Security & Data Handling
Last updated: 2026-06-05
Anonymous by default — and we never ask who you are
You can get a full estimate with no account, no email, and no company name. We designed the tool so you never have to identify yourself or your employer to get value from it.
- Anonymous and Free use: no account, no email, no company name.
- Pro: an email only, used for sign-in and billing. We still never ask for your company name.
- On every plan, we never ask for your company name — and you do not need to paste contract pricing that identifies you to use the tool.
We don't sell your data — or your renewal — as a lead
You are our customer — not Microsoft, and not a reseller. We are funded by your subscription, never by selling your information or your renewal as a lead, and never by commissions or referral fees. We do not share your inputs with Microsoft, resellers, CSP partners, or other users.
We don't use your inputs to train AI models
Your questions and the figures you enter are used to produce your result — not to train AI models. We use Anthropic's Claude models under Anthropic's commercial API terms, which do not use customer inputs to train models. We send only the minimum necessary to produce an answer, and we do not retain your prompts after your result is generated; Anthropic may retain API inputs only briefly (currently up to 30 days) for safety and abuse monitoring.
What we collect and keep
We practice data minimisation: we collect what is needed to run the tool and little else. Estimates are computed from the figures you enter, which we do not retain once your result is generated. If you create an account, your saved scenarios are kept until you delete them or close your account (deleted from our live systems within 7 days of your request, and purged from backups as they roll over). Where you explicitly opt in to contribute to our price benchmark, we store only de-identified, structured price points — no company name, email, or quote text — pooled into anonymous aggregates that are retained to keep benchmarks accurate. Full retention windows and your deletion rights are described in our Privacy Policy.
Where your data is processed
We run on reputable cloud infrastructure and use a small number of sub-processors, each processing only what its function requires: Vercel (application hosting and content delivery), Supabase (database and authentication), Anthropic (AI processing), Stripe (subscription payments), Resend (transactional email), and, where enabled, Cloudflare (Turnstile bot protection on sign-in and account forms). A Data Processing Addendum (DPA) is available on request for business customers, and we will give reasonable notice of material changes to this list. Tell us if you require a specific processing region.
How we protect it
The application is built on a zero-trust model: identity, tier, and quota are resolved on the server, never trusted from the browser. Secrets and privileged keys are server-side only and are never shipped to the client. Data is encrypted in transit. We follow least-privilege access internally.
Connecting your Microsoft 365 tenant (optional)
If we offer an optional license-utilisation scan, it is strictly read-only and opt-in. It requests least-privilege, read-only permissions, granted by your administrator through Microsoft's standard admin-consent flow. It cannot read your mail or files and cannot make any changes to your tenant. You can review and revoke access at any time from Enterprise Applications in Microsoft Entra. We intend to complete Microsoft Publisher Verification so the consent screen shows a verified publisher before this is offered to organisations.
Certifications and roadmap
We are an independent product and are transparent about where we are. Today we rely on the architectural commitments above — anonymity, minimal retention, no training on your inputs, least-privilege, and encryption. Formal attestations such as SOC 2 and independent penetration testing are on our roadmap; we will state our status here as it progresses rather than imply certifications we do not yet hold.
Report a security issue
Found a vulnerability or have a security question? Email security@renewalcheck.io. For privacy requests, see our Privacy Policy, or contact legal@renewalcheck.io. RenewalCheck.io is an independent tool and is not affiliated with Microsoft.
Microsoft, Microsoft 365, Azure, and other Microsoft product names are trademarks of the Microsoft group of companies. RenewalCheck.io is an independent tool and is not affiliated with, endorsed by, or sponsored by Microsoft. All other trademarks are the property of their respective owners.