Privacy Policy

Effective August 11, 2026

1. Information We Collect

Information You Provide

  • Account: name, email address, hashed password
  • Profile: display name, avatar, preferences
  • Content: documents, blocks, files, conversations, workflows
  • Billing: processed by Stripe; we do not store full credit card numbers

Information Collected Automatically

  • Usage data: pages visited, features used, AI inference calls
  • Device: browser type, operating system, IP address
  • Cookies and similar technologies (see Cookie Policy)

2. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process transactions and send related communications
  • Respond to requests and provide support
  • Send administrative messages (security alerts, Terms updates)
  • Detect and prevent fraud and abuse
  • Comply with legal obligations

3. Data Sharing

We do not sell your personal data. We share data only:

  • With service providers who process data on our behalf, under contract
  • With marketplace app developers when you install their apps
  • As required by law or to protect rights and safety
  • In connection with a business transfer (merger, acquisition, or asset sale)

4. International Data Transfers

Data is stored on Cloudflare infrastructure in the region you configure (US or EU). For EEA transfers, Standard Contractual Clauses apply. You may configure your data region in Workspace Settings → Compliance.

5. Data Retention

Data is retained while your account is active. Upon deletion, data is soft-deleted and permanently erased after your configured retention period (default 30 days).

6. Your Rights — GDPR (EU/EEA)

  • Right of access — request a copy of your data (Art. 15)
  • Right to rectification — correct inaccurate data (Art. 16)
  • Right to erasure — request deletion of your data (Art. 17)
  • Right to data portability — export data in machine-readable format (Art. 20)
  • Right to object — object to processing based on legitimate interests (Art. 21)
  • Right to withdraw consent — at any time (Art. 7)

7. Your Rights — CCPA (California)

  • Right to know — what personal information we collect, use, and disclose
  • Right to delete — request deletion of your personal information
  • Right to opt-out — we do not sell personal data; no opt-out needed
  • Right to non-discrimination — no discrimination for exercising CCPA rights

8. COPPA (Children's Privacy)

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13 without verified parental consent.

9. Exercising Your Rights

Use the tools in your Workspace Settings → Compliance tab, or contact [email protected]. We respond within 30 days (GDPR) or 45 days (CCPA).

10. Security

Encryption at rest and in transit (TLS 1.3), role-based access controls with per-organization data isolation, audit logging, regular security assessments, and incident response procedures.

11. Breach Notification

In the event of a personal data breach, we will notify affected users without undue delay and within 72 hours (GDPR) or 60 days (HIPAA).

12. Changes

We may update this Privacy Policy. Material changes will be communicated via email and in-app notification.

13. Contact

Universal Reason LLC · [email protected]