How we collect, use, and protect your information when you use AssurAI.
Short version: Your audit data is yours. We never sell it, never use it to train AI models, and you can delete it anytime. We take that responsibility seriously.
AssurAI is operated by AssurAI Inc., a Delaware C-Corporation, operating from San Jose, California, USA. We provide an AI-native GRC platform for audit, compliance, and risk professionals.
Data Controller: AssurAI Inc. ยท San Jose, California
Privacy contact: privacy@getassurai.com
Name, email, company name, and role when you create an account.
Features accessed, AI tools used, session duration โ used to improve the platform.
Controls, evidence, findings, and workpapers you create. This data belongs entirely to you.
Documents uploaded are processed by AI, stored encrypted, and never shared or used for training.
IP address, browser type, device information, and cookies for security and functionality.
| Purpose | Legal Basis |
|---|---|
| Providing and improving AssurAI | Contract performance |
| Processing AI requests on your behalf | Contract performance |
| Service notifications and updates | Contract performance |
| Security monitoring and fraud prevention | Legitimate interest |
| Product analytics | Legitimate interest |
| Marketing emails (with consent) | Consent |
| Legal compliance | Legal obligation |
Full details at getassurai.com/security.
We retain your data while your account is active. On cancellation:
Depending on your location you may have rights to access, correct, delete, port, restrict, or object to processing of your data, and to withdraw consent at any time.
Email privacy@getassurai.com. We respond within 30 days.
AssurAI is based in the United States. EEA, UK, and Swiss users: transfers to the US are covered by Standard Contractual Clauses (SCCs) with all sub-processors. For our DPA, email privacy@getassurai.com.
Your data is never used to train AI models. When you use AssurAI's AI features, your documents and queries are processed to generate outputs for you โ and only you. This is contractually guaranteed with Anthropic.
EU/UK residents: if we haven't resolved your concern, you may complain to your local data protection authority.