1. Scope
This Privacy Policy applies to ControlAI Fundraising OS at controlraise.com. The application is a private, invite-only business tool for authorized ControlAI team members and collaborators. It is not intended as a public consumer service.
2. Information we handle
Depending on how the application is used, we may handle:
- Account information: name, email address, profile image, authentication identifiers, role, and access status supplied through Clerk and Google Sign-In.
- Investor and professional information: names, roles, organizations, public profiles, business contact details, investment focus, portfolio information, and other professional data gathered from public sources or supplied by authorized users.
- Research and evidence: source URLs, excerpts, publication and retrieval dates, confidence assessments, contradictions, qualification notes, and enrichment results.
- Workspace content: private relationship notes, review decisions, outreach drafts, lists, saved queries, and workflow status entered by authorized users.
- Operational information: audit events, job status, security events, timestamps, provider usage, cost records, and technical request metadata needed to operate and protect the service.
3. How we use information
We use information to:
- authenticate authorized users and enforce role-based access;
- maintain, deduplicate, qualify, and enrich investor records;
- produce evidence-backed research and human-reviewable outreach preparation;
- preserve provenance, review history, security logs, and cost controls;
- operate, troubleshoot, secure, and improve the application; and
- comply with applicable legal obligations and respond to lawful requests.
4. Google account data
When an authorized user signs in with Google, the application requests only the basic information needed for authentication: identity, email address, and basic profile information. We use this information to match the user to an approved application account, display the user's identity, and protect access. We do not request access to Gmail, Google Drive, contacts, calendars, or other Google content through this sign-in flow.
5. How information is shared
We do not sell personal information. Information may be shared with authorized workspace users according to their role and with service providers that help us operate the application. These may include Clerk and Google for authentication; hosting, database, backup, and security providers; and configured AI, search, research, contact-verification, or enrichment providers when an authorized workflow requires them.
Private relationship evidence is subject to narrower access controls and is excluded from external research requests unless an authorized user deliberately approves an appropriate use. We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or secure the service.
6. Retention and deletion
We retain information for as long as it is needed to operate the workspace, preserve evidence and audit history, meet security or legal obligations, and support legitimate fundraising operations. Retention periods may vary by record type. Authorized users may request access, correction, export, or deletion by contacting the application owner. Some information may be retained when required for security, legal compliance, backup integrity, or the preservation of a documented review trail.
7. Security
We use safeguards appropriate to a private business application, including encrypted network connections, invite-only authentication, role-based authorization, isolated secrets, audit records, and restricted administrative access. No system can guarantee absolute security, and authorized users are responsible for protecting their accounts and devices.
8. International processing
Service providers may process information in countries other than the user's own. Where required, we use provider terms and safeguards intended to support lawful cross-border processing.
9. Children
This business application is not directed to children, and we do not knowingly collect personal information from children through it.
10. Changes and contact
We may update this policy as the application or its practices change. The effective date above identifies the current version. Questions, requests, or concerns may be sent to roarora@gmail.com.