Privacy Policy
Last updated Sep 25, 2026
Effective date: TODO: launch date
TODO: legal entity name ("we," "us," "our," or "Company") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal data in connection with our services, including the senti.nexus web dashboard and Chrome extension (the "Services").
Please read this policy carefully. If you have questions, contact us at TODO: privacy email.
1. Who we are
Organization: TODO: legal entity name Address: TODO: legal entity address Jurisdiction: TODO: jurisdiction where entity is registered Contact: TODO: privacy email or TODO: support URL
2. Information we collect
2.1 Account information
When you sign up, we collect:
- Email address
- Display name
- Password (hashed, never stored in plaintext)
If you choose to sign in with Google, we collect:
- Name
- Email address
- Profile image URL
- Google account identifier
2.2 Workspace and team data
Within your workspace, we collect and store:
- Member names, emails, and roles
- Seat assignments (a seat represents an assigned person, not a device)
- Device names, operating systems, and last-seen timestamps
- Workspace settings and configuration
- Knowledge entries (categories, questions, answers, sources, revision history)
- Proposals for new knowledge (including original suggestion, supporting evidence, and review comments)
- Audit logs of approval actions and permission changes
2.3 Audio and transcription
The Chrome extension captures audio only after you explicitly start a session. No audio is captured or uploaded automatically.
How it works:
- Capture happens only in your browser after you click Start.
- Raw audio files are never uploaded to our servers.
- Your browser uses Chrome's built-in speech recognition to convert audio to text.
- On-device recognition (when the language pack is installed) processes audio locally in your browser; a text transcript is sent to our servers.
- If on-device recognition is not available, your browser may use Google's server-based recognition (Google's privacy terms apply).
- Local session history (raw transcripts, waveforms, interim text) stays in your browser.
The finalized utterance text and limited recent context are sent through our servers for the classification step (see section 2.4). You cannot disable this if you use the service.
2.4 Classification and JEV
When the extension sends text for analysis, we use TypeSafe's JEV service to:
- Classify the utterance type (e.g., objection, question, action item)
- Suggest relevant knowledge entries
- Assign confidence levels to suggestions
This happens server-side. We send:
- Finalized utterance text (never raw audio)
- Limited recent conversation context
- Relevant knowledge entry snippets from your workspace
We do not claim the product is fully offline or that your conversation content never reaches our servers. Classification requires server-side processing.
We do not retain transcript content in routine logs. We keep decision metadata (labels, confidence scores, timing) per your workspace retention policy.
2.5 AI-generated suggestions
If you use OpenRouter to generate responses or documents, those requests go directly from your browser or extension to OpenRouter using your own API key. We never receive your OpenRouter key, your prompts, or the generated content. OpenRouter's and the model providers' privacy policies apply to that data.
2.6 Billing information
We use Stripe to handle subscriptions. We never receive or store your credit card numbers or bank account details. Stripe handles all payment processing. Only metadata about your subscription (plan, billing period, payment status) is stored on our servers.
2.7 Usage and metering
We collect aggregate usage metrics:
- Number of sessions per workspace
- Number of utterances classified
- Number of knowledge entries accessed
- API request counts and latency
We do not log the content of sessions, utterances, or knowledge entries in usage metrics.
2.8 Device information
We collect:
- Browser type and version
- Operating system name and version
- Device name (as set by you in settings)
- IP address (for security and abuse prevention)
3. Knowledge isolation
Your workspace's knowledge base is used only for your own team. We do not:
- Use your knowledge entries to improve our public templates
- Train models on your content
- Share your knowledge with other customers or workspaces
- Analyze your content to provide services to competitors
Public templates are maintained separately and are never auto-updated into your workspace without your explicit action.
4. Data retention and deletion
4.1 Your data
You may export or delete your workspace data at any time through the dashboard. When you delete a knowledge entry or proposal, it is marked as deleted in our database.
Local extension data: The Chrome extension maintains a local copy of your approved knowledge. When you remove a team member's seat, the next time the extension syncs with our servers, that member's local copies of proprietary knowledge are invalidated. However, data already downloaded to the member's device or exported before removal cannot be recalled. We document this limit clearly.
4.2 Trial and expired accounts
If your trial expires or your subscription is canceled:
- You cannot start new coaching sessions.
- You can still view and export your workspace knowledge.
- We retain your data for TODO: retention period after expiration, then delete it.
4.3 Account deletion
If you delete your account, we delete your personal data (name, email, password hash). Workspace data is retained unless all workspace owners delete the workspace itself.
5. Subprocessors
We rely on the following service providers to operate the Services:
- Cloudflare: DNS, CDN, and DDoS protection. TODO: Cloudflare region/country
- Stripe: Payment processing. TODO: Stripe's region/country
- TypeSafe: Classification and structured decision-making. TODO: TypeSafe's region/country
- Google: Authentication (Google Sign-In). Uses your Google account data per Google's privacy policy.
- Email provider: TODO: email service name and region/country
- Hosting infrastructure: TODO: cloud provider, region, country
- OpenRouter: Optional, customer-controlled. Your API key and requests never pass through our servers.
6. Data transfers and location
Your personal data is processed and stored in TODO: country/region. If you are located in a different jurisdiction, by using the Services you consent to the transfer of your data to TODO: country/region.
For EU/EEA residents, we rely on TODO: legal mechanism: Standard Contractual Clauses, adequacy decision, etc. to transfer your data.
7. Your rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Correct inaccurate information
- Deletion: Request deletion of your data (subject to legal obligations)
- Portability: Receive your data in a portable format
- Restrict processing: Ask us to limit how we use your data
- Object: Opt out of certain processing
To exercise these rights, contact TODO: privacy email.
For EU/EEA residents (GDPR): Your data controller is TODO: legal entity name. You may also lodge a complaint with your local data protection authority.
For California residents (CCPA): You have the right to know, delete, and opt out of the sale of your data. We do not sell your data. Contact TODO: privacy email to exercise your rights.
8. Google API Services compliance
We use Google APIs with the following scopes: openid email profile.
Google's required disclosure:
Your use of Google APIs with senti.nexus is subject to Google API Services: User Data Policy including the "Limited Use" requirements. We use data from the Google API only to:
- Sign you in and manage your account
- Display your name and profile picture in our app
- Verify your email
We do not use this data for any other purpose, including marketing or analysis, and we do not share it with third parties except as described in this policy.
9. Cookies and tracking
We use session cookies to maintain your login state. These are necessary for the service to function.
We do not use advertising trackers, retargeting pixels, or other tracking technologies for marketing purposes.
The Chrome extension does not set cookies. It uses local browser storage (IndexedDB) to store your approved knowledge locally for fast access.
10. Children
The Services are not directed to children under the age of TODO: age, typically 13. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly. Contact TODO: privacy email if you believe we have collected data from a child.
11. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS) and at rest. However, no system is completely secure. We cannot guarantee absolute security.
If we discover a security breach, we will notify affected users as required by law.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of the Services after changes constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy, contact us at:
TODO: privacy email TODO: legal entity name TODO: legal entity address TODO: support URL