Privacy Policy

Last Updated: June 25, 2025

This Privacy Policy explains how Originalis ("we," "our," or "us") collects, uses, stores, and protects your personal information when you access or use our website and associated services (collectively, the "Service"). We are committed to safeguarding your privacy and maintaining the highest standards of data security and sovereignty.

1. Information We Collect

We collect both personal and non-personal information. Personal information refers to data that can identify you as an individual, such as your email address, username, and password, as well as any additional information you provide during the use of the Service. Non-personal information refers to data that does not directly identify you. This includes anonymous usage data, general demographic information, referring and exit pages, URL click paths, browser and device types, operating system details, and preferences submitted by or inferred from your behavior on the site.

In addition to the information you submit voluntarily, we may automatically collect technical information about your device and usage patterns. This may include your device's IP address, browser type, and information related to how you interact with the Service.

2. How We Use Your Information

We use personal information to operate and improve our Service, respond to inquiries, provide technical support, and communicate with you about important updates, product enhancements, or promotional offers. We do not sell, rent, or trade your personal information to third parties for marketing purposes without your explicit consent.

We may share your personal information with trusted third-party service providers who help us operate the Service. These providers process data only under our instruction and in accordance with this Privacy Policy. In certain cases, we may disclose personal information if required to do so by law or if we believe in good faith that such action is necessary to comply with a legal obligation, protect our rights, prevent fraud, enforce our Terms of Service, or address security or technical issues.

Non-personal information is used to understand usage trends, improve the design and performance of the Service, and generate aggregate analytics. We may share or disclose non-personal information at our discretion, including with partners or external collaborators.

In the event of a business transaction such as a merger, acquisition, or asset sale, your personal information may be transferred as part of that transaction. By using the Service, you acknowledge and consent to such potential transfers under the terms of this Privacy Policy.

We do not send any data back to the models for training but we may train in aggregate for our own fine tuning in a secure and anonymized manner, ensuring that no proprietary or identifiable information is exposed during this process.

3. Google and Microsoft Workspace Data Usage

If you authorize us to access your data via Google Workspace or Microsoft 365 APIs, we will use that data exclusively to deliver core functionality within the Service, such as summarization of email content, meeting context, and contact enrichment. We do not use or retain any Google or Microsoft user data to develop, improve, or train generalized artificial intelligence or machine learning models. All data accessed through these APIs is used only as needed to fulfill features of the Service and is never disclosed to third parties beyond what is required to operate the Service securely and effectively.

We retain data obtained through Google or Microsoft APIs only for as long as is necessary to provide our Service or to comply with legal obligations. In most cases, this period does not exceed 12 months from the user's last interaction with the Service.

Users may request deletion of their Google or Microsoft data at any time by contacting us at support@originalis.ai. Upon receiving a deletion request, we will remove the associated data from our active systems within 30 days, unless retention is required by law. If a user's account remains inactive for 12 consecutive months, we will automatically delete all related Google and Microsoft data.

For disaster recovery purposes, encrypted backups may be retained for up to 60 days after deletion from active systems. These backups are stored securely and are not used for any other purpose.

4. Data Storage and Security

We store user data in secure environments designed to comply with modern data protection standards and regional data residency requirements. Whenever possible, we ensure that data remains in jurisdictions aligned with applicable data sovereignty laws, such as the United States or the European Union.

To protect your information, we implement industry-standard security protocols, including HTTPS encryption, secure socket layer (SSL) technology, firewalls, and access controls. We are also in SOC2 certification process. We also conduct periodic security assessments and audits. While we make every effort to safeguard your data, no system is entirely immune to breaches. By using the Service, you acknowledge and accept these inherent risks and agree to take precautions such as protecting your account credentials.

5. Your Rights

You have the right to access, update, or delete your personal information at any time. You may also object to certain forms of data processing, request data portability, or withdraw your consent where applicable. If you no longer wish to receive marketing communications, you may unsubscribe using the link provided in our emails or contact us directly.

Depending on your jurisdiction, additional rights may apply under local privacy laws, such as the General Data Protection Regulation (GDPR) in the European Union or the California Consumer Privacy Act (CCPA) in the United States. If you wish to exercise any of your rights, please email us at support@originalis.ai and we will respond in accordance with the applicable regulations.

6. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, to comply with legal obligations, and to enforce our agreements. If your account remains inactive for 12 months, we may delete your data in accordance with our retention policy.

7. Children's Privacy

The Service is not intended for users under the age of 18. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that we have inadvertently collected such information without verified parental consent, we will delete it promptly. If you believe that a minor has submitted data to us, please contact us immediately.

8. External Links

Our website may contain links to third-party websites or services that are not owned or operated by us. This Privacy Policy applies solely to data collected through our Service. We are not responsible for the privacy practices or content of those external websites. We encourage you to review the privacy policies of any third-party services you choose to access.

9. Changes to This Privacy Policy

We reserve the right to update or revise this Privacy Policy at any time. If we make significant changes, we will notify you via email or display a prominent notice on our website at least 30 days before the changes take effect. Non-material changes may take effect immediately. We encourage you to check this page periodically to stay informed of our current privacy practices.

10. Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please contact us at support@originalis.ai.