1. What we collect
Account information: your email address, and a display name derived from it unless you set one. Marketing consent: whether you've opted in to product updates. Unchecked by default, and recorded with a timestamp only when you actively check the box. Customer Data: the product decisions, evidence (files, pasted text, links, metrics), and analysis history you create in the Service. Billing information: if you subscribe to a paid plan, Stripe processes and stores your payment details directly. We receive a customer and subscription identifier, never your card number.
2. How we use it
To operate the Service: authenticate you, run the analysis you request against the evidence you provide, store your decision history, and send transactional email (password resets, billing receipts). If you've opted in, we send occasional product updates, and every such email includes an unsubscribe link. We do not sell your data or use Customer Data to train models.
3. Sub-processors
We rely on a small number of infrastructure providers to run the Service: Supabase (database, authentication, file storage), Anthropic (the AI model that produces analysis output, which receives the evidence text you submit for a given decision, not your account credentials), and Stripe (payment processing). Each is bound by its own data-processing terms.
4. Data isolation
Every organization's decisions, evidence, and analysis history are isolated at the database level, enforced by row-level security policies and not just application code, so one customer's data is never visible to another's account.
5. Retention and deletion
We retain your data for as long as your account is active. You can request deletion of your account and associated Customer Data at any time by contacting us. We'll delete it within a reasonable period except where retention is required by law (for example, billing records) or where it persists briefly in backups.
6. Your rights
Depending on where you live, you may have the right to access, correct, or delete your personal information, or to object to certain processing. Contact us and we'll respond.
7. Security
Data is encrypted in transit and at rest through our infrastructure providers. Evidence files are stored in a private bucket accessible only to members of the organization that uploaded them.
8. Changes to this policy
We'll post updates here with a new date. Material changes will be communicated by email where we have one on file.
9. Contact
Questions about this policy, or a data request: shalin@vantagecpg.com.