Privacy Policy
Effective July 5, 2026
1. Overview
A1Raptor provides a sales-knowledge platform that answers your team’s questions from your organization’s own documents and connected tools. This policy explains what we collect, how we use it, and the choices you have. For customers with a separate data processing agreement, that agreement controls where it differs from this policy.
2. Data we collect
Account data — name, work email, password hash (or SSO identifiers), organization name, and role.
Customer content — documents your organization uploads or connects (for example from Slack, Google Drive, Microsoft 365, Notion, Confluence, Dropbox, or Zendesk), the questions your team asks, and the answers generated from them.
Usage and device data — log data such as feature usage, timestamps, browser type, and IP address, used for security, rate limiting, and product improvement.
Billing data — handled by Stripe; we do not store full card numbers.
3. How we use data
We use data to provide and secure the Service: answering queries from your organization’s content, syncing connected sources you enable, sending transactional email (invites, billing, account notices), processing payments, preventing abuse, and improving reliability. Customer content is used only to provide the Service to your organization — we do not sell it and do not use it to train generalized AI models.
4. AI processing
To generate answers, relevant excerpts of your organization’s content are sent to our AI providers (Anthropic for generation, OpenAI for embeddings) under agreements that prohibit them from using that data to train their models. Answers are grounded in your content and cite their sources.
5. Subprocessors
We use the following subprocessors to operate the Service:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and delivery |
| Supabase | Database, authentication, and file storage |
| Anthropic | AI answer generation (Claude) |
| OpenAI | Text embeddings for search |
| Stripe | Payment processing |
| Resend | Transactional email |
| Upstash | Rate limiting (Redis) |
| Sentry | Error monitoring |
We will update this list as our infrastructure changes.
6. Sharing
We share data only with the subprocessors above, with your organization’s administrators (who control the workspace), when required by law, or in connection with a merger or acquisition (with notice). We never sell personal information.
7. Security
Data is encrypted in transit (TLS) and at rest. Access tokens for connected tools are stored encrypted. Access to production systems is limited to authorized personnel. No method of transmission or storage is 100% secure; we will notify affected customers of a breach as required by law.
8. Retention and deletion
Customer content is retained while your organization’s account is active. When a subscription ends, we provide a window to export content on request (see the Terms of Service), after which it is deleted from production systems. Backups age out on a rolling schedule. You can request deletion of your account data at any time.
9. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing (including under GDPR and CCPA). Because we process most data on behalf of your organization, we may direct requests about workspace content to your administrator. To exercise rights over your own account data, contact us at the address below.
10. Cookies
We use only essential cookies: session authentication and security. We do not run third-party advertising or cross-site tracking cookies.
11. Children
The Service is for business use and not directed to anyone under 16; we do not knowingly collect data from children.
12. Changes and contact
We may update this policy and will post the new effective date here, with notice for material changes. Questions or requests: support@a1raptor.com.