LEGAL
This Privacy Policy explains how Sentiora Ltd (“Sentiora”, “we”, “us”, or “our”) collects, uses, stores, shares, and deletes personal data when you use Sentiora, our AI safety monitoring and governance platform (the “Service”), and related websites.
Sentiora Ltd is a company registered in England and Wales. Registered office: England, United Kingdom. Company registration number and full registered office address will be added once available.
This Policy should be read with our Terms of Service. If you have questions, contact support@sentiora.io.
This Policy is available at https://www.sentiora.io/privacy.
1. Who this Policy applies to
This Policy applies to people who create Sentiora accounts or sign in to the Service; people invited to join a workspace, for example by invitation email; people who visit our marketing website or use public demo features, where personal data is processed; and people whose personal data appears in Customer Content that a customer submits to the Service, for example inside monitored conversations. Where an organisation uses Sentiora to monitor AI conversations, that organisation typically decides why Customer Content is processed. In those cases, Sentiora processes that content to provide the Service to the customer.
2. Personal data and Customer Content
In this Policy, “personal data” means information that identifies or can reasonably identify a person. “Customer Content” means data a customer or its users submit to the Service in the course of using it — for example conversation messages, incident notes and comments, policy configuration, knowledge source text, website content the customer asks us to crawl and index, project settings, and related metadata. Customer Content may include personal data about end users of the customer’s AI applications. The customer retains ownership of Customer Content. Sentiora processes Customer Content only to provide the Service. Sentiora does not use Customer Content to train its own AI models.
3. Information we collect
3.1 Account data
When you create or use an account, we store your name, email address, email verification status, optional profile image URL, authentication details including hashed password for email/password accounts or OAuth account identifiers and tokens when you sign in with Google, and account created and updated timestamps. Passwords are stored as hashes. We do not store plaintext passwords.
3.2 Workspace and team data
We store workspace and membership information, including workspace name and related workspace settings; membership roles (Owner, Admin, Reviewer, Developer, Viewer); invitation emails, invited roles, invitation status, and related metadata when someone is invited to a workspace.
3.3 Customer Content
Customers may submit Customer Content to the Service. Depending on how the Service is used, this may include conversations and message content ingested through the API, SDK, or product; incident records, notes, comments, mentions, and activity history; policy configuration and evaluation findings; knowledge sources, indexed page content, and embeddings derived from that content; project names and configuration, including encrypted customer AI provider keys where configured; and API key metadata. We store hashed API keys and prefixes; plaintext keys are shown only at creation.
3.4 Billing data
For paid plans, we store workspace billing identifiers and subscription status needed to operate billing, for example Polar customer and subscription identifiers and period information. Checkout uses the signed-in user’s email with our billing provider, Polar. We do not store full payment card numbers in Sentiora’s application database.
3.5 Notifications and communications
We store in-app notifications and notification preferences. Notification content may include names, incident titles, and comment previews. We may also send transactional emails, for example verification, password reset, welcome, workspace invitations, and operational notifications, to the email address on your account.
3.6 Technical and session data
We may process session records, including session tokens and, where provided by our authentication system, IP address and user agent associated with a session; IP address temporarily for rate limiting and abuse prevention; error and performance telemetry through Sentry and Vercel Analytics / Speed Insights; and theme preference stored in your browser’s local storage, not as a Sentiora account field. We do not operate a separate first-party advertising cookie system in the application today.
3.7 Demo features
If you use public demo features, demo chat messages may be processed by the Service and by AI providers used for the demo. Demo environments may also contain synthetic example content.
4. How we use information
We use personal data and Customer Content to provide, operate, and maintain the Service; authenticate users and secure accounts; provision workspaces, memberships, and invitations; evaluate conversations against policies and support incident review workflows; index and search knowledge content; send transactional and operational emails and in-app notifications; process subscriptions and payments through Polar; enforce plan limits and prevent abuse; monitor errors and performance; and comply with law and enforce our Terms. We process personal data where it is needed to provide the Service under our Terms, to operate and secure the Service, to communicate with you about the Service, and where required by applicable law.
5. AI processing
To evaluate conversations and operate knowledge features, the Service may send relevant Customer Content to AI model providers. Conversation evaluation may use an OpenAI API key configured by the customer for a project, or a Sentiora-managed OpenAI configuration when a project key is not configured. Knowledge embeddings and related knowledge AI features may use Sentiora-managed OpenAI processing. Demo chat may also use OpenAI processing. Sentiora does not use Customer Content to train its own AI models.
6. When we share information
6.1 Service providers
We use third-party providers to operate the Service. These include Better Auth for sign-in, sessions, and related account flows; Google for optional account sign-in; Polar for subscription billing and the customer portal; PostgreSQL database hosting for primary application data storage; OpenAI for model inference; Resend for transactional email delivery; Upstash for optional distributed rate limiting; Sentry for error monitoring and performance traces; Vercel Analytics and Speed Insights for analytics and performance metrics; and Linear when a customer connects Linear to create issues. Customers may also configure notification destinations, for example webhooks, that receive notification title and body content. We may update the providers we use from time to time as needed to operate the Service.
6.2 Workspace members and administrators
People in your workspace can access Customer Content and membership information according to their roles and permissions.
6.3 Legal and safety
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or security of Sentiora, our customers, or others.
7. Cookies and similar technologies
The Service currently uses authentication and session cookies issued by our authentication system, Better Auth, to keep you signed in and manage session state; short-lived session cache cookies used by the authentication system; browser local storage for theme preference, which is not an authentication cookie; and Vercel Analytics and Speed Insights technologies for analytics and performance measurement. This section describes current cookie and similar technology usage for the Service. It is not a separate Cookie Policy.
8. Security
We implement technical and organisational measures designed to protect personal data, including account authentication and session management; role-based access controls within workspaces; hashed storage of project API keys; encrypted storage of certain secrets, such as customer-provided AI provider keys and integration tokens; and HTTPS for application traffic in normal production deployments. No method of transmission or storage is completely secure. This Policy does not claim ISO, SOC 2, or other certifications.
9. Retention and deletion
Sentiora retains personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and protect the security and integrity of the Service. Unless a longer period is required by law, we apply the following retention practices:
9.1 Account information
Retained while the account is active. Deleted or anonymised within 30 days of account deletion unless a longer retention period is required by law.
9.2 Workspace data
Retained while the workspace is active. Deleted within 30 days after workspace deletion.
9.3 Customer Content
Customer Content — including conversations, incidents, policies, knowledge sources, comments, and related operational data — is retained until deleted by the customer or workspace owner. It is deleted within 30 days after workspace or account deletion.
9.4 API keys
API keys remain active until revoked. Revoked keys may be retained in hashed form for up to 30 days for security and audit purposes before permanent deletion.
9.5 Notifications
Notifications are retained for up to 90 days, after which they may be automatically removed.
9.6 Activity history
Retained while the workspace exists. Deleted within 30 days after workspace deletion.
9.7 Authentication sessions
Retained until expiry, logout, or revocation. Expired sessions are automatically removed.
9.8 Error logs
Operational error logs may be retained for up to 90 days.
9.9 Analytics and performance data
Analytics and performance data may be retained for up to 12 months to improve the Service.
9.10 Rate limiting and security logs
Rate limiting and security logs may be retained for up to 30 days.
9.11 Billing records
Billing records may be retained for up to 7 years, or longer where required by applicable law.
You may delete your account in product settings. Deleting an account permanently deletes workspaces you own and associated workspace data, removes your memberships from other workspaces, and deletes your user account and sessions, subject to the retention periods above. Limited copies may remain for a short period in backups or with service providers while those systems complete deletion.
10. Your rights
Depending on where you live and how the Service is used, you may have rights to access, correct, delete, or restrict processing of your personal data, or to object to certain processing. To exercise privacy rights, contact support@sentiora.io. We may need to verify your request. If your data appears only inside a customer’s Customer Content, we may direct you to that customer where appropriate. If you are in the United Kingdom, you may also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
11. International transfers
We and our providers may process data in the United Kingdom and other countries. Where personal data is transferred internationally, we use appropriate safeguards required by applicable law.
12. Children
The Service is intended for users aged 18 or over. We do not knowingly offer accounts to children under 18.
13. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above and post the revised Policy at https://www.sentiora.io/privacy. If a change is material, we may also provide additional notice.
14. Contact
For privacy enquiries, contact support@sentiora.io.