How account, billing, and exhibit-session information is handled.
Effective July 29, 2026. Dancel Legal Consulting provides ClearExhibit and is responsible for the application account and billing records described in this notice.
Account and access information
Sign in with ChatGPT supplies the signed-in email address to ClearExhibit for access control. ClearExhibit converts that address into a keyed, one-way account identifier before storing subscription access records. The application uses the signed-in email to display the account and bind the named presenter, but billing tables do not store that raw email address.
Subscription and billing records
Billing records can include the selected plan, subscription status, paid-through date, cancellation state, accepted terms version, and Stripe customer, subscription, checkout, invoice, and event identifiers. They can also include review or security holds needed to prevent access from being granted from incomplete, disputed, refunded, or inconsistent payment information. They do not include exhibit content, witness links, filenames, or matter information.
Payments
Stripe provides secure checkout, recurring billing, tax calculation when configured, and the customer billing portal. Information entered on Stripe's pages is handled under Stripe's privacy practices. ClearExhibit receives the billing status and identifiers needed to grant, renew, pause, or end named-presenter access.
Exhibit-session information
- Temporary session state such as the selected focus mode, callout coordinates, revision numbers, presence times, and technical acknowledgment state.
- A selected image or rendered PDF page when the presenter uploads an exhibit. The original PDF stays in the presenter browser.
- Original image and PDF filenames stay in the presenter browser. The session receives only a server-enforced neutral direct-image or generated PDF-page display name.
- The presenter browser stores an expiring session identifier, control capability, and revision in browser session storage. A witness browser stores a random per-browser identifier used for connection ownership and technical acknowledgment.
Analytics and abuse control
The application stores aggregate daily homepage-load and plan-selection-link click counts. Reloads and repeated clicks can count again, so those counts are not unique people, purchases, subscriptions, sales, conversions, leads, or emails sent. It also stores short-lived, purpose-separated pseudonymous HMAC records to apply bounded session-start, exhibit-upload, exhibit-read, and analytics limits. Those records do not contain raw network addresses, raw session identifiers, exhibit content, contact information, referrers, or user-agent strings.
Do Not Track, Global Privacy Control, witness and preview URLs, and identified automated-test browsers are excluded from application analytics. Hosting and network providers still process ordinary request metadata under their own terms.
Access, expiration, and deletion
A signed-in presenter with active access and a separate presenter control capability is required to create or change presenter-selected content. An unlisted witness link cannot change that content, but a non-preview witness browser updates connection and revision acknowledgment state. Sessions expire after 12 hours, and expired exhibit objects are queued for application cleanup. ClearExhibit does not provide legal hold or promise that a browser or provider backup deletes on the same schedule.
Retention and customer choices
Billing and access records are retained as needed to operate the subscription, resolve disputes, maintain security, and meet legal, tax, or accounting duties. Canceling a subscription ends future renewal but does not necessarily require immediate deletion of transaction records. Browser session storage is controlled by the browser and can remain until the tab, session, or stored state is cleared even after the server session has expired or been revoked.
Current data-use boundary
Do not upload confidential, privileged, sealed, regulated, personal, or other prohibited material. Use only non-confidential sample, synthetic, public, or properly redacted material. If sensitive information is submitted accidentally, stop using the session, end it if possible, and contact support without repeating the sensitive content.
Support and privacy contact
Support and privacy emails may be used to respond, maintain ordinary business records, and investigate content-minimized product or account issues. Do not attach exhibits, screenshots, witness links, client names, or matter details.
Questions or requests may be sent to shane.okeefe@dancel.com.