Privacy Policy

<!-- PLACEHOLDER: Replace with lawyer-reviewed content before public launch -->

Last updated: March 2026

This Privacy Policy describes how GroundTruth OS ("we", "us", "our") collects, uses, and protects your personal information when you use our knowledge distillation platform ("the Service").

1. Information We Collect

Account Information

  • Email address (via Stytch authentication)
  • Name (if provided via Google OAuth)
  • Organisation and workspace membership

Content You Provide

  • Documents uploaded, pasted, or imported from Google Drive
  • Canonical knowledge base entries you create or edit
  • Agent definitions and configurations
  • Decisions and review requests

Automatically Collected

  • Usage analytics (via PostHog): page views, feature usage, session data
  • Device and browser information
  • IP address
  • Authentication events and timestamps

Generated Data

  • Extracted canonical knowledge (AI-processed from your documents)
  • Interview transcripts and AI responses
  • Audit logs of content changes
  • Agent system prompts compiled from your knowledge base

2. How We Use Your Information

We use your information to:

  • Provide and operate the Service
  • Authenticate your identity and manage access
  • Process your documents using AI to extract structured knowledge
  • Generate and compile agent system prompts
  • Send transactional emails (login codes, notifications)
  • Analyse usage to improve the Service
  • Detect and prevent abuse

We do not use your content to train AI models.

3. Third-Party Services

We share data with third parties only as necessary to provide the Service:

ServicePurposeData Shared
StytchAuthenticationEmail, session tokens
Google GeminiAI extraction and interviewDocument content (processed, not stored by Google for training)
Google DriveDocument importOAuth tokens, file metadata and content
PostHogProduct analyticsUsage events, device info, IP address
SupabaseDatabase hostingAll application data (encrypted at rest)

Each third party processes data under their own privacy policy and our data processing agreements.

4. Data Retention

  • Account data: Retained while your account is active, deleted within 30 days of closure
  • Uploaded documents: Retained until you delete them or close your account
  • Canonical knowledge base: Retained until you delete entries or close your account
  • Audit logs: Retained for 12 months for compliance purposes
  • Analytics data: Retained per PostHog's retention policy

5. Your Rights

You have the right to:

  • Access your personal data — export your knowledge base at any time via the Export feature
  • Correct inaccurate data — edit your canonical documents directly
  • Delete your data — remove individual documents or request full account deletion
  • Export your data — download your complete knowledge base as JSON
  • Restrict processing — contact us to limit how we process your data
  • Object to analytics — disable PostHog tracking via your browser settings

6. Data Security

We protect your data through:

  • Encryption in transit (TLS) and at rest
  • Application-level tenant isolation (workspace-scoped queries)
  • API key authentication with scoped permissions
  • Audit logging of all data mutations
  • Regular security reviews

7. International Transfers

Your data may be processed in regions where our infrastructure providers operate. We ensure appropriate safeguards are in place for any international data transfers.

8. Cookies

We use essential cookies for:

  • stytch_session_jwt — Authentication session
  • active_org_id — Active workspace selection
  • PostHog cookies — Anonymous usage analytics (can be blocked)

We do not use advertising or third-party tracking cookies.

9. Children's Privacy

The Service is not intended for use by anyone under 16 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification.

11. Contact

For privacy questions or data requests, contact us at hello@groundtruthos.ai.