Summand

Privacy Policy

Last modified: May 16, 2026

This Privacy Policy describes how Intelligible AI, Inc. ("Intelligible," "we," "us," or "our") collects, uses, and shares personal information when you use the Summand platform and related services (the "Service"). By using the Service, you agree to the practices described in this policy.

What Does This Privacy Policy Apply To?

This policy applies to personal information we collect through the Summand platform at summand.com, our APIs, and any related tools and documentation. It does not apply to third-party services that integrate with Summand, which are governed by their own privacy policies.

1. Information We Collect

Account Information. When you create an account, we collect your name, email address, and password. If you sign in through a third-party provider (e.g., Google or enterprise SSO), we receive your name and email from that provider.

Customer Data. You may upload CSV files, connect databases, or otherwise provide data for analysis. We process this data solely to provide the Service. We do not access your Customer Data except as needed to operate, maintain, or improve the Service, or as directed by you.

Usage Information. We automatically collect information about how you interact with the Service, including pages visited, features used, timestamps, browser type, operating system, and IP address.

Payment Information. If you subscribe to a paid plan, our payment processor (Stripe) collects your payment details. We do not store full credit card numbers on our servers.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your data uploads and generate analysis results
  • Authenticate your identity and manage your account
  • Process payments and manage subscriptions
  • Send transactional communications (e.g., account confirmations, security alerts)
  • Send product updates and announcements (you may opt out at any time)
  • Monitor and improve the Service's performance, reliability, and security
  • Detect, prevent, and respond to fraud, abuse, or security incidents
  • Comply with legal obligations

3. How We Share Your Information

We do not sell your personal information. Our current sub-processors are:

  • AWS (Amazon Web Services): Hosting, storage, KMS-encrypted audit trail. Region: us-east-1.
  • Vercel: Frontend hosting and edge delivery.
  • WorkOS: Identity, SSO, and authentication.
  • Stripe: Payment processing and billing.
  • PostHog: Product analytics and session replay (subject to consent — see "Cookies and Tracking").
  • Sentry: Error monitoring and performance traces.
  • Anthropic: Large-language-model inference for the in-product AI agent. Customer chat content is sent to Anthropic to generate responses and is not used to train their foundation models per their API terms.

We may additionally share information when:

  • Enterprise Customers: If you use Summand through an organization with enterprise SSO, your organization's administrator may have access to account and usage information
  • Legal Requirements: When required by law, legal process, or to protect the rights, property, or safety of Intelligible, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity

4. Your Rights and Choices

Access and Correction. You can access and update your account information through your Account settings at any time.

Data Export (Portability). Authenticated users can export a JSON archive of their account data, datasets metadata, shares, and conversation history via GET /api/user/export. The endpoint streams the response and includes pointers to any S3-hosted Customer Data.

Deletion (Right to be Forgotten). Authenticated users can request permanent deletion via POST /api/user/delete. The deletion is executed as a distributed transaction across our DynamoDB tables, S3 prefixes, WorkOS identity store, Stripe customer records (where legal retention does not apply), and the PostHog person record. Records required for legal hold (paid invoices, security audit trail) are retained for the period mandated by law and otherwise scrubbed of personal identifiers. We complete the deletion within 30 days; you can also email privacy@intelligible.ai if you prefer a manual request.

Privacy preferences. Accept, decline, or revoke consent for product analytics and session replay at any time via Privacy preferences.

Email Opt-Out. You can unsubscribe from non-essential emails using the unsubscribe link in any email or through your Account settings. Transactional emails (e.g., security alerts, billing receipts) cannot be opted out of.

5. Cookies and Tracking

We use cookies and similar technologies to authenticate sessions, remember preferences, and analyze usage patterns. On first visit we surface a consent banner that lets you accept or decline analytics cookies; your decision can be reversed at any time via Privacy preferences. We honor the browser's Do Not Track header and treat it as a decline.

  • Essential Cookies: Required for authentication and core functionality. These cannot be disabled.
  • Product Analytics (PostHog): Page views, feature usage, and aggregated funnel metrics. Subject to consent.
  • Session Replay (PostHog, masked): A 10% sample of authenticated sessions is recorded in production to help us debug usability issues. All input fields and password fields are masked at the source. Subject to consent and skipped when DNT is on or consent is declined.
  • Error Monitoring (Sentry): Stack traces and performance samples from a subset of requests. No customer dataset content is included.

6. Data Retention and Security

We retain your personal information for as long as your account is active or as needed to provide the Service. Customer Data is deleted within 30 days of account termination. Conversation history with the in-product AI agent is retained for 90 days and then automatically purged. Security audit logs (sign-in attempts, permission grants/revokes, API key usage) are retained for thirteen months to support SOC 2 monitoring and may be retained longer under legal hold.

We implement industry-standard security measures including encryption at rest and in transit (KMS-managed customer-managed keys), least-privilege access controls, organization-wide CloudTrail logging with S3 Object Lock immutability, GuardDuty threat detection, AWS Config, and Security Hub. All production data is hosted on AWS in the US-East-1 region. Backups follow a daily / weekly / monthly tiered schedule, with cold retention up to seven years for records subject to compliance hold.

7. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

8. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will take steps to delete it promptly.

9. Region-Specific Disclosures

California Residents (CCPA). You have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@intelligible.ai.

EEA/UK Residents (GDPR). Our legal basis for processing personal information includes: performance of a contract (providing the Service), legitimate interests (improving and securing the Service), consent (marketing communications), and legal obligations. You have the right to access, rectify, erase, restrict processing, data portability, and object to processing. To exercise your rights, contact us at privacy@intelligible.ai.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Last modified" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

For questions about this Privacy Policy or our data practices, contact us at privacy@intelligible.ai.

Intelligible AI, Inc.

© 2026 Intelligible AI, Inc. All rights reserved.