๐Ÿ”’ Legal

Privacy Policy

How we collect, use, and protect your information when you use AssurAI.

Last updated: June 2026 ยท Effective: June 22, 2026
Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use It
  4. Data Sharing
  5. Data Security
  6. Data Retention
  7. Your Rights
  8. Cookies
  9. International Transfers
  10. AI & Your Data
  11. Evidence Hashing
  12. BSA/AML Data
  13. Enterprise & VPC
  14. Contact Us
๐Ÿ”’

Short version: Your audit data is yours. We never sell it, never use it to train AI models, and you can delete it anytime. We take that responsibility seriously.

1. Who We Are

AssurAI is operated by AssurAI Inc., a Delaware C-Corporation, operating from San Jose, California, USA. We provide an AI-native GRC platform for audit, compliance, and risk professionals.

Data Controller: AssurAI Inc. ยท San Jose, California
Privacy contact: privacy@getassurai.com

2. Information We Collect

Account Information

Name, email, company name, and role when you create an account.

Usage Data

Features accessed, AI tools used, session duration โ€” used to improve the platform.

Audit & Compliance Data

Controls, evidence, findings, and workpapers you create. This data belongs entirely to you.

Evidence Files and Uploaded Documents

When you use Evidence Intelligence, RCM Auto-Reader, Walkthrough AI, Reconciliation AI, or Prior Year Workpaper Ingestion features, you upload documents for AI processing. How we handle uploaded documents:

Technical Data

IP address, browser type, device information, and browser localStorage for security and functionality.

3. How We Use Your Information

PurposeLegal Basis
Providing and improving AssurAIContract performance
Processing AI requests on your behalfContract performance
Service notifications and updatesContract performance
Security monitoring and fraud preventionLegitimate interest
Product analyticsLegitimate interest
Marketing emails (with consent)Consent
Legal complianceLegal obligation

4. Data Sharing

We do not sell your personal data. We share data only with essential sub-processors:

All sub-processors are bound by data processing agreements.

5. Data Security

Full details at getassurai.com/security.

6. Data Retention

We retain your data as follows:

Upon account closure, all personal data is deleted within 90 days except where retention is required by applicable law. Immediate deletion is available on request at any time โ€” contact privacy@getassurai.com.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact privacy@getassurai.com. We will respond within 30 days. For EU/EEA residents, you have the right to lodge a complaint with your local data protection authority.

8. Cookies and Local Storage

AssurAI uses browser localStorage (not cookies) to store:

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. Google Ads conversion tracking may place a cookie if you arrive via a Google Ad โ€” this is governed by Google's privacy policy. You can control cookies via your browser settings.

9. International Data Transfers

AssurAI is based in the United States. EEA, UK, and Swiss users: transfers to the US are covered by Standard Contractual Clauses (SCCs) with all sub-processors. For our DPA, email privacy@getassurai.com.

10. AI Processing via Anthropic

๐Ÿค–

Your data is never used to train AI models. When you use AssurAI's AI features, your documents and queries are processed to generate outputs for you โ€” and only you. This is contractually guaranteed with Anthropic.

AssurAI uses Anthropic's Claude API to provide AI features. When you use any AI feature โ€” including Evidence Intelligence, MRC Testing, Walkthrough AI, Reconciliation AI, BSA/AML tools, or any other AI-powered feature โ€” your input data (including uploaded document content) is transmitted to Anthropic for processing.

Anthropic's data handling:

Users in regulated industries (financial services, healthcare, government) should review Anthropic's current data handling practices and enterprise options before uploading sensitive data.

11. Evidence Integrity and Cryptographic Hashing

When you upload documents to Evidence Intelligence, AssurAI generates a SHA-256 cryptographic hash of each file. We store:

We do not store the document content itself. The hash is used to generate Evidence Integrity Certificates and to support audit trail documentation. Hash records are retained for the duration of your account and deleted upon account closure.

12. BSA/AML Module Data Handling

The BSA/AML Compliance Module processes data you provide about your institution's AML program, customer data patterns, and transaction monitoring. This data is:

We strongly recommend that institutions subject to BSA/AML regulations do not upload real customer personally identifiable information (PII) or real transaction data to AssurAI. Use anonymised or sample data for testing purposes.

13. Enterprise and Private Cloud Deployments

Enterprise customers with Private Cloud (VPC) or On-Premises deployments have additional data handling options:

Contact shakeel@getassurai.com to request a Data Processing Agreement or to discuss Enterprise data handling requirements. For our existing DPA documentation see dpa.html.

14. Contact Us

EU/UK residents: if we haven't resolved your concern, you may complain to your local data protection authority.

Privacy questions?

We respond to every privacy request within 30 days.

privacy@getassurai.com