๐Ÿ”’ Legal

Privacy Policy

How we collect, use, and protect your information when you use AssurAI.

Last updated: May 19, 2026 ยท Effective: May 18, 2026
Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use It
  4. Data Sharing
  5. Data Security
  6. Data Retention
  7. Your Rights
  8. Cookies
  9. International Transfers
  10. AI & Your Data
  11. Contact Us
๐Ÿ”’

Short version: Your audit data is yours. We never sell it, never use it to train AI models, and you can delete it anytime. We take that responsibility seriously.

1. Who We Are

AssurAI is operated by AssurAI Inc., a Delaware C-Corporation, operating from San Jose, California, USA. We provide an AI-native GRC platform for audit, compliance, and risk professionals.

Data Controller: AssurAI Inc. ยท San Jose, California
Privacy contact: privacy@getassurai.com

2. Information We Collect

Account Information

Name, email, company name, and role when you create an account.

Usage Data

Features accessed, AI tools used, session duration โ€” used to improve the platform.

Audit & Compliance Data

Controls, evidence, findings, and workpapers you create. This data belongs entirely to you.

Evidence Files

Documents uploaded are processed by AI, stored encrypted, and never shared or used for training.

Technical Data

IP address, browser type, device information, and cookies for security and functionality.

3. How We Use Your Information

PurposeLegal Basis
Providing and improving AssurAIContract performance
Processing AI requests on your behalfContract performance
Service notifications and updatesContract performance
Security monitoring and fraud preventionLegitimate interest
Product analyticsLegitimate interest
Marketing emails (with consent)Consent
Legal complianceLegal obligation

4. Data Sharing

We do not sell your personal data. We share data only with essential sub-processors:

All sub-processors are bound by data processing agreements.

5. Data Security

Full details at getassurai.com/security.

6. Data Retention

We retain your data while your account is active. On cancellation:

7. Your Rights

Depending on your location you may have rights to access, correct, delete, port, restrict, or object to processing of your data, and to withdraw consent at any time.

Email privacy@getassurai.com. We respond within 30 days.

8. Cookies

We use essential cookies for authentication and session management, and Google Analytics 4 for product analytics. You can control cookies via browser settings.

9. International Data Transfers

AssurAI is based in the United States. EEA, UK, and Swiss users: transfers to the US are covered by Standard Contractual Clauses (SCCs) with all sub-processors. For our DPA, email privacy@getassurai.com.

10. AI & Your Data

๐Ÿค–

Your data is never used to train AI models. When you use AssurAI's AI features, your documents and queries are processed to generate outputs for you โ€” and only you. This is contractually guaranteed with Anthropic.

11. Contact Us

EU/UK residents: if we haven't resolved your concern, you may complain to your local data protection authority.

Privacy questions?

We respond to every privacy request within 30 days.

privacy@getassurai.com