1. What we collect

Account information: your email address, and a display name derived from it unless you set one. Marketing consent: whether you've opted in to product updates. Unchecked by default, and recorded with a timestamp only when you actively check the box. Customer Data: the product decisions, evidence (files, pasted text, links, metrics), and analysis history you create in the Service. Billing information: if you subscribe to a paid plan, Stripe processes and stores your payment details directly. We receive a customer and subscription identifier, never your card number.

2. How we use it

To operate the Service: authenticate you, run the analysis you request against the evidence you provide, store your decision history, and send transactional email (password resets, billing receipts). If you've opted in, we send occasional product updates, and every such email includes an unsubscribe link. We do not sell your data or use Customer Data to train models.

3. Sub-processors

We rely on a small number of infrastructure providers to run the Service: Supabase (database, authentication, file storage), Anthropic (the AI model that produces analysis output, which receives the evidence text you submit for a given decision, not your account credentials), and Stripe (payment processing). Each is bound by its own data-processing terms.

4. Data isolation

Every organization's decisions, evidence, and analysis history are isolated at the database level, enforced by row-level security policies and not just application code, so one customer's data is never visible to another's account.

5. Retention and deletion

We retain your data for as long as your account is active. You can request deletion of your account and associated Customer Data at any time by contacting us. We'll delete it within a reasonable period except where retention is required by law (for example, billing records) or where it persists briefly in backups.

6. Your rights

Depending on where you live, you may have the right to access, correct, or delete your personal information, or to object to certain processing. Contact us and we'll respond.

7. Security

Data is encrypted in transit and at rest through our infrastructure providers. Evidence files are stored in a private bucket accessible only to members of the organization that uploaded them.

8. Changes to this policy

We'll post updates here with a new date. Material changes will be communicated by email where we have one on file.

9. Contact

Questions about this policy, or a data request: shalin@vantagecpg.com.