Privacy Policy
Last updated: July 6, 2026
1. Scope
This policy covers the Records Labs platform: the app, APIs, website widgets, and connected-service integrations. The browser extension has its own, more specific policy: Extension Privacy. When your organization uses Records Labs, your organization is the controller of the content it brings and of its website visitors’ data; Records Labs processes that data to provide the Service.
2. What we collect
Account and workspace data
- Name, email, and authentication data for signing in.
- Workspace configuration: members, roles, agents, knowledge rules, integrations.
Customer content
- Documents, pages, transcripts, and records your organization uploads, captures, or connects (for example from Google Drive, Gmail, Slack, HubSpot, Epicor). We process it (extraction, chunking, embedding, transcription) to answer questions with citations.
- Questions asked and answers generated, with usage and quality telemetry.
Website widget visitors
- Messages a visitor sends to a widget, limited page context (page URL/title where the widget is embedded), and technical data (IP-derived rate-limit keys, origin).
- Identity only if the embedding site provides it: self-reported details (such as a name or email typed into a form) or a cryptographically signed identity from the site’s own login system, optionally including traits (such as a plan or tier) used to scope which knowledge the widget may use.
- Widgets support a consent-required tracking mode; the embedding organization is responsible for its own visitor notice and consent.
Billing
- Payments run through Stripe. We store plan, credit, and invoice records; we never store full card numbers — Stripe holds payment credentials.
3. How we use data
- To provide, secure, and improve the Service (including abuse and fraud prevention).
- To generate answers: relevant content is sent to large language models acting as our processors. Customer content is not used to train foundation models.
- To meter usage, bill credits, and send operational notices.
- To comply with law and enforce our Terms.
4. Subprocessors
We use a small set of infrastructure providers to run the Service:
- Supabase — database, authentication, and file storage.
- Railway — backend compute.
- Vercel — web application hosting.
- Stripe — payments and billing.
- OpenRouter and the model providers it routes to (for example Anthropic, OpenAI, Google, xAI) — AI answer generation.
- Google APIs — only for workspaces that connect Google Drive/Gmail sources.
- Twilio — only for workspaces that enable SMS/voice channels.
Each processes data only as needed to provide its function. A current list is available on request at privacy@recordslabs.ai.
5. Retention and deletion
- Customer content follows your workspace’s retention and trash controls; deleted content is purged on the schedule shown in the app.
- Query and audit logs are retained for operations, security, and billing accuracy, then deleted or de-identified.
- On workspace termination, we delete or de-identify customer content within a commercially reasonable period, except where law requires retention.
6. Security
Tenant isolation, role- and rule-based access controls, encryption in transit, secret redaction on sensitive fields, and audit logging. Widget knowledge exposure is fail-closed: public widgets see only knowledge explicitly marked public unless an administrator configures a stronger trust anchor (origin lock, signed page pass, or signed-in visitor identity).
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data. Workspace members should contact their administrator first (most actions are self-serve); anyone can reach us at privacy@recordslabs.ai. Widget visitors should contact the organization whose site embeds the widget — that organization controls their data — and we will support its requests.
8. Children
The Service is a workplace tool and is not directed to children under 13.
9. Changes
We may update this policy; material changes will be announced in the app or by email and reflected here with a new date.
10. Contact
Records Labs — privacy@recordslabs.ai