Skip to content
RegSignal
  • Product
  • Solutions
  • Developers
  • Resources
  • Pricing
Sign inRequest access
  • Product
    • Detect
    • Understand
    • Act
    • Trust
    • All capabilities
  • Solutions
    • Compliance teams
    • Software vendors
    • Consultancies
    • Industries
  • Developers
    • API reference
    • Webhook signatures
    • TypeScript SDK
    • Python SDK
    • OpenAPI spec
  • Resources
    • Coverage
    • Source registry
    • Changelog
    • Service status
    • Trust and security
  • Pricing
Sign inRequest access

Legal

Privacy Policy

What personal data RegSignal collects when you use the website, console, API and MCP server, why, how long it is kept, who else processes it, and how to exercise your rights.

Last updated 2026-09-14

On this page

  1. Who we are and what this covers
  2. What we collect
  3. Why we use it and our legal bases
  4. How long we keep it
  5. Who we share it with
  6. International transfers
  7. Security
  8. Your rights and how to exercise them
  9. Cookies and local storage
  10. Children
  11. Changes to this policy
  12. Contact

Draft pending legal review

This document is a working draft for RegSignal’s beta with design partners. It has not been reviewed by counsel and is not yet a binding offer. Text in [brackets] is a placeholder that will be completed before general availability.

1. Who we are and what this covers

[Legal entity name], registered at [Registered address] (RegSignal, we), is the controller of the personal data described in this policy. You can reach us about privacy at [Privacy contact email]. [Data protection officer, if appointed.] [EU representative, if required.] [UK representative, if required.]

This policy covers the RegSignal marketing site, the console, the REST API, the MCP server, email digests and our communications with customers and beta design partners.

When a customer submits documents, product profiles or questions that contain personal data, RegSignal processes that personal data on the customer's behalf as a processor, under the Data Processing Addendum. For that data, the customer's own privacy notice applies, and requests should go to the customer first; we will help them respond.

2. What we collect

Categories of personal data
CategoryExamplesSource
Account and identity dataEmail address, name, identifiers from Google sign-in or your SAML identity provider, organization memberships, roles, invitations, sign-in events and the IP addresses recorded in authentication logsYou, your organization's admins, your identity provider, Supabase Auth
Usage eventsFor each API or console request: organization, endpoint, method, status code, billing units, latency, channel (API or console) and time. For language-model calls: purpose, model, token counts and latency, without the prompt text. API key prefix and when a key was last usedGenerated by the Service
Audit logsActor (user id, email, and whether they used a session, an API key or the gateway), action, target, a short summary, structured metadata, client IP address and request id, for every change made in the console or APIGenerated by the Service
Submitted documents and customer contentInternal documents ingested as signals, product profiles, Ask questions and conversations, pinned answers, triage notes, tasks, saved filters, webhook, Slack, Teams, Jira and ServiceNow configuration. Any personal data these contain (for example a supplier contact named in a notice)You and your Users (we act as processor, see above)
FeedbackFeedback, bug reports, feature requests, survey answers, and notes from calls with design partners, including your name and roleYou
Billing data (when paid plans are enabled)Billing contact, Stripe customer and subscription identifiers, subscription status, invoices, tax identifiers and billing address. Card details are collected by Stripe and never reach RegSignalYou, Stripe
Technical dataError reports (stack trace, request path and method, browser and page URL for console errors) with request bodies and credential headers removed; hosting request logs (path, status, latency); email delivery recordsGenerated by the Service, Sentry, Render, Resend
Browser storageSign-in cookies, the selected organization, and interface preferences kept in your browser's local storage. See the Cookie noticeYour browser

We do not use analytics, advertising or tracking cookies, and we do not buy personal data from data brokers.

3. Why we use it and our legal bases

Where the EU or UK GDPR applies, we rely on the following legal bases:

Purposes and legal bases
PurposeData usedLegal basis
Provide the Service: sign-in, organizations and roles, the feed, Ask, impact matching, notifications and connectorsAccount data, customer content, usage eventsPerformance of our contract with your organization; our legitimate interest in providing the Service to its Users
Send sign-in links, invitations and the digests you subscribe toEmail address, digest contentContract; legitimate interests
Enforce plan limits, meter usage and billUsage events, billing dataContract; legal obligations for tax and accounting records
Keep the Service secure, investigate incidents and prevent abuseAudit logs, authentication logs, technical dataLegitimate interests in security; legal obligations where they apply
Give customers an audit trail of changes in their organizationAudit logsContract; legitimate interests of the customer and RegSignal
Support you and run the beta programAccount data, feedback, correspondenceContract; legitimate interests in improving the Service
Improve the ServiceAggregated usage events, error reports, feedback. Not the content of your documents, and never to train modelsLegitimate interests
Comply with law and defend legal claimsAny of the above, as necessaryLegal obligation; legitimate interests

Language-model processing (classification, summaries, impact assessment, Ask answers and translation) is used to deliver features you request. It does not make decisions about individuals that have legal or similarly significant effects.

We do not use Customer Data to train or fine-tune machine learning models. [Confirm before launch whether any marketing email will be sent, and on what basis.]

4. How long we keep it

Organization owners can shorten or lengthen most retention windows under Settings > Organization > Data retention. A nightly job deletes data older than each window and records a deletion receipt. The defaults are:

Retention defaults
DataDefaultNotes
Internal documents (submitted signals) and their search chunksKept until you delete themOwners may set a window; deleting a signal removes it immediately
Ask conversations, messages and pinned answers365 days after the last messageOwners may shorten, lengthen or keep indefinitely
Audit events730 daysMinimum 365 days, so both parties keep a record of changes
Usage events (the billing record)400 daysMinimum 400 days, the billing and dispute window
Webhook delivery logs90 daysOwners may shorten or lengthen
Account data and membershipsWhile you are a member of an organizationRemoved members lose access immediately; ask us to delete your sign-in account
Product profiles, triage notes, tasks, filters, webhooks, connectorsUntil you delete them or the organizationDeleted with the organization
Database backups7 daysDeleted data leaves backups when the backup window rolls over
Error reports (Sentry)Sentry plan default, 90 days at the time of writing[Confirm on the current Sentry plan]
Hosting logs (Render) and email logs (Resend)Provider plan defaults[Confirm retention periods with each provider]
Language-model inputs and outputs (Anthropic)Per Anthropic's API terms[Confirm retention period in the vendor assessment]
Feedback and support correspondence[Retention period for feedback and support email]
Billing records held by StripeAs required for tax and accounting[Confirm statutory period for the governing jurisdiction]

When an organization is deleted, its organization-scoped data is deleted from the primary database at once and leaves backups within 7 days. The public regulatory corpus is not personal data about you and is kept.

5. Who we share it with

  • Subprocessors that host and operate the Service, listed with the data each receives on the Subprocessors page: Supabase, Render, Anthropic, Sentry, Resend, Stripe (when billing is enabled), Jina, Exa, GitHub and Google Workspace. Jina, Exa and GitHub do not receive customer data.
  • Destinations you configure, such as your webhook endpoints, Slack, Microsoft Teams, Jira, ServiceNow or your SAML identity provider. You control what they receive.
  • Other members of your organization, who can see audit events and the content your organization shares.
  • Authorities or other parties where the law requires it, or to protect the rights, property or safety of RegSignal, our customers or others.
  • A successor in a merger, acquisition or sale of assets, subject to this policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. International transfers

RegSignal stores its production data in the United States (Supabase on AWS us-west-2, Oregon, with a staging project in us-west-1) and runs its services in Render's Oregon region. Language-model processing by Anthropic, error tracking, email and billing providers also process data in the United States. No other hosting region is offered today.

If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to the United States. We rely on [Transfer mechanism, for example the EU Standard Contractual Clauses with the UK Addendum, or certification under the EU-US Data Privacy Framework, to be confirmed by counsel], and we require equivalent safeguards from our subprocessors. You can ask for a copy of the relevant safeguards at [Privacy contact email].

7. Security

We protect personal data with organization-level tenant isolation, TLS in transit, encryption at rest by our hosting providers, hashed API keys, role-based access, an audit log and scrubbed error reports. The Trust page describes the controls and what is still in progress. SOC 2 Type I is in progress; we do not hold a SOC 2 report or any certification today. No system is perfectly secure, and we will tell affected customers about personal data breaches as described in the Data Processing Addendum.

8. Your rights and how to exercise them

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on consent. Residents of some US states have similar rights to know, delete and correct, and the right not to be discriminated against for exercising them.

  • In the product. You can update your profile, leave an organization, and delete content you created. Admins can remove members; owners can set retention windows and delete the organization.
  • By email. Write to [Privacy contact email] from the email address on your account. We verify requests through that address and reply within one month, or tell you if we need longer and why.
  • Data a customer controls. If your request concerns personal data in a customer's documents or questions, we will pass it to that customer and support them in answering it.
  • Deleting a sign-in account. We remove you from every organization and delete your sign-in account. Audit events that record your past actions stay with the organization that owns them, for the retention period above, and we will explain this in our reply.
  • Complaints. You can complain to your local data protection authority. We would appreciate the chance to address your concern first.

9. Cookies and local storage

The site and console use only strictly necessary cookies for sign-in and organization selection, and local storage for interface preferences. There are no analytics or advertising cookies. The Cookie notice lists each one.

10. Children

RegSignal is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We will update the last-updated date when this policy changes and tell organization owners about material changes by email or in the console before they take effect.

12. Contact

  • Privacy questions and requests: [Privacy contact email]
  • Postal address: [Legal entity name], [Registered address]
  • Security issues: the address published in /.well-known/security.txt and on the Trust page

Other documents

  • Terms of Service
  • Data Processing Addendum
  • Acceptable Use Policy
  • Subprocessors
  • Cookie notice
  • Beta program
RegSignal

Product

  • Overview
  • Detect
  • Understand
  • Act
  • Trust
  • All capabilities

Jurisdictions

  • United States
  • European Union
  • United Kingdom
  • India
  • Japan
  • All 21 jurisdictions

Solutions

  • Compliance teams
  • Software vendors
  • Consultancies
  • Industries
  • Pricing

Developers

  • API reference
  • Webhook signatures
  • TypeScript SDK
  • Python SDK
  • OpenAPI spec

Resources

  • Coverage
  • Source registry
  • Changelog
  • Service status
  • Request access

Company

  • About
  • Contact
  • Trust
  • Security contact
  • Enterprise
  • Log in

Legal

  • Terms of Service
  • Privacy Policy
  • DPA
  • Acceptable use
  • Subprocessors
  • Cookie notice
  • Beta program

  • Terms
  • Privacy
  • Cookies
  • Security

© 2026 RegSignal. All rights reserved