Privacy Policy
Version 2026-09-21-v1
1. What we collect
- Account info: email address, password hash (never the password itself), organization details.
- Product usage: the data you enter — leads, clients, proposals, audit results, activity notes.
- Operational logs: timestamps of key actions (sign-in, invite sent, audit run) for security and debugging.
- Standard request metadata: IP address, user agent, referrer.
2. How we use it
To run the service on your behalf, keep your account secure, communicate with you about your account, and improve the product. We do not sell your data.
3. Sub-processors
- Supabase — database, authentication, storage.
- Resend (optional) — sending transactional email.
- Anthropic (optional) — generating optional AI summaries and drafts. We send only structured findings/line items, never raw pages.
- Google PageSpeed Insights (optional) — performance metrics for URLs you audit.
- OpenStreetMap Nominatim / Overpass — geocoding and business search for the "Find leads" feature.
4. Sharing
We share your data with sub-processors as needed to run the service, with authorities where required by law, and with anyone you explicitly invite to your organization. That's it.
5. Retention
We keep your data for as long as your organization exists. You can export or delete it any time from Settings. When you delete an organization, its data is removed within 30 days.
6. Your rights
You can access, export, correct, or delete your personal data at any time from Settings. For anything you can't do in-app, contact the account owner of your organization.
7. Security
See /security for a plain-English overview of how the app is built.
8. Contact
Questions about this policy? Contact the account owner of yourVolkri organization.