Who we are and what this covers
[Legal entity name], registered at [Registered address] (RegSignal, we), is the controller of the personal data described in this policy. You can reach us about privacy at [Privacy contact email]. [Data protection officer, if appointed.] [EU representative, if required.] [UK representative, if required.]
This policy covers the RegSignal marketing site, the console, the REST API, the MCP server, email digests and our communications with customers and beta design partners.
When a customer submits documents, product profiles or questions that contain personal data, RegSignal processes that personal data on the customer's behalf as a processor, under the Data Processing Addendum. For that data, the customer's own privacy notice applies, and requests should go to the customer first; we will help them respond.
What we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity data | Email address, name, identifiers from Google sign-in or your SAML identity provider, organization memberships, roles, invitations, sign-in events and the IP addresses recorded in authentication logs | You, your organization's admins, your identity provider, Supabase Auth |
| Usage events | For each API or console request: organization, endpoint, method, status code, billing units, latency, channel (API or console) and time. For language-model calls: purpose, model, token counts and latency, without the prompt text. API key prefix and when a key was last used | Generated by the Service |
| Audit logs | Actor (user id, email, and whether they used a session, an API key or the gateway), action, target, a short summary, structured metadata, client IP address and request id, for every change made in the console or API | Generated by the Service |
| Submitted documents and customer content | Internal documents ingested as signals, product profiles, Ask questions and conversations, pinned answers, triage notes, tasks, saved filters, webhook, Slack, Teams, Jira and ServiceNow configuration. Any personal data these contain (for example a supplier contact named in a notice) | You and your Users (we act as processor, see above) |
| Feedback | Feedback, bug reports, feature requests, survey answers, and notes from calls with design partners, including your name and role | You |
| Billing data (when paid plans are enabled) | Billing contact, Stripe customer and subscription identifiers, subscription status, invoices, tax identifiers and billing address. Card details are collected by Stripe and never reach RegSignal | You, Stripe |
| Technical data | Error reports (stack trace, request path and method, browser and page URL for console errors) with request bodies and credential headers removed; hosting request logs (path, status, latency); email delivery records | Generated by the Service, Sentry, Render, Resend |
| Browser storage | Sign-in cookies, the selected organization, and interface preferences kept in your browser's local storage. See the Cookie notice | Your browser |
We do not use analytics, advertising or tracking cookies, and we do not buy personal data from data brokers.
Why we use it and our legal bases
Where the EU or UK GDPR applies, we rely on the following legal bases:
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service: sign-in, organizations and roles, the feed, Ask, impact matching, notifications and connectors | Account data, customer content, usage events | Performance of our contract with your organization; our legitimate interest in providing the Service to its Users |
| Send sign-in links, invitations and the digests you subscribe to | Email address, digest content | Contract; legitimate interests |
| Enforce plan limits, meter usage and bill | Usage events, billing data | Contract; legal obligations for tax and accounting records |
| Keep the Service secure, investigate incidents and prevent abuse | Audit logs, authentication logs, technical data | Legitimate interests in security; legal obligations where they apply |
| Give customers an audit trail of changes in their organization | Audit logs | Contract; legitimate interests of the customer and RegSignal |
| Support you and run the beta program | Account data, feedback, correspondence | Contract; legitimate interests in improving the Service |
| Improve the Service | Aggregated usage events, error reports, feedback. Not the content of your documents, and never to train models | Legitimate interests |
| Comply with law and defend legal claims | Any of the above, as necessary | Legal obligation; legitimate interests |
Language-model processing (classification, summaries, impact assessment, Ask answers and translation) is used to deliver features you request. It does not make decisions about individuals that have legal or similarly significant effects.
We do not use Customer Data to train or fine-tune machine learning models. [Confirm before launch whether any marketing email will be sent, and on what basis.]
How long we keep it
Organization owners can shorten or lengthen most retention windows under Settings > Organization > Data retention. A nightly job deletes data older than each window and records a deletion receipt. The defaults are:
| Data | Default | Notes |
|---|---|---|
| Internal documents (submitted signals) and their search chunks | Kept until you delete them | Owners may set a window; deleting a signal removes it immediately |
| Ask conversations, messages and pinned answers | 365 days after the last message | Owners may shorten, lengthen or keep indefinitely |
| Audit events | 730 days | Minimum 365 days, so both parties keep a record of changes |
| Usage events (the billing record) | 400 days | Minimum 400 days, the billing and dispute window |
| Webhook delivery logs | 90 days | Owners may shorten or lengthen |
| Account data and memberships | While you are a member of an organization | Removed members lose access immediately; ask us to delete your sign-in account |
| Product profiles, triage notes, tasks, filters, webhooks, connectors | Until you delete them or the organization | Deleted with the organization |
| Database backups | 7 days | Deleted data leaves backups when the backup window rolls over |
| Error reports (Sentry) | Sentry plan default, 90 days at the time of writing | [Confirm on the current Sentry plan] |
| Hosting logs (Render) and email logs (Resend) | Provider plan defaults | [Confirm retention periods with each provider] |
| Language-model inputs and outputs (Anthropic) | Per Anthropic's API terms | [Confirm retention period in the vendor assessment] |
| Feedback and support correspondence | [Retention period for feedback and support email] | |
| Billing records held by Stripe | As required for tax and accounting | [Confirm statutory period for the governing jurisdiction] |
When an organization is deleted, its organization-scoped data is deleted from the primary database at once and leaves backups within 7 days. The public regulatory corpus is not personal data about you and is kept.
International transfers
RegSignal stores its production data in the United States (Supabase on AWS us-west-2, Oregon, with a staging project in us-west-1) and runs its services in Render's Oregon region. Language-model processing by Anthropic, error tracking, email and billing providers also process data in the United States. No other hosting region is offered today.
If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to the United States. We rely on [Transfer mechanism, for example the EU Standard Contractual Clauses with the UK Addendum, or certification under the EU-US Data Privacy Framework, to be confirmed by counsel], and we require equivalent safeguards from our subprocessors. You can ask for a copy of the relevant safeguards at [Privacy contact email].
Security
We protect personal data with organization-level tenant isolation, TLS in transit, encryption at rest by our hosting providers, hashed API keys, role-based access, an audit log and scrubbed error reports. The Trust page describes the controls and what is still in progress. SOC 2 Type I is in progress; we do not hold a SOC 2 report or any certification today. No system is perfectly secure, and we will tell affected customers about personal data breaches as described in the Data Processing Addendum.
Your rights and how to exercise them
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on consent. Residents of some US states have similar rights to know, delete and correct, and the right not to be discriminated against for exercising them.
- In the product. You can update your profile, leave an organization, and delete content you created. Admins can remove members; owners can set retention windows and delete the organization.
- By email. Write to [Privacy contact email] from the email address on your account. We verify requests through that address and reply within one month, or tell you if we need longer and why.
- Data a customer controls. If your request concerns personal data in a customer's documents or questions, we will pass it to that customer and support them in answering it.
- Deleting a sign-in account. We remove you from every organization and delete your sign-in account. Audit events that record your past actions stay with the organization that owns them, for the retention period above, and we will explain this in our reply.
- Complaints. You can complain to your local data protection authority. We would appreciate the chance to address your concern first.
Children
RegSignal is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We will update the last-updated date when this policy changes and tell organization owners about material changes by email or in the console before they take effect.
Contact
- Privacy questions and requests: [Privacy contact email]
- Postal address: [Legal entity name], [Registered address]
- Security issues: the address published in
/.well-known/security.txtand on the Trust page