Privacy Policy
1. Introduction
This Privacy Policy describes how SentiWorks, Inc. ("SentiWorks," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the SentiBrief service, including our websites at https://sentibrief.com and https://sentibrief.ai (which provide the same Service), our mobile-web experience, and our native mobile applications for iOS and Android (collectively, the "Service"). SentiBrief is a software-as-a-service application that lets users configure automated "agents" that generate personalized briefings ("Signals"), including text, images, and audio, using third-party artificial intelligence providers, and that delivers and shares those briefings on a schedule the user selects.
This Privacy Policy applies to personal information we process about visitors to the Service, registered account holders, and individuals who receive briefings shared through the Service. It does not apply to third-party websites, applications, or services that we do not own or control. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
SentiWorks, Inc. is the controller (or, where applicable, the business) responsible for the personal information processed through the Service. SentiWorks is a corporation based in the United States.
2. Information We Collect
We collect personal information that you provide to us directly, information that is collected automatically when you use the Service, and information we receive from third parties such as authentication and payment providers. The categories of personal information we collect are described in Sections 3 and 4 below. The specific information collected depends on how you interact with the Service and the features you use.
3. Information You Provide to Us
We collect the following categories of information directly from you:
- Account and identity information. When you create an account, we collect your email address, a password (which we store only in hashed form), your name, your date of birth (used to confirm you meet our minimum age requirement), and your time zone (used to schedule delivery of your briefings). If you sign in using a third-party identity provider, we receive identifiers associated with that account (see "Authentication information" below).
- Authentication information. If you choose to sign in with Google or with Apple, we receive account identifiers, basic profile information, and authorization scopes from those providers in order to create or access your account. We do not receive your third-party account password.
- Agent configuration and content. When you set up and operate an agent, we collect the configuration inputs you provide, which may include free-text entries, selected lists and options, chosen icons, and other parameters. We also collect files and other materials you upload ("Artifacts"), such as images and documents, that an agent uses or relies on.
- Communications, sharing, and recipient information. If you share a briefing, we collect the information you supply to do so, including recipient email addresses (limited in number per share), any note you add, and your choice of whether to share anonymously. If you submit feedback or contact us for support, we collect the content of those communications and the contact details you provide.
- Preferences and consent choices. We collect your communication and notification preferences (including whether you wish to receive email notifications when new Signals are delivered, marketing email preferences, and delivery-time settings) and your cookie-consent selections.
- Payment information. When you purchase a paid subscription, payment is processed by our third-party payment processor. We do not collect or store your full payment card number. We receive limited billing information from our payment processor, such as the card brand, the last four digits of the card, the card's expiration date, your subscription status, and your invoice and transaction history. Subscriptions purchased through the Apple App Store are managed by Apple, and the associated purchase information is handled by Apple under its terms.
The content you provide through agent configuration, uploaded Artifacts, and shared materials may contain additional personal information if you choose to include it. You are responsible for the information you submit to the Service, and you should not upload information you do not have the right to share.
4. Information We Collect Automatically
When you access or use the Service, we and our service providers automatically collect certain information, including:
- Device and connection information. Your IP address, browser type, operating system, device type and identifiers, application version, and the platform you are using (for example, web, mobile web, iOS, or Android). Where we retain IP addresses in our operational logs, we apply masking to reduce the precision of the address.
- Usage and analytics information. Information about how you interact with the Service, collected through our first-party analytics pipeline. This includes events such as account creation and sign-in, page and content impressions, searches and search results, clicks, agent-setup funnel steps, sharing actions, notification events, and retention milestones. Analytics events are associated with per-session identifiers.
- Log and diagnostic information. Server-side logs that record requests, correlation identifiers used to trace a request across our systems, error and performance information, and, for our mobile applications, crash and diagnostic reports. Our logging is configured to redact secrets and to reduce the inclusion of personal information.
- Cookies and similar technologies. Information collected through cookies, local storage, and session storage as described in Section 5.
We do not collect precise geolocation information. Camera, microphone, and geolocation device permissions are disabled by the Service through our browser permissions policy. We infer only approximate location (for example, a general region derived from your IP address or the time zone you select) for purposes such as scheduling and security.
Sensitive Information
We do not intentionally collect special categories of personal data or sensitive personal information such as government identifiers, biometric data, genetic data, health information, precise geolocation, racial or ethnic origin, religious beliefs, or information about sex life or sexual orientation. We collect your date of birth for the limited purpose of verifying that you meet our minimum age requirement, and we collect account credentials (such as your hashed password) for authentication. Because you control the content of your agent configurations and uploaded Artifacts, such content could contain sensitive information if you choose to include it; we discourage you from submitting sensitive information that is not necessary for your use of the Service.
5. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to operate the Service, remember your preferences, secure your session, and understand how the Service is used. We classify these technologies as follows:
- Strictly necessary. Required for the Service to function. These include authentication and session cookies, a cookie that records your cookie-consent choices, and a cookie that remembers whether you are using the desktop or mobile experience. We also store limited information in your browser's local and session storage to cache your profile, maintain analytics session identifiers, and preserve your billing and consent state. We rely on a bot-mitigation provider (see Section 7) that loads a script to distinguish humans from automated abuse.
- Personalization (optional). Used to remember preferences such as your display theme. These are enabled only with your consent.
When you first visit the Service, we present a consent banner for optional cookies that allows you to accept, reject, or customize your choices by category. You can change your choices at any time using the "Cookie settings" control available in the Service. Your consent selections are stored on your device and, for signed-in users, associated with your account so that they are remembered across sessions and devices. We do not use cookies or similar technologies for cross-context behavioral advertising.
Analytics
We use first-party analytics to understand how the Service is used and to operate, secure, and improve it. We treat this as a necessary operational activity carried out in our legitimate interest in providing and improving the Service, not as advertising, and we do not use it to build advertising profiles or to track you across other websites, applications, or services. You can opt out of first-party analytics at any time using the analytics control in your privacy settings, and we honor Global Privacy Control (GPC) signals sent by your browser as an opt-out. Opting out does not disable strictly necessary processing or the operation of features you use.
6. How We Use Information
We use personal information for the following purposes:
- To provide and operate the Service, including creating and authenticating your account, configuring and running your agents, generating and delivering your Signals, storing and managing your Artifacts, and enabling sharing features you choose to use.
- To process payments and manage subscriptions, including initiating checkout, confirming and reflecting subscription changes, displaying invoices and payment-method information, and managing cancellations, renewals, and plan changes.
- To communicate with you, including sending transactional messages such as email-verification codes, password-reset instructions, security notices, notifications that new Signals are available, and responses to your support requests.
- To send product and marketing communications, where you have opted in or where otherwise permitted by law, and subject to your ability to opt out at any time.
- To personalize your experience, including presenting recommended agents and tailoring content and scheduling to your stated preferences and time zone.
- To analyze and improve the Service, including measuring engagement, understanding feature usage and funnels, diagnosing problems, and developing new features.
- To maintain security and prevent abuse, including authenticating users, mitigating automated abuse and fraud, checking proposed passwords against known-compromised password datasets, enforcing our terms, and protecting the rights, property, and safety of SentiWorks, our users, and others.
- To comply with legal obligations, including responding to lawful requests, maintaining records, and exercising or defending legal claims.
7. How We Share Information
We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising or targeted advertising. We disclose personal information only in the following circumstances:
- Service providers and sub-processors. We share personal information with vendors that perform services on our behalf and are contractually bound to protect it and use it only as directed. Our principal service providers include:
- Cloudflare, Inc. — application hosting, content delivery, edge compute, object storage for Artifacts, bot mitigation (Turnstile), and email delivery infrastructure.
- Neon, Inc. — managed database services and authentication infrastructure used to store account and Service data and to manage sign-in.
- Stripe, Inc. — payment processing and subscription billing.
- OpenAI and Google LLC (Google Gemini and Cloudflare Workers AI hosted models) — artificial-intelligence model providers used to generate briefing content, images, and audio (see Section 8).
- Google LLC — Google sign-in (OAuth), cloud computing infrastructure used to run our briefing-generation pipeline, and Firebase Cloud Messaging used to deliver push notifications.
- Apple Inc. — Sign in with Apple, Apple Push Notification service, and App Store subscription management for purchases made through the App Store.
- A provider of compromised-password screening, queried using a privacy-preserving method that does not transmit your full password, used to enforce our password policy.
- Where enabled, third-party analytics providers that process usage events on our behalf to help us understand and improve the Service.
- User-directed sharing. When you create a share link, send a briefing by email, or use your device's native sharing features, we disclose the relevant briefing content and associated information to the recipients and through the channels you select. Public agent pages and shared briefing pages that you choose to make available may be accessible to anyone who has the link.
- Legal and safety. We may disclose personal information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of SentiWorks, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, personal information may be transferred as part of that transaction, subject to the commitments made in this Privacy Policy.
- With your consent or at your direction. We may share personal information for other purposes with your consent or at your direction.
We may also create and share aggregated or de-identified information that cannot reasonably be used to identify you.
8. AI and Automated Processing
The Service generates briefing content using third-party artificial-intelligence model providers, currently OpenAI, Google (including Google Gemini and models hosted on Cloudflare Workers AI). To generate your Signals, we transmit the configuration inputs, uploaded Artifacts, and related context you provide to these providers, which process that information to produce text, images, and audio outputs that are returned to you through the Service.
These AI providers process the information we transmit in order to deliver the outputs and may retain it for a limited period in accordance with their respective terms, including for purposes such as service delivery and abuse monitoring. We do not use the content of your agent configurations, Artifacts, or generated Signals to train our own machine-learning models.
AI-generated content may be inaccurate, incomplete, or otherwise unreliable. The Service displays a notice that AI can make mistakes and that you should verify important information. The Service does not make decisions that produce legal or similarly significant effects about you solely by automated means without human involvement. Automated processing is used to generate briefing content and to present recommended agents based on your use of the Service.
The agent personas, characters, and imagery generated or displayed by the Service are fictional and AI-generated. They are not real people and are not intended to depict or resemble any actual person, living or dead, and any such resemblance is unintentional and coincidental. We do not create these personas or images to represent identifiable real individuals.
9. Payments and Financial Information
Paid subscriptions are processed by Stripe, our third-party payment processor, or, for purchases made through the Apple App Store, by Apple. We do not receive or store your full payment card number, security code, or other complete payment credentials. Stripe processes your payment information in accordance with its own privacy policy and applicable payment-industry standards. We receive limited billing information necessary to manage your subscription, such as your card brand, the last four digits of your card, expiration date, subscription status, and invoice history. You can manage your payment methods and billing details through the billing portal made available in the Service or, for App Store purchases, through your Apple account.
10. Data Retention
We retain personal information for as long as necessary to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. In general:
- Account information is retained for the life of your account and deleted or de-identified within a reasonable period after your account is closed, unless we are required or permitted to retain it longer.
- Artifacts and agent content are retained while the owning agent and account remain active and until you delete them. Files that you upload and that remain associated with an active agent are retained for the life of that agent; files you delete are removed in accordance with our standard processes.
- Share links that you create expire after a limited period (typically thirty days) and may be revoked by you at any time before expiration.
- Operational logs are retained for a limited period for security, troubleshooting, and reliability purposes.
- Analytics information is retained for as long as needed to understand and improve the Service.
Where we are unable to delete certain information promptly (for example, because it is stored in backups), we will isolate it from further processing until deletion is possible. Actual retention periods may vary based on the type of information and the purposes described above.
11. Security
We maintain reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction. These measures include encryption of data in transit using industry-standard protocols, storage of passwords in hashed form, access controls, automated bot-mitigation on authentication actions, screening of passwords against known-compromised datasets, redaction of secrets and personal information in our operational logs, and hardened security response headers designed to reduce common web vulnerabilities.
No method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for notifying us of any unauthorized use of your account. You may sign out of other active sessions and change your password through the Service.
12. User Choices and Privacy Rights
You have choices regarding your personal information:
- Access and update. You can review and update your name, time zone, and certain other profile details within the Service, and you can change your password or set a password if you registered using a third-party identity provider.
- Communication preferences. You can opt in or out of email notifications for new Signal deliveries and of marketing communications through your settings. Marketing emails also include a one-click unsubscribe link. Transactional and service-related messages are not promotional and may still be sent while your account is active.
- Cookie and consent choices. You can accept, reject, or customize optional cookie categories at any time using the cookie-settings control.
- Analytics choices. You can opt out of our first-party analytics at any time using the analytics control in your privacy settings, and we honor Global Privacy Control (GPC) signals sent by your browser as an opt-out.
- Manage your content. You can view, download, and delete your Artifacts through the artifact-management area of the Service, and you can delete individual agents. Deleting required setup files may archive the agent that relies on them.
- Connected accounts. You can view, link, and unlink third-party sign-in accounts (such as Google) through your settings.
To exercise rights that are not available as self-service features—including requests to access, correct, delete, or receive a portable copy of your personal information, or to close your account entirely—you may contact us at support@sentiworks.com. We will respond to verifiable requests as required by applicable law. We may need to verify your identity before fulfilling your request, and we will not discriminate against you for exercising your privacy rights. If an authorized agent submits a request on your behalf, we may require proof of authorization and verification of your identity.
Account Deletion
You may close your account and request deletion of your personal information by contacting us at support@sentiworks.com. You may also delete specific agents and Artifacts directly within the Service at any time. When you delete your SentiBrief account through the Service, SentiBrief product data is archived for up to 60 days for restoration requests, charge disputes, fraud prevention, security, legal compliance, and legitimate business administration before it becomes eligible for deletion or de-identification. Upon a verified account-deletion request, we will delete or de-identify your personal information, except where retention is required or permitted by law as described in Section 10.
13. U.S. State Privacy Rights
Depending on your state of residence, you may have rights under state privacy laws, including the California Consumer Privacy Act, as amended (the "CCPA"), and comparable laws in states such as Virginia, Colorado, Connecticut, and Utah, among others. These rights may include the right to know or access the personal information we collect about you, the right to correct inaccurate personal information, the right to delete personal information, the right to obtain a portable copy of certain personal information, the right to opt out of the sale of personal information or of processing for targeted advertising, and the right to be free from discrimination for exercising your rights.
We do not sell personal information and do not process personal information for targeted advertising or share it for cross-context behavioral advertising as those terms are defined under applicable state law. We do not use or disclose sensitive personal information for purposes that would require us to offer a right to limit its use under the CCPA. We honor Global Privacy Control (GPC) signals sent by your browser as an opt-out of first-party analytics, and we treat such signals as a valid opt-out request where applicable law requires us to recognize them.
In the preceding twelve months, we have collected the categories of personal information described in Sections 3 and 4, which correspond to the following CCPA categories: identifiers (such as name, email address, IP address, and account or device identifiers); information described in California Civil Code Section 1798.80(e) (such as name and payment-related information processed by our payment processor); commercial information (such as subscription and transaction history); Internet or other electronic network activity information (such as usage and analytics data and logs); audio, electronic, or visual information (such as uploaded Artifacts and generated images and audio); approximate (non-precise) geolocation information; and inferences drawn to recommend agents. We collect these categories from the sources, use them for the purposes, and disclose them to the categories of recipients described in this Privacy Policy.
To exercise your state privacy rights, contact us at support@sentiworks.com. You may also designate an authorized agent to make a request on your behalf, subject to verification.
California "Shine the Light"
California residents may request information about our disclosure of personal information to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.
Right to Appeal
If we deny your request to exercise a privacy right and you reside in a state that provides a right to appeal, you may appeal our decision by contacting us at support@sentiworks.com. If your appeal is denied, you may contact the attorney general or relevant supervisory authority in your state.
14. Children's Privacy
The Service is not directed to children under the age of 13, and we require account holders to be at least 13 years old. We do not knowingly collect personal information from children under 13. In jurisdictions where the minimum age of digital consent is higher, you must meet the applicable minimum age in your jurisdiction to use the Service. If we learn that we have collected personal information from a child below the applicable minimum age without appropriate consent, we will take steps to delete that information. If you believe a child has provided us with personal information, please contact us at support@sentiworks.com.
15. Third-Party Links and Services
The Service may contain links to, or integrate with, third-party websites, applications, and services that we do not own or control, including identity providers, payment processors, and AI providers. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third party before providing your information to it.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make changes, we will revise the "Last Updated" date above. If we make material changes, we will provide additional notice as appropriate, such as by posting a prominent notice within the Service or, where required, by notifying you by email. Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes, except where additional consent is required by law.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
SentiWorks, Inc.
Email: support@sentiworks.com
Website: https://sentibrief.com and https://sentibrief.ai
