructure level.
6. Data Location and Security
| Measure | Implementation |
|---|---|
| Data residency | United States only (Azure East US) |
| Encryption in transit | TLS 1.3 for all connections |
| Encryption at rest | AES-256 (Azure Storage Service Encryption) |
| AI inference | Azure OpenAI (FedRAMP High authorized); zero data retention on inference |
| Password storage | bcrypt adaptive hashing |
| Session tokens | JWT with 24-hour expiry |
| Network protection | Cloudflare WAF, DDoS protection |
7. AI Processing
Your contract documents are processed by Azure OpenAI, a FedRAMP High-authorized AI service operated by Microsoft. Key facts about this processing:
- Your data is processed in US data centers only
- Microsoft does not store prompts or completions from Azure OpenAI
- Your data is not used to train, retrain, or improve AI models
- Processing is synchronous — data passes through the model and the response is returned; nothing persists on the AI infrastructure
8. Data Retention and Deletion
- Active accounts: Data is retained for the duration of your account or subscription.
- Account closure: All associated data is deleted within 30 days of account closure.
- Deletion requests: You may request deletion of specific contracts or your entire account at any time by emailing privacy@frameworkadvisoryllc.com. Deletion is complete and verifiable within 30 days.
- Backups: Backup copies expire within the 30-day deletion window. No indefinite backup retention.
9. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Azure OpenAI (Microsoft) | AI contract analysis | Document text (not stored by Microsoft) |
| Azure Blob Storage (Microsoft) | Document and report storage | Uploaded files, analysis results |
| Stripe, Inc. | Payment processing | Email, payment method (handled by Stripe) |
| Cloudflare, Inc. | CDN, security, DNS | Request metadata (IP, headers) — not document content |
10. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Correction: Update your account information
- Deletion: Request deletion of your account and all associated data
- Portability: Receive your data (documents and reports) in machine-readable format
- Objection: Object to specific processing activities
To exercise these rights, contact privacy@frameworkadvisoryllc.com.
11. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect information from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Material changes will be communicated via email.
13. Contact
For privacy-related questions or to exercise your data rights:
Framework Advisory Firm LLC
Email: privacy@frameworkadvisoryllc.com