Legal

Privacy Policy

Last updated: 2026-05-31

Beta notice.percivoAI is in private beta. This policy describes the honest current state of our data handling and will be expanded as the product matures. We'll notify customers in writing before any material change.

1. Who we are

This Privacy Policy explains how percivoAI (“percivoAI,” “we,” or “us”) collects, uses, and protects personal data when you visit percivo.ai or use the percivoAI service (the “Service”). We act as the data controller for personal data submitted directly to us, and as a data processor for personal data that customers submit through the Service.

2. What we collect

Account data

When you create an account: your name, email address, the organization you represent, and a hashed password.

Workspace content

The brand information, indications, approved claims, prompts, competitors, and owned domains you configure for monitoring. This is your content. We process it solely to provide the Service to you.

AI response data

The text outputs we collect from third-party AI tools (ChatGPT, Claude, Gemini, Perplexity, Grok) in response to your prompts, plus our derived analysis (sentiment, accuracy assessments, theme extraction, recommended actions).

Technical and usage data

Your IP address, browser type, device identifiers, pages visited, and timestamps. Used for security, abuse prevention, and product improvement.

What we do not collect

We do not collect personal health information (PHI), patient-level records, or adverse-event reports through the Service. Acceptable use rules in our Terms of Use prohibit submitting them.

3. How we use personal data

We use personal data to:

  • Provide, operate, maintain, and support the Service.
  • Authenticate you and enforce account security and acceptable use.
  • Communicate with you about the Service.
  • Improve the Service — analyze usage patterns at an aggregate level. We do not train AI models on Customer Data.
  • Comply with legal obligations.

4. Legal bases (GDPR)

For users in the European Economic Area and the United Kingdom, our legal bases under the GDPR / UK GDPR are:

  • Performance of a contract — to provide the Service to your organization and respond to your requests.
  • Legitimate interests — to secure the Service, prevent abuse, and improve the product.
  • Legal obligation — to comply with applicable law.
  • Consent — where required (e.g. for marketing communications), based on opt-in.

5. Sub-processors

We use the following sub-processors to operate the Service. We notify customers in writing before any change.

  • Supabase — database, authentication, file storage (EU)
  • Anthropic — Claude monitoring, response analysis, accuracy assessment, content generation (US)
  • OpenAI — ChatGPT monitoring (US)
  • Google — Gemini monitoring (US)
  • Perplexity — Perplexity monitoring (US)
  • xAI — Grok monitoring (US)
  • Inngest — background job scheduling (US)
  • PostHog — product analytics, EU region; only used when you grant analytics consent

6. International data transfers

Customer data at rest is hosted in the European Union. Calls to third-party AI providers (Anthropic, OpenAI, Google, Perplexity, xAI) currently route through US endpoints. We rely on Standard Contractual Clauses and equivalent safeguards for those transfers and are tracking EU-region availability across our AI sub-processors.

7. Retention

We retain account and workspace data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce agreements. You can request deletion of your account data at any time by writing to hello@percivo.ai.

8. Security

We encrypt customer data at rest (AES-256 via Supabase) and in transit (TLS 1.2 or higher). We use role-based access controls, multi-factor authentication, and an append-only audit log. SOC 2 is on the roadmap.

9. Your rights

Subject to applicable law, you have the right to access, correct, delete, or restrict our processing of your personal data; to object to processing; to data portability; and to lodge a complaint with your local data protection authority. To exercise these rights, email hello@percivo.ai.

10. Cookies

We use strictly necessary cookies to keep you signed in and operate the Service. We also offer optional product analytics (PostHog, EU region) which only runs when you grant consent through our cookie banner. We do not use third-party advertising cookies. You can change your choice at any time from the “Cookie preferences” link in the footer. See our Cookie Policy for the full inventory.

11. Children

The Service is for business use and is not directed at children under 18. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy as the product matures. Material changes will be communicated to customers in writing at least 30 days before they take effect.

13. Contact

For privacy questions, to exercise your rights, or to report a security issue, contact us at hello@percivo.ai.