Privacy
You are handing us how your company operates. This page says plainly what we do with it.
What we hold
The documents you send us (your SOPs, playbooks and policies) and the text of the questions your team asks. Each answer is stored with the sources it cited so your admin can see what was asked and whether it was answered.
For each person using the product we hold the email address they sign in with, their role, and when they were last active. That is the whole account record.
What we read from the page
The browser extension reads a small, named set of fields from the tool you are working in, only on pages your workspace's adapter is configured for, and only the fields that adapter names. On a CRM deal record that is values like the deal stage or the pipeline: enough to make an answer concrete about the record in front of you.
It never scrapes the page wholesale, never reads pages outside the configured tools, and never writes to your records. It cannot change anything in your systems.
One tenant per company
Each customer's documents live in their own workspace, isolated at the database level and enforced by row-level security. There is no shared index. A question asked in one workspace cannot retrieve another workspace's content.
Your documents are never training data
Your content is used as retrieval context to answer your team's questions, and for nothing else. We do not train models on it, and our model providers do not train on data sent through their APIs under the terms we use.
Who processes your data
Supabase: database and authentication. Your documents, search index and question history live here, in the EU (Frankfurt).
Vercel: application hosting for the API, dashboard and this site. The API, which is what touches your documents, is pinned to the EU (Frankfurt). Vercel is a US company and its control plane is US-operated.
Anthropic: answer generation (United States). Receives the question and the document excerpts needed to answer it. Does not train on data sent through the API under our terms.
Voyage AI: turns text into search vectors (United States). Receives document text and question text. Does not train on API data under our terms.
Resend: transactional email such as sign-in codes and the weekly digest (United States/EU). Receives email addresses and message content, never your documents.
Transfers to our US subprocessors are covered by the EU Standard Contractual Clauses. We will tell you before adding a subprocessor that processes customer content.
Deletion
Delete a workspace and its documents, its search index and its question history are removed with it. Deletion cascades through every table that references the workspace; there is no archived copy left behind.
You can ask for your data to be exported or deleted at any time by emailing us.
Security
Data is encrypted in transit and at rest. Access to production data is limited to the people who operate the service. Sign-in is handled by our authentication provider; we never see or store your password.
Contact
Questions about any of this, or a data request: hello@handrax.com. Our data processing agreement is a page, not an attachment we send on request. Read it before you ask.