If you read nothing else, read this. The rest of the document explains each of these in detail.
| Point | Plain-English |
|---|---|
| Who we are | Norn AI, Inc., a Delaware corporation operating the Norn intelligence platform at nornai.tech. |
| Whose data this covers | Account holders (tenant admins and operators), and named individuals whose information appears in the public-source knowledge graph or in customer-uploaded content. |
| What we collect | Account data (name, email, role), authentication metadata, billing data, operator-private content (situations, analyses, evidence, gaps, chat history) stored under your customer organization's tenant, uploaded document files held in short-lived private staging (24-hour TTL), prediction-resolution pairs used for calibration, and public-source data assembled into the knowledge graph. |
| What we do not do | No marketing emails or third-party tracking. No sale of personal data. No training of generative AI models on operator-private content. No advertising or analytics subprocessors with access to operator content. |
| Subprocessors | Supabase, Neo4j Aura, Upstash, Railway, Vercel, Anthropic (via the customer's own Anthropic account). See §07 and the Security & Data Handling document for the canonical list. |
| Your rights | Access, correct, delete, port, restrict, and object to our processing. See §10. To exercise any right, email blair@nornai.tech. |
| Children | Norn is not designed for or directed at children under 18. |
| Effective date | 18 June 2026. |
This Privacy Policy describes how Norn AI, Inc., a Delaware corporation ("Norn," "we," "us," or "our"), collects, uses, shares, and protects personal data in connection with the Norn intelligence platform (the "Service"), available at nornai.tech.
This Policy applies to: (a) visitors to the Norn website; (b) authorized users of the Service ("operators" and "tenant administrators"); (c) named individuals whose information appears in operator-uploaded content or in the public-source knowledge graph; and (d) prospective customers and contacts who reach us for sales, support, or security questions.
This Policy is incorporated by reference into the Norn Terms of Service. Capitalized terms not defined here carry the meanings given in the Terms of Service.
Norn plays two distinct roles depending on the data in question. This distinction matters under GDPR, UK GDPR, and similar regimes.
| Role | When it applies | What it means |
|---|---|---|
| Controller | For account data (the names, emails, and roles of the people who hold accounts with Norn), billing data, security and audit logs, marketing communications (to the limited extent we send any), and the public-source knowledge graph (which we curate and maintain). | Norn determines the purposes and means of processing. This Policy is the controller-side notice to those data subjects. |
| Processor | For Customer Data (the situations, analyses, evidence, gaps, recommended actions, documents, chat history, and other operator-private content that the Customer organization processes through the Service). | Norn processes that data on behalf of the Customer organization, who is the controller. For GDPR-scope processing, we will execute a Data Processing Addendum (DPA) at Tier 2 or Tier 3 contract. |
The two roles can coexist: a single piece of data may be controller data under one classification (e.g., a tenant admin's email as an account identifier) and processor data under another (the same email as content of a Customer's situation).
| Category | Examples | Source |
|---|---|---|
| Identity | Full name, display name, work email, role within tenant (operator / tenant_admin / superadmin) | Provided by the user during invitation acceptance or by a tenant admin during invitation |
| Authentication | Email, hashed password (managed by Supabase Auth), session tokens, login timestamps, IP address of recent sessions | Generated during sign-in |
| Tenant association | The tenant identifier you belong to and your role within it | Set at invitation acceptance |
| Billing | Billing contact name, billing email, payment method tokens (held by payment processor; Norn does not store full card numbers), invoice history | Provided by the tenant admin during subscription setup |
This is the substantive content operators produce inside the Service. It is tenant-scoped, encrypted at rest, and not used to train generative AI models. It includes:
| Category | Examples |
|---|---|
| Situations & analyses | Situation names, target outcomes, descriptions, priorities, categories, generated analyses, courses of action, recommended actions, confidence scores, evidence, information gaps, sources |
| Documents (short-lived staging) | PDF / DOCX / PPTX files uploaded for analysis are staged in a private, service-role-only object-storage bucket for up to 24 hours from upload, then swept by a daily cron. Derived entities and situation records persist. The raw file itself is not retained beyond the 24-hour staging window (see Security & Data Handling §03 Path 2). |
| Chat history | The full transcript of an operator's chat exchanges with the Service, including tool calls (web searches, graph reads/writes, evidence captures, situation updates). |
| Briefings | Scheduled and on-demand briefing artifacts, retained for the life of the tenant unless deleted. |
| Prediction log | Every forward-looking probability emitted by the analysis worker is logged with raw and calibrated probability, calibration head identifier, model version, prediction text, timeframe, and (when known) resolution outcome. |
From the tenant-scoped prediction log, Norn reads resolved prediction-outcome pairs into a platform-wide calibration corpus, as described in detail in Security & Data Handling §04 Layer 2. The corpus does not include operator identity, tenant identity, situation context, or any other Operator-Private Content beyond the six fields enumerated there.
The collective knowledge graph contains deduplicated entities and typed relationships drawn from public-record sources (filings, news, registries, court records). Entities of type person represent named individuals appearing in those public records. The graph does not carry operator identity, tenant identity, or any back-reference to Operator-Private Content. See Security & Data Handling §04 Layer 1 for the PII policy governing person entities.
| Category | Examples |
|---|---|
| Audit log | Append-only record of authentication events, identity / role changes, impersonation sessions, data lifecycle events, configuration changes, security events. Tenant-scoped; readable by tenant admins. |
| Application logs | Structured logs of request handling, job processing, errors. Sensitive fields (passwords, tokens, document content, API keys) are not logged. Retained 30–90 days depending on hosting layer. |
| Support correspondence | Emails and tickets exchanged with Norn for support, billing, or contractual matters. |
| Purpose | Data categories | Lawful basis (where GDPR applies) |
|---|---|---|
| Provide the Service — authenticate users, route requests, run analyses, store and retrieve operator-private content, send transactional email (invitations, password resets, billing notices) | Account, authentication, operator-private content, operational | Contract (Art. 6(1)(b)) with the user or the user's employer |
| Billing and accounting — invoice, collect payment, maintain financial records | Billing data, identity | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax / records retention |
| Security, fraud prevention, abuse — rate-limit, detect intrusion, investigate misuse, respond to incidents | Authentication, audit log, application logs | Legitimate interest (Art. 6(1)(f)) in protecting the Service and its users |
| Improve the Service — debug, measure performance, refine product based on aggregate usage patterns and operator feedback | Aggregate operational data and application logs (no operator-private content) | Legitimate interest (Art. 6(1)(f)) |
| Statistical calibration of probabilistic outputs — train and improve the calibration head that corrects systematic bias in raw model probabilities (see Security & Data Handling §04 Layer 2) | Resolved prediction-outcome pairs from prediction_log (probability, outcome, prediction text for domain classification, timeframe, source) | Legitimate interest (Art. 6(1)(f)) in providing accurate probabilities to all customers, balanced against the limited and disclosed nature of the data used (no identity, no situation context, no operator-private content beyond enumerated fields). Customers consent to this processing via the Terms of Service; Tier 3 customers may opt out (see Security & Data Handling §04). |
| Knowledge graph maintenance — ingest, deduplicate, and maintain entities and relationships drawn from public records | Public-source records and derived graph entities, including person entities | Legitimate interest (Art. 6(1)(f)) of the operators using the platform to assess named counterparties in commercial and regulatory contexts. Balanced against data-subject rights via the erasure process described in Security & Data Handling §04. |
| Comply with law — respond to lawful requests, enforce Terms, defend legal claims | As needed | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest, we conduct and maintain a legitimate-interest assessment — including for the calibration corpus and knowledge graph — balancing our interest against data-subject rights. You may object to processing based on legitimate interest at any time (see §10).
A focused list of practices Norn does not engage in. We state these affirmatively so the absence is visible in a security and privacy review.
| We do not | Detail |
|---|---|
| Sell personal data | Norn does not sell personal data in the sense defined under CCPA / CPRA, GDPR, or analogous regimes. We have no commercial arrangement under which personal data flows to a third party for that third party's independent benefit. |
| Train generative AI models on operator-private content | Situations, analyses, evidence, gaps, recommended actions, document text, and chat history are not used to train any LLM, embedding model, or other generative model. (For the narrow, disclosed flow of resolved prediction-outcome pairs into the statistical calibration head, see §05.) |
| Send marketing emails | Norn does not send unsolicited marketing communications. Transactional emails (invitations, password resets, billing notices, security alerts, material policy changes) are sent as needed to operate the Service. |
| Use third-party advertising or marketing trackers | The Service does not run third-party ad pixels, analytics scripts that ingest operator content, or marketing CRMs that have access to operator-private content. |
| Profile users for advertising | We do not build user-level profiles for targeting advertising or for any third-party marketing purpose. |
| Process data from 9point8 Collective | The Service contractually prohibits ingestion or processing of data from 9point8 Collective or any 9point8 account. This is a hard line in our Terms of Service. |
| Make automated decisions with legal effect about individuals | Outputs are decision-support for human operators, not automated decisions. Customers agree in the Terms of Service not to use Outputs for legally significant automated decisions about individuals without human review. |
We share personal data only as described in this section. The complete canonical list of subprocessors and what each one sees lives in the Security & Data Handling document, §12. That list is incorporated here by reference and updated when subprocessors change.
| Subprocessor | Purpose | What it sees |
|---|---|---|
| Supabase (US default) | Authentication, Postgres application database, and private object storage for document-ingestion staging | Account data, operator-private content, audit log. Document-ingest blobs (24-hour TTL, service-role-only access). Encrypted at rest. |
| Neo4j Aura (US default) | Knowledge graph database | Public-source entities and relationships; no operator-private content; no operator or tenant identity. Encrypted at rest. |
| Upstash (US) | Redis for the background job queue | Job payloads in flight (with tenant context). TTL-bounded. |
| Railway (US) | API and worker hosting | Compute for the application boundary. Operator content seen in flight; not persisted at the host beyond redacted logs. |
| Vercel (global edge, primary US) | Web app hosting | HTTP request metadata; no customer content at rest. |
| Anthropic (per Anthropic's deployment) | LLM inference and managed web-search tool, under the customer's own Anthropic account (BYOK) | Prompt and completion content per Claude call; subject to Anthropic's data-handling policy under the customer's Anthropic contract (default 30-day API retention for abuse monitoring; waivable via Anthropic Zero Data Retention agreements). |
| Recipient | Purpose |
|---|---|
| Payment processor | Process subscription billing (held in the payment processor's vault; Norn does not store full card numbers). |
| Professional advisors | Lawyers, accountants, auditors, and consultants bound by confidentiality, where engaged to advise Norn. |
| Corporate transactions | In the event of a merger, acquisition, financing, or sale of substantially all assets, personal data may transfer to the successor, who will be bound by privacy obligations no less protective than this Policy or, where required, with notice and an opportunity for data subjects to exercise rights. |
| Legal compliance | Government authorities, courts, or other parties as required to comply with applicable law, court order, or other lawful process. We push back on overbroad requests and notify Customer where legally permitted. |
Norn is a US company. Our primary infrastructure providers operate in the United States by default. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States and potentially other jurisdictions where our subprocessors operate.
For transfers of personal data subject to GDPR, UK GDPR, or Swiss data-protection law out of those jurisdictions, we rely on the EU Standard Contractual Clauses ("SCCs"), UK International Data Transfer Addendum, and Swiss Federal Data Protection Office addendum, as applicable, executed as part of a Data Processing Addendum (DPA) at Tier 2 or Tier 3 contract. We will provide a copy of the relevant transfer mechanism on request.
Tier 3 Customers may negotiate configurable data residency (for example, EU-only deployment of the application database) at contract; the build status of regional residency options is disclosed at procurement.
| Data | Default retention |
|---|---|
| Account & tenant data | Retained while the account / tenant is active. |
| Operator-private content (situations, analyses, evidence, gaps, recommended actions, chat history, briefings) | Retained while the tenant is active, unless deleted by the operator or tenant admin. |
| Uploaded document files | Staged in a private object-storage bucket for up to 24 hours from upload, then swept by a daily cron. Maximum file lifetime: 24 hours. Derived entities and situation records persist. |
| Prediction log | Retained while the tenant is active. |
| Knowledge graph entities & relationships | Retained as part of the collective graph; individual graph entries can be removed by tenant admin (for tenant back-references) or by data-subject erasure request for person entities (see §10 and Security & Data Handling §04). |
| Audit log | Retained while the tenant is active. Append-only at the database layer. |
| Application logs (with sensitive fields redacted) | 30–90 days, depending on hosting layer. |
| Billing records | Retained for the longer of (a) the duration required by tax and financial-records law (typically 7 years) or (b) the period during which a potential dispute could be raised. |
| Support correspondence | Retained for the life of the customer relationship plus 2 years. |
When a tenant terminates its subscription, Norn retains Customer Data for 30 days to allow export or reactivation. After 30 days, Customer Data is purged from active systems. Provider-managed backup retention windows follow the underlying provider schedules (see Security & Data Handling §11), after which backups are also purged. A signed deletion attestation is available on request for Tier 3 contracts.
Resolved prediction-outcome pairs that have already been incorporated into a deployed calibration head before termination remain in that artifact, because individual contributions cannot be extracted from the trained curve. Future retraining cycles do not include data from terminated tenants.
Depending on where you are located, you have rights regarding your personal data. The rights below are available to all data subjects regardless of jurisdiction, even where local law does not strictly require them.
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete personal data. |
| Erasure ("right to be forgotten") | Request deletion of your personal data, subject to limits in applicable law and the technical limits of the calibration corpus described in §09. For person entities in the collective graph, see Security & Data Handling §04 for the erasure process. |
| Restriction | Request that we restrict processing pending the resolution of an objection or correction request. |
| Objection | Object to processing based on legitimate interest. We will stop unless we have compelling lawful grounds to continue. |
| Portability | Receive your personal data in a structured, commonly used, machine-readable format and (where technically feasible) transmit it to another controller. |
| Withdraw consent | Where processing relies on consent, withdraw it at any time (withdrawal does not affect processing that occurred before withdrawal). |
| Complain to a supervisory authority | Lodge a complaint with your local data-protection authority. In the EU, this is typically the authority in the member state of your habitual residence; in the UK, the ICO; in California, the California Privacy Protection Agency. |
Email blair@nornai.tech with the subject line beginning "Privacy Request —" and a description of the right you wish to exercise. We may need to verify your identity (a low-friction verification step proportionate to the sensitivity of the request) before acting.
| Step | What happens |
|---|---|
| 1. Receive request | We acknowledge within 5 business days. |
| 2. Verify | We may ask for additional information to confirm your identity, scoped to the minimum necessary. |
| 3. Action | We complete the request within 30 days (GDPR statutory) or 45 days (CCPA / CPRA statutory). Complex requests may extend by an additional 60 days with notice. |
| 4. Confirm | We provide written confirmation of the action taken or, if denied, a reasoned explanation and information about your right to appeal or complain to a supervisory authority. |
If we are a processor for the data in question (most operator-private content), we will route your request to the relevant Customer organization (the controller) and assist them in fulfilling it.
If you are a California resident, you have the rights described in §10 plus the following additional disclosures under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA / CPRA"):
| Disclosure | Statement |
|---|---|
| Categories of personal information collected | Identifiers (name, email); commercial information (subscription and billing data); internet activity (authentication logs, application logs); professional or employment-related information (role, organization); inferences drawn from any of the foregoing for the purpose of providing the Service. See §04 for the canonical list. |
| Sources | Directly from you; from your employer or tenant admin (for invited users); from your interactions with the Service. |
| Business purposes | As described in §05. |
| Categories of third parties to whom we disclose | Subprocessors (as listed in §07); professional advisors; payment processor; corporate-transaction counterparties; legal authorities (as required). |
| Sale of personal information | We do not sell personal information. |
| Sharing for cross-context behavioral advertising | We do not share personal information for cross-context behavioral advertising. |
| Sensitive personal information | We do not collect sensitive personal information beyond what is reasonably necessary to provide the Service (authentication credentials), and we do not use it for purposes that require an opt-out under CPRA. |
| Retention | As described in §09. |
| Right to know / delete / correct / opt-out / non-discrimination | You have the rights described in §10. We will not discriminate against you for exercising them. |
| Authorized agents | You may designate an authorized agent to make a request on your behalf. The agent must provide written authorization, and we may verify your identity directly. |
The Service uses a minimal set of cookies and browser-storage entries for essential functionality. We do not run third-party advertising cookies, marketing pixels, or cross-site tracking trackers.
| Type | Purpose | Provider |
|---|---|---|
| Essential / authentication | Maintain your signed-in session, prevent session fixation, prevent cross-site request forgery, remember tenant context. | Norn (first-party); Supabase Auth (first-party from your perspective; subprocessor from ours). |
| Functional preferences | Remember UI preferences (theme, pinned situations, focus-mode state). | Norn (first-party). |
| Operational telemetry | Anonymous performance / error data to debug application issues. No cross-site tracking; no advertising tie-back. | Norn (first-party). |
We do not use Do Not Track signals to alter our processing because we do not engage in cross-site tracking that would be affected by them. We honor Global Privacy Control signals where required by law.
The Service is intended for use in a professional context by adults. We do not knowingly collect personal data from children under 18. The Service is not marketed to or designed for minors. If we learn that we have collected personal data from a child under 18 without verified parental consent, we will delete it promptly. If you believe a child has provided us with personal data, contact blair@nornai.tech.
The collective knowledge graph does not deliberately ingest information about identifiable minors. Entities of type person are drawn from public-record sources covering adult figures in commercial, regulatory, and public-affairs contexts.
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These controls are described in detail in the Security & Data Handling document. Highlights:
No security program is perfect. If we discover a security incident affecting your personal data, we will notify you in accordance with applicable law and our incident-response commitments in the Security & Data Handling document §15.
We may update this Policy from time to time. For material changes — changes to the categories of personal data we collect, the purposes for which we process it, the parties with whom we share it, or your rights — we will provide at least 30 days' notice by email to tenant admins on file and by posting the updated Policy at nornai.tech/privacy-policy.html with a new effective date. Non-material changes (clarifications, formatting, typographical corrections) may be made without notice and take effect upon posting.
Your continued use of the Service after the effective date of a modification constitutes acceptance of the modified Policy. If you do not agree to a material modification, your remedies include exercising your rights under §10 and terminating your subscription under the Terms of Service.
| Purpose | Reach |
|---|---|
| Data-subject requests (access, rectification, erasure, restriction, objection, portability, consent withdrawal) | blair@nornai.tech with subject line beginning "Privacy Request —" |
| Privacy questions & complaints | blair@nornai.tech |
| Data Processing Addendum (DPA) requests | blair@nornai.tech — DPAs are executed at Tier 2 and Tier 3 contract |
| Security incident notification | blair@nornai.tech |
| Mailing address | Norn AI, Inc. — address provided upon request to legal counsel handling formal notice |
Norn AI, Inc. acts as its own data-protection point of contact at this stage. As the company grows, we will appoint a dedicated Data Protection Officer (DPO) where required by applicable law and will update this Policy with their contact details.