NØRN

Privacy Policy
EFFECTIVE 18 JUNE 2026 · nornai.tech

Contents

01Summary — What You Need to Know
02Who We Are & Scope
03Our Role — Controller vs. Processor
04What Personal Data We Process
05Why We Process It & Lawful Bases
06What We Do Not Do With Your Data
07Sharing & Subprocessors
08International Transfers
09Retention & Deletion
10Your Rights & How to Exercise Them
11California Disclosures (CCPA / CPRA)
12Cookies & Tracking
13Children
14Security
15Changes to This Policy
16Contact & Data-Subject Requests

01   Summary — What You Need to Know

If you read nothing else, read this. The rest of the document explains each of these in detail.

PointPlain-English
Who we areNorn AI, Inc., a Delaware corporation operating the Norn intelligence platform at nornai.tech.
Whose data this coversAccount holders (tenant admins and operators), and named individuals whose information appears in the public-source knowledge graph or in customer-uploaded content.
What we collectAccount data (name, email, role), authentication metadata, billing data, operator-private content (situations, analyses, evidence, gaps, chat history) stored under your customer organization's tenant, uploaded document files held in short-lived private staging (24-hour TTL), prediction-resolution pairs used for calibration, and public-source data assembled into the knowledge graph.
What we do not doNo marketing emails or third-party tracking. No sale of personal data. No training of generative AI models on operator-private content. No advertising or analytics subprocessors with access to operator content.
SubprocessorsSupabase, Neo4j Aura, Upstash, Railway, Vercel, Anthropic (via the customer's own Anthropic account). See §07 and the Security & Data Handling document for the canonical list.
Your rightsAccess, correct, delete, port, restrict, and object to our processing. See §10. To exercise any right, email blair@nornai.tech.
ChildrenNorn is not designed for or directed at children under 18.
Effective date18 June 2026.

02   Who We Are & Scope

This Privacy Policy describes how Norn AI, Inc., a Delaware corporation ("Norn," "we," "us," or "our"), collects, uses, shares, and protects personal data in connection with the Norn intelligence platform (the "Service"), available at nornai.tech.

This Policy applies to: (a) visitors to the Norn website; (b) authorized users of the Service ("operators" and "tenant administrators"); (c) named individuals whose information appears in operator-uploaded content or in the public-source knowledge graph; and (d) prospective customers and contacts who reach us for sales, support, or security questions.

This Policy is incorporated by reference into the Norn Terms of Service. Capitalized terms not defined here carry the meanings given in the Terms of Service.

03   Our Role — Controller vs. Processor

Norn plays two distinct roles depending on the data in question. This distinction matters under GDPR, UK GDPR, and similar regimes.

RoleWhen it appliesWhat it means
ControllerFor account data (the names, emails, and roles of the people who hold accounts with Norn), billing data, security and audit logs, marketing communications (to the limited extent we send any), and the public-source knowledge graph (which we curate and maintain).Norn determines the purposes and means of processing. This Policy is the controller-side notice to those data subjects.
ProcessorFor Customer Data (the situations, analyses, evidence, gaps, recommended actions, documents, chat history, and other operator-private content that the Customer organization processes through the Service).Norn processes that data on behalf of the Customer organization, who is the controller. For GDPR-scope processing, we will execute a Data Processing Addendum (DPA) at Tier 2 or Tier 3 contract.

The two roles can coexist: a single piece of data may be controller data under one classification (e.g., a tenant admin's email as an account identifier) and processor data under another (the same email as content of a Customer's situation).

04   What Personal Data We Process

Account & access data (we are controller)

CategoryExamplesSource
IdentityFull name, display name, work email, role within tenant (operator / tenant_admin / superadmin)Provided by the user during invitation acceptance or by a tenant admin during invitation
AuthenticationEmail, hashed password (managed by Supabase Auth), session tokens, login timestamps, IP address of recent sessionsGenerated during sign-in
Tenant associationThe tenant identifier you belong to and your role within itSet at invitation acceptance
BillingBilling contact name, billing email, payment method tokens (held by payment processor; Norn does not store full card numbers), invoice historyProvided by the tenant admin during subscription setup

Operator-private content (we are processor; the Customer organization is controller)

This is the substantive content operators produce inside the Service. It is tenant-scoped, encrypted at rest, and not used to train generative AI models. It includes:

CategoryExamples
Situations & analysesSituation names, target outcomes, descriptions, priorities, categories, generated analyses, courses of action, recommended actions, confidence scores, evidence, information gaps, sources
Documents (short-lived staging)PDF / DOCX / PPTX files uploaded for analysis are staged in a private, service-role-only object-storage bucket for up to 24 hours from upload, then swept by a daily cron. Derived entities and situation records persist. The raw file itself is not retained beyond the 24-hour staging window (see Security & Data Handling §03 Path 2).
Chat historyThe full transcript of an operator's chat exchanges with the Service, including tool calls (web searches, graph reads/writes, evidence captures, situation updates).
BriefingsScheduled and on-demand briefing artifacts, retained for the life of the tenant unless deleted.
Prediction logEvery forward-looking probability emitted by the analysis worker is logged with raw and calibrated probability, calibration head identifier, model version, prediction text, timeframe, and (when known) resolution outcome.

Calibration corpus data (we are controller of the corpus; see §5 for lawful basis)

From the tenant-scoped prediction log, Norn reads resolved prediction-outcome pairs into a platform-wide calibration corpus, as described in detail in Security & Data Handling §04 Layer 2. The corpus does not include operator identity, tenant identity, situation context, or any other Operator-Private Content beyond the six fields enumerated there.

Knowledge graph data (we are controller of the graph)

The collective knowledge graph contains deduplicated entities and typed relationships drawn from public-record sources (filings, news, registries, court records). Entities of type person represent named individuals appearing in those public records. The graph does not carry operator identity, tenant identity, or any back-reference to Operator-Private Content. See Security & Data Handling §04 Layer 1 for the PII policy governing person entities.

Operational data (we are controller)

CategoryExamples
Audit logAppend-only record of authentication events, identity / role changes, impersonation sessions, data lifecycle events, configuration changes, security events. Tenant-scoped; readable by tenant admins.
Application logsStructured logs of request handling, job processing, errors. Sensitive fields (passwords, tokens, document content, API keys) are not logged. Retained 30–90 days depending on hosting layer.
Support correspondenceEmails and tickets exchanged with Norn for support, billing, or contractual matters.

05   Why We Process & Lawful Bases (GDPR Art. 6)

PurposeData categoriesLawful basis (where GDPR applies)
Provide the Service — authenticate users, route requests, run analyses, store and retrieve operator-private content, send transactional email (invitations, password resets, billing notices)Account, authentication, operator-private content, operationalContract (Art. 6(1)(b)) with the user or the user's employer
Billing and accounting — invoice, collect payment, maintain financial recordsBilling data, identityContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax / records retention
Security, fraud prevention, abuse — rate-limit, detect intrusion, investigate misuse, respond to incidentsAuthentication, audit log, application logsLegitimate interest (Art. 6(1)(f)) in protecting the Service and its users
Improve the Service — debug, measure performance, refine product based on aggregate usage patterns and operator feedbackAggregate operational data and application logs (no operator-private content)Legitimate interest (Art. 6(1)(f))
Statistical calibration of probabilistic outputs — train and improve the calibration head that corrects systematic bias in raw model probabilities (see Security & Data Handling §04 Layer 2)Resolved prediction-outcome pairs from prediction_log (probability, outcome, prediction text for domain classification, timeframe, source)Legitimate interest (Art. 6(1)(f)) in providing accurate probabilities to all customers, balanced against the limited and disclosed nature of the data used (no identity, no situation context, no operator-private content beyond enumerated fields). Customers consent to this processing via the Terms of Service; Tier 3 customers may opt out (see Security & Data Handling §04).
Knowledge graph maintenance — ingest, deduplicate, and maintain entities and relationships drawn from public recordsPublic-source records and derived graph entities, including person entitiesLegitimate interest (Art. 6(1)(f)) of the operators using the platform to assess named counterparties in commercial and regulatory contexts. Balanced against data-subject rights via the erasure process described in Security & Data Handling §04.
Comply with law — respond to lawful requests, enforce Terms, defend legal claimsAs neededLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))

Where we rely on legitimate interest, we conduct and maintain a legitimate-interest assessment — including for the calibration corpus and knowledge graph — balancing our interest against data-subject rights. You may object to processing based on legitimate interest at any time (see §10).

06   What We Do Not Do With Your Data

A focused list of practices Norn does not engage in. We state these affirmatively so the absence is visible in a security and privacy review.

We do notDetail
Sell personal dataNorn does not sell personal data in the sense defined under CCPA / CPRA, GDPR, or analogous regimes. We have no commercial arrangement under which personal data flows to a third party for that third party's independent benefit.
Train generative AI models on operator-private contentSituations, analyses, evidence, gaps, recommended actions, document text, and chat history are not used to train any LLM, embedding model, or other generative model. (For the narrow, disclosed flow of resolved prediction-outcome pairs into the statistical calibration head, see §05.)
Send marketing emailsNorn does not send unsolicited marketing communications. Transactional emails (invitations, password resets, billing notices, security alerts, material policy changes) are sent as needed to operate the Service.
Use third-party advertising or marketing trackersThe Service does not run third-party ad pixels, analytics scripts that ingest operator content, or marketing CRMs that have access to operator-private content.
Profile users for advertisingWe do not build user-level profiles for targeting advertising or for any third-party marketing purpose.
Process data from 9point8 CollectiveThe Service contractually prohibits ingestion or processing of data from 9point8 Collective or any 9point8 account. This is a hard line in our Terms of Service.
Make automated decisions with legal effect about individualsOutputs are decision-support for human operators, not automated decisions. Customers agree in the Terms of Service not to use Outputs for legally significant automated decisions about individuals without human review.

07   Sharing & Subprocessors

We share personal data only as described in this section. The complete canonical list of subprocessors and what each one sees lives in the Security & Data Handling document, §12. That list is incorporated here by reference and updated when subprocessors change.

Subprocessors

SubprocessorPurposeWhat it sees
Supabase (US default)Authentication, Postgres application database, and private object storage for document-ingestion stagingAccount data, operator-private content, audit log. Document-ingest blobs (24-hour TTL, service-role-only access). Encrypted at rest.
Neo4j Aura (US default)Knowledge graph databasePublic-source entities and relationships; no operator-private content; no operator or tenant identity. Encrypted at rest.
Upstash (US)Redis for the background job queueJob payloads in flight (with tenant context). TTL-bounded.
Railway (US)API and worker hostingCompute for the application boundary. Operator content seen in flight; not persisted at the host beyond redacted logs.
Vercel (global edge, primary US)Web app hostingHTTP request metadata; no customer content at rest.
Anthropic (per Anthropic's deployment)LLM inference and managed web-search tool, under the customer's own Anthropic account (BYOK)Prompt and completion content per Claude call; subject to Anthropic's data-handling policy under the customer's Anthropic contract (default 30-day API retention for abuse monitoring; waivable via Anthropic Zero Data Retention agreements).

Other sharing

RecipientPurpose
Payment processorProcess subscription billing (held in the payment processor's vault; Norn does not store full card numbers).
Professional advisorsLawyers, accountants, auditors, and consultants bound by confidentiality, where engaged to advise Norn.
Corporate transactionsIn the event of a merger, acquisition, financing, or sale of substantially all assets, personal data may transfer to the successor, who will be bound by privacy obligations no less protective than this Policy or, where required, with notice and an opportunity for data subjects to exercise rights.
Legal complianceGovernment authorities, courts, or other parties as required to comply with applicable law, court order, or other lawful process. We push back on overbroad requests and notify Customer where legally permitted.
What we do not share for. No personal data is shared with advertising networks, ad-tech vendors, marketing CRMs, or third parties that ingest content for those third parties' own commercial purposes. The complete "What we do not use" list lives in Security & Data Handling §12.

08   International Transfers

Norn is a US company. Our primary infrastructure providers operate in the United States by default. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States and potentially other jurisdictions where our subprocessors operate.

For transfers of personal data subject to GDPR, UK GDPR, or Swiss data-protection law out of those jurisdictions, we rely on the EU Standard Contractual Clauses ("SCCs"), UK International Data Transfer Addendum, and Swiss Federal Data Protection Office addendum, as applicable, executed as part of a Data Processing Addendum (DPA) at Tier 2 or Tier 3 contract. We will provide a copy of the relevant transfer mechanism on request.

Tier 3 Customers may negotiate configurable data residency (for example, EU-only deployment of the application database) at contract; the build status of regional residency options is disclosed at procurement.

09   Retention & Deletion

DataDefault retention
Account & tenant dataRetained while the account / tenant is active.
Operator-private content (situations, analyses, evidence, gaps, recommended actions, chat history, briefings)Retained while the tenant is active, unless deleted by the operator or tenant admin.
Uploaded document filesStaged in a private object-storage bucket for up to 24 hours from upload, then swept by a daily cron. Maximum file lifetime: 24 hours. Derived entities and situation records persist.
Prediction logRetained while the tenant is active.
Knowledge graph entities & relationshipsRetained as part of the collective graph; individual graph entries can be removed by tenant admin (for tenant back-references) or by data-subject erasure request for person entities (see §10 and Security & Data Handling §04).
Audit logRetained while the tenant is active. Append-only at the database layer.
Application logs (with sensitive fields redacted)30–90 days, depending on hosting layer.
Billing recordsRetained for the longer of (a) the duration required by tax and financial-records law (typically 7 years) or (b) the period during which a potential dispute could be raised.
Support correspondenceRetained for the life of the customer relationship plus 2 years.

End of relationship

When a tenant terminates its subscription, Norn retains Customer Data for 30 days to allow export or reactivation. After 30 days, Customer Data is purged from active systems. Provider-managed backup retention windows follow the underlying provider schedules (see Security & Data Handling §11), after which backups are also purged. A signed deletion attestation is available on request for Tier 3 contracts.

Resolved prediction-outcome pairs that have already been incorporated into a deployed calibration head before termination remain in that artifact, because individual contributions cannot be extracted from the trained curve. Future retraining cycles do not include data from terminated tenants.

10   Your Rights & How to Exercise Them

Depending on where you are located, you have rights regarding your personal data. The rights below are available to all data subjects regardless of jurisdiction, even where local law does not strictly require them.

RightWhat it means
AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of inaccurate or incomplete personal data.
Erasure ("right to be forgotten")Request deletion of your personal data, subject to limits in applicable law and the technical limits of the calibration corpus described in §09. For person entities in the collective graph, see Security & Data Handling §04 for the erasure process.
RestrictionRequest that we restrict processing pending the resolution of an objection or correction request.
ObjectionObject to processing based on legitimate interest. We will stop unless we have compelling lawful grounds to continue.
PortabilityReceive your personal data in a structured, commonly used, machine-readable format and (where technically feasible) transmit it to another controller.
Withdraw consentWhere processing relies on consent, withdraw it at any time (withdrawal does not affect processing that occurred before withdrawal).
Complain to a supervisory authorityLodge a complaint with your local data-protection authority. In the EU, this is typically the authority in the member state of your habitual residence; in the UK, the ICO; in California, the California Privacy Protection Agency.

How to exercise a right

Email blair@nornai.tech with the subject line beginning "Privacy Request —" and a description of the right you wish to exercise. We may need to verify your identity (a low-friction verification step proportionate to the sensitivity of the request) before acting.

StepWhat happens
1. Receive requestWe acknowledge within 5 business days.
2. VerifyWe may ask for additional information to confirm your identity, scoped to the minimum necessary.
3. ActionWe complete the request within 30 days (GDPR statutory) or 45 days (CCPA / CPRA statutory). Complex requests may extend by an additional 60 days with notice.
4. ConfirmWe provide written confirmation of the action taken or, if denied, a reasoned explanation and information about your right to appeal or complain to a supervisory authority.

If we are a processor for the data in question (most operator-private content), we will route your request to the relevant Customer organization (the controller) and assist them in fulfilling it.

11   California Disclosures (CCPA / CPRA)

If you are a California resident, you have the rights described in §10 plus the following additional disclosures under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA / CPRA"):

DisclosureStatement
Categories of personal information collectedIdentifiers (name, email); commercial information (subscription and billing data); internet activity (authentication logs, application logs); professional or employment-related information (role, organization); inferences drawn from any of the foregoing for the purpose of providing the Service. See §04 for the canonical list.
SourcesDirectly from you; from your employer or tenant admin (for invited users); from your interactions with the Service.
Business purposesAs described in §05.
Categories of third parties to whom we discloseSubprocessors (as listed in §07); professional advisors; payment processor; corporate-transaction counterparties; legal authorities (as required).
Sale of personal informationWe do not sell personal information.
Sharing for cross-context behavioral advertisingWe do not share personal information for cross-context behavioral advertising.
Sensitive personal informationWe do not collect sensitive personal information beyond what is reasonably necessary to provide the Service (authentication credentials), and we do not use it for purposes that require an opt-out under CPRA.
RetentionAs described in §09.
Right to know / delete / correct / opt-out / non-discriminationYou have the rights described in §10. We will not discriminate against you for exercising them.
Authorized agentsYou may designate an authorized agent to make a request on your behalf. The agent must provide written authorization, and we may verify your identity directly.

12   Cookies & Tracking

The Service uses a minimal set of cookies and browser-storage entries for essential functionality. We do not run third-party advertising cookies, marketing pixels, or cross-site tracking trackers.

TypePurposeProvider
Essential / authenticationMaintain your signed-in session, prevent session fixation, prevent cross-site request forgery, remember tenant context.Norn (first-party); Supabase Auth (first-party from your perspective; subprocessor from ours).
Functional preferencesRemember UI preferences (theme, pinned situations, focus-mode state).Norn (first-party).
Operational telemetryAnonymous performance / error data to debug application issues. No cross-site tracking; no advertising tie-back.Norn (first-party).

We do not use Do Not Track signals to alter our processing because we do not engage in cross-site tracking that would be affected by them. We honor Global Privacy Control signals where required by law.

13   Children

The Service is intended for use in a professional context by adults. We do not knowingly collect personal data from children under 18. The Service is not marketed to or designed for minors. If we learn that we have collected personal data from a child under 18 without verified parental consent, we will delete it promptly. If you believe a child has provided us with personal data, contact blair@nornai.tech.

The collective knowledge graph does not deliberately ingest information about identifiable minors. Entities of type person are drawn from public-record sources covering adult figures in commercial, regulatory, and public-affairs contexts.

14   Security

We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These controls are described in detail in the Security & Data Handling document. Highlights:

No security program is perfect. If we discover a security incident affecting your personal data, we will notify you in accordance with applicable law and our incident-response commitments in the Security & Data Handling document §15.

15   Changes to This Policy

We may update this Policy from time to time. For material changes — changes to the categories of personal data we collect, the purposes for which we process it, the parties with whom we share it, or your rights — we will provide at least 30 days' notice by email to tenant admins on file and by posting the updated Policy at nornai.tech/privacy-policy.html with a new effective date. Non-material changes (clarifications, formatting, typographical corrections) may be made without notice and take effect upon posting.

Your continued use of the Service after the effective date of a modification constitutes acceptance of the modified Policy. If you do not agree to a material modification, your remedies include exercising your rights under §10 and terminating your subscription under the Terms of Service.

16   Contact & Data-Subject Requests

PurposeReach
Data-subject requests (access, rectification, erasure, restriction, objection, portability, consent withdrawal)blair@nornai.tech with subject line beginning "Privacy Request —"
Privacy questions & complaintsblair@nornai.tech
Data Processing Addendum (DPA) requestsblair@nornai.tech — DPAs are executed at Tier 2 and Tier 3 contract
Security incident notificationblair@nornai.tech
Mailing addressNorn AI, Inc. — address provided upon request to legal counsel handling formal notice

Norn AI, Inc. acts as its own data-protection point of contact at this stage. As the company grows, we will appoint a dedicated Data Protection Officer (DPO) where required by applicable law and will update this Policy with their contact details.

Privacy isn't a tab we ticked. It's a design principle of the Service: operator-private work is sacred, the collective layers are deliberate and disclosed, and the question we ask before any data flow is "would we want to discover this in a security review of someone else's product?"