Pricing Vision Careers
Log in Sign up

Privacy Policy

Cinchapi, Inc.

Effective Date: July 14, 2026

  • 1. Introduction
  • 2. Information We Collect
  • 3. How We Use Your Information
  • 4. How We Share Your Information
  • 5. Data Retention
  • 6. Data Security
  • 7. Human Review of Content
  • 8. Your Rights and Choices
  • 9. California Privacy Rights (CCPA/CPRA)
  • 10. European and UK Data Subjects (GDPR)
  • 11. Children’s Privacy
  • 12. Third-Party Links and Services
  • 13. Changes to This Privacy Policy
  • 14. Contact Us

Source: https://cinchapi.com/legal/privacy

1. Introduction

Cinchapi, Inc. (“Cinchapi,” “we,” “our,” or “us”) is committed to protecting the privacy of individuals who visit our websites, use our products and services, or otherwise interact with us. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you access or use any Cinchapi products, services, applications, or platforms, including those available at https://cinchapi.com and https://api.cinchapi.com (collectively, the “Services”).

This Privacy Policy applies to all users of our Services, including individual consumers and business customers. By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use our Services.

2. Information We Collect

2.1 Account Information

When you create an account or register for our Services, we may collect the following information:

  • Full name and display name
  • Email address
  • Company or organization name
  • Job title or role
  • Account credentials and authentication information
  • Profile preferences and settings

2.2 Payment and Billing Information

When you purchase or subscribe to our Services, we collect billing information necessary to process your transactions. This may include:

  • Credit or debit card number (processed and stored by our third-party payment processor)
  • Billing address
  • Transaction history and subscription details

We use third-party payment processors (such as Stripe) to handle payment transactions. We do not directly store your full credit card number on our servers.

2.3 Usage and Interaction Data

We automatically collect information about how you interact with our Services, including:

  • Log data (IP address, browser type, operating system, device identifiers)
  • Usage patterns, features accessed, and actions taken within the Services
  • Session duration, frequency of use, and performance metrics
  • Error logs and diagnostic information
  • Metadata about interactions with AI agents, assistants, and analysts, including features and models used, request status, timestamps, and performance information

2.4 Customer Content and AI Interactions

Our Services may allow you to submit, create, or process content and files, including:

  • Documents, data files, images, and other materials you submit to the Services
  • Prompts, goals, configurations, instructions, inputs, and outputs from your interactions with AI agents, assistants, and analysts
  • Custom automations, workflows, and integrations you create

2.5 Data from Connected Systems and Integrations

Our Services may connect to third-party systems, platforms, and data sources on your behalf. When you authorize such connections, we may collect and process:

  • Data retrieved from connected APIs, databases, and external services
  • Authentication tokens and credentials necessary to maintain connections, which are encrypted at rest
  • Metadata about connected systems and synchronization status

You are responsible for ensuring that you have the necessary rights and permissions to share data from connected systems with our Services.

2.6 Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activity, measure the effectiveness of our Services, and improve your experience. The types of cookies we use include:

  • Essential Cookies. Required for the operation of the Services, including authentication, security, and session management. These cookies cannot be disabled.
  • Analytics Cookies. Help us understand how users interact with the Services by collecting usage data. These cookies allow us to measure and improve performance.
  • Functional Cookies. Enable enhanced features and personalization, such as remembering your preferences and settings.
  • Marketing Cookies. Used to deliver relevant advertisements and measure the effectiveness of marketing campaigns.

We may use both first-party and third-party analytics and tracking tools for these purposes. The specific tools and services we use may change over time as we evaluate and adopt new technologies.

Even before you provide consent, our analytics provider may receive anonymous, aggregate page-view information from your browser, including the URL of the page you are viewing, the referring URL, approximate geographic region inferred from your IP address, and basic browser and device information (user agent). These signals do not include any persistent identifier, no cookie is set, and we cannot use them to recognize you across sessions or devices. We use them only to measure aggregate traffic and improve the Services. If you accept our cookie banner, we additionally place the analytics cookies described above and begin collecting session-level usage data. If you decline, or do not respond, only the anonymous aggregate signals continue.

You may manage your cookie preferences through our cookie consent banner (where available), your browser settings, or by contacting us at privacy@cinchapi.com. Please note that disabling certain cookies may affect the functionality of our Services. For users in the European Economic Area or the United Kingdom, we obtain your consent before placing non-essential cookies in accordance with applicable law.

2.7 Sensitive and Regulated Data

You must obtain Cinchapi’s express written agreement before submitting Restricted Regulated Data as defined in Section 7 of our Terms, including protected health information, Social Security numbers, financial account or payment-card numbers, government-issued identification numbers, and records requiring additional sector-specific safeguards. The ability to upload data is not authorization to submit it. Ordinary confidential business information and personal data are not restricted solely because they are confidential or subject to general data protection laws. Contact legal@cinchapi.com to discuss appropriate arrangements before submission. This restriction does not limit Cinchapi’s obligations under applicable law, this Policy, or an applicable data processing or other written agreement.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, maintain, secure, and improve our Services, subject to the model training choices and commitments in Section 3.1
  • To process transactions, manage subscriptions, and send billing-related communications
  • To personalize your experience and deliver relevant features and content
  • To enable AI agents, assistants, and analysts to execute tasks, goals, and automations on your behalf
  • To communicate with you regarding account activity, updates, security alerts, and support
  • To monitor and analyze usage trends, performance, and system health
  • To detect, prevent, and address fraud, abuse, security incidents, and technical issues
  • To comply with legal obligations and enforce our Terms of Use
  • To provide AI functionality and, only when authorized under Section 3.1, to perform model training or customer-specific model customization

3.1 AI Model Training and Improvement

“Customer Data” includes content and information submitted to or processed through the Services, including prompts, inputs, outputs, uploaded files, user submissions, and data retrieved from connected systems. “Service Data” means technical and operational information relating to use of the Services, including system logs, performance metrics, telemetry, and feature-usage statistics. Service Data excludes Customer Data, the content of Customer Data, and information reasonably capable of reconstructing or revealing Customer Data.

“Model Training” means using data to train, retrain, fine-tune, distill, or otherwise create or modify the weights or parameters of an artificial-intelligence or machine-learning model. A “Shared Model” is any model other than a Customer-Specific Model that is used by or for Cinchapi, another customer, or a third party. A “Customer-Specific Model” is a model or model customization created at a customer’s direction solely for that customer’s use and not used to train or improve another model or provide model functionality to another customer or third party.

An “Enterprise Offering” is a Service identified as enterprise in the applicable subscription plan, order form, service description, or written agreement. An “API Offering” is access to the Services through a Cinchapi application programming interface under an applicable API plan or agreement.

Cinchapi does not use Customer Data for Model Training by default. If we offer an optional model-improvement program, you may affirmatively enroll through the controls we provide. While you are enrolled, we may use eligible Customer Data to perform Model Training, including to train or improve Shared Models. The enrollment notice will describe the eligible Customer Data, purposes, retention period, and available controls. Enrollment applies only to eligible Customer Data submitted after you enroll unless you separately agree otherwise. You may withdraw prospectively at any time. Withdrawal stops the use of your Customer Data in future Model Training after the change takes effect, but does not require us to retrain, modify, or delete models developed before withdrawal. An affirmative enrollment may be limited to specific Customer Data that you choose to submit through a clearly disclosed feedback or model-improvement control.

For an organization or workspace account, only an owner or administrator authorized to manage data settings may enroll Customer Data in an optional model-improvement program. The enrollment controls will identify the account, workspace, users, and eligible Customer Data within the scope of the enrollment. The person enrolling represents that they have authority to make that choice for the displayed scope. An individual user may not enroll organization or workspace Customer Data outside that user’s authorized scope.

We do not use Customer Data submitted through an Enterprise Offering or API Offering to perform Model Training on a Shared Model, including through an optional model-improvement or feedback control. At a customer’s request, we may use specifically designated Customer Data solely to create, fine-tune, evaluate, or operate a Customer-Specific Model under a separate written agreement that describes the authorized use. Customer Data used for a Customer-Specific Model will not be used to train or improve a Shared Model.

Model Training does not include processing Customer Data through a model to generate an output; retrieval-augmented generation; creating embeddings, indexes, or caches solely to provide the Services; prompt configuration; or other processing that does not modify model weights or parameters. We may use Service Data, and aggregated or de-identified information that cannot reasonably identify you or your organization or reveal Customer Data, to operate, maintain, secure, support, analyze, and improve the Services. We may also use Service Data to train narrow models used solely to detect and address fraud, abuse, safety, reliability, and performance issues. These permissions do not authorize Model Training on Customer Data, which requires the affirmative enrollment or separate written agreement described in this Section 3.1. We do not use Service Data or aggregated or de-identified information to train or improve general-purpose generative AI models.

Human review for safety, abuse prevention, customer support, or quality assurance does not cause Customer Data to be included in Model Training. Customer Data may be reviewed for Model Training only when authorized through an affirmative enrollment or a written agreement for a Customer-Specific Model.

3.2 Marketing Communications

We may send you promotional emails, newsletters, SMS messages, or other marketing communications about our Services. You may opt out of marketing communications at any time by clicking the “unsubscribe” link in any marketing email, replying “STOP” to any marketing SMS, or contacting us at privacy@cinchapi.com.

Please note that even after opting out of marketing communications, you will continue to receive transactional and service-related messages, such as account notifications, billing communications, and security alerts.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers. We share information with third-party vendors who perform services on our behalf, such as payment processing, hosting, analytics, and customer support, subject to contractual obligations of confidentiality.
  • AI Infrastructure Providers. To deliver AI functionality, we may transmit Customer Data to third-party AI model and infrastructure providers for inference and related processing. We take commercially reasonable measures to prevent those providers from using Customer Data to train or improve their own models or models for third parties. Depending on the provider and offering, these measures may include negotiated contractual protections, provider commercial or API terms that restrict such use, and enabled data-use controls. We also enable zero-data-retention or comparable minimum-retention settings where commercially available and technically supported and otherwise use available controls to minimize provider retention. Provider retention practices and zero-data-retention availability vary by provider, model, and offering; we do not guarantee zero data retention unless expressly stated in a separate written agreement. A provider may perform Model Training solely on Cinchapi’s behalf when authorized by an affirmative enrollment or a written agreement for a Customer-Specific Model. These providers may otherwise process Customer Data only to provide services to Cinchapi and in accordance with our instructions.
  • Connected Third-Party Services. When you authorize integrations with third-party platforms, data may be transmitted to and from those services in accordance with your configuration and their respective privacy policies.
  • Legal Requirements. We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Cinchapi, our users, or others.
  • Business Transfers. In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice where required by applicable law.
  • With Your Consent. We may share your information with third parties when you have given us your express consent to do so.

Workspace Administration

If you use an organization or shared workspace, we make information available to authorized workspace administrators and billing managers according to their roles and the functionality of the Services. This may include your name, account email address, membership and role, assigned licenses, and usage information, including credit consumption. We also make workspace billing and shared-credit information available to users with the applicable permissions.

Administrative status does not, by itself, provide access to another user’s private conversations. Access to Customer Data depends on the applicable Service’s permissions and sharing settings. Your organization may separately process information it receives through the Services under its own privacy policies. Contact your organization about its handling of that information and Cinchapi about processing for which Cinchapi is responsible.

5. Data Retention

We retain personal information and Customer Data for as long as your account is active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.

Subject to the authorized Model Training and Customer-Specific Model retention described below, following account termination or deletion, we will delete or anonymize Customer Data no later than ninety (90) days after termination or deletion. If the Terms provide a post-termination retrieval period, we will not delete Customer Data before that period expires unless you request deletion or earlier deletion is required by applicable law. Copies residing in routine backup systems will be deleted in the ordinary course of backup rotation. We may retain information for longer where required by applicable law or reasonably necessary for security, fraud and abuse prevention, dispute resolution, enforcement of our agreements, or to establish, exercise, or defend legal claims.

If you affirmatively enroll in an optional model-improvement program, Customer Data used for Model Training may be retained for the period disclosed when you enroll. Withdrawal stops future Model Training after the change takes effect but does not require us to retrain, modify, or delete models developed before withdrawal. Customer Data used for a Customer-Specific Model is retained as provided in the applicable written agreement.

We may retain Service Data for as long as reasonably necessary for security, reliability, support, capacity planning, analytics, and product improvement. We may retain aggregated or de-identified information that cannot reasonably identify you or your organization indefinitely. We do not use Service Data or aggregated or de-identified information to train or improve general-purpose generative AI models.

To request earlier deletion or exercise applicable privacy rights, contact us at privacy@cinchapi.com.

6. Data Security

We implement reasonable administrative, technical, organizational, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, and destruction. Depending on the nature of the information and Services, these measures may include:

  • Encryption in transit and infrastructure-level encryption at rest for data stored in Google Cloud
  • Encryption of connector credentials at rest
  • Access controls and authentication measures
  • Security monitoring, assessment, and testing appropriate to identified risks
  • Personnel confidentiality obligations and security awareness measures
  • Incident-response and service-recovery procedures

While we take reasonable measures to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.

6.1 Breach Notification

In the event of a security breach that compromises your personal information, Cinchapi will notify affected users and applicable regulatory authorities in accordance with applicable law. For users in the European Economic Area or the United Kingdom, Cinchapi will notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of a qualifying breach, where required under GDPR. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms. For users in the United States, Cinchapi will comply with applicable state breach notification laws.

7. Human Review of Content

Cinchapi personnel may access and review user content, including inputs, outputs, uploaded files, and AI interactions, on a limited basis for the following purposes:

  • Safety monitoring and enforcement of our acceptable use policies
  • Abuse detection and prevention
  • Customer support, when you contact us for assistance or troubleshooting
  • Quality assurance and improvement of the Services

Human review is conducted under strict confidentiality obligations, and access to user content is limited to authorized personnel on a need-to-know basis. Human review does not cause Customer Data to be included in AI or machine-learning model-training datasets. Content reviewed for support, safety, abuse prevention, or quality assurance remains subject to Section 3.1.

8. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Request correction of inaccurate or incomplete personal information.
  • Deletion. Request deletion of your personal information, subject to certain exceptions.
  • Portability. Request a copy of your data in a portable, machine-readable format.
  • Objection/Restriction. Object to or request restriction of certain processing activities.
  • Withdrawal of Consent. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Model Training Choice. If we offer an optional model-improvement program, you may choose whether to enroll and may withdraw prospectively at any time.

To exercise any of these rights, please contact us at privacy@cinchapi.com. We will respond to verifiable requests within the timeframes required by applicable law.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the categories of sources from which it is collected, the business purpose for collection, and the categories of third parties with whom it is shared. You also have the right to request deletion of your personal information and the right to opt out of the sale or sharing of personal information.

Cinchapi does not sell personal information and does not share personal information for cross-context behavioral advertising as defined by the CCPA/CPRA. If our practices change in the future, we will update this Privacy Policy and provide the required opt-out mechanisms, including a “Do Not Sell or Share My Personal Information” link on our website.

To exercise your California privacy rights, please contact us at privacy@cinchapi.com. We will not discriminate against you for exercising your CCPA/CPRA rights.

10. European and UK Data Subjects (GDPR)

10.1 Legal Basis for Processing

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Performance of a Contract. Processing necessary to provide the Services you have requested.
  • Legitimate Interests. Processing necessary for our legitimate business interests, such as improving our Services, ensuring security, and conducting analytics, where those interests are not overridden by your data protection rights.
  • Consent. Where you have provided your explicit consent to specific processing activities, including optional Model Training where offered.
  • Legal Obligation. Processing necessary to comply with applicable laws and regulations.

10.2 Your Rights Under GDPR

In addition to the rights described in Section 8, EEA and UK data subjects have the right to lodge a complaint with a supervisory authority in the EU Member State or UK jurisdiction where you reside or where the alleged infringement occurred.

10.3 International Data Transfers

Your personal data may be transferred to and processed in the United States or other countries outside the EEA/UK. When transferring data outside the EEA/UK, we implement appropriate safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission or UK equivalent transfer mechanisms, to ensure that your data receives an adequate level of protection.

10.4 Business and Enterprise Processing

Where Cinchapi processes personal data on behalf of a user or organization acting as a data controller — for example, when you sync, upload, or connect data that contains the personal data of third parties — Cinchapi generally acts as a data processor or service provider and the customer generally acts as the controller or business. Our Data Processing Addendum is automatically incorporated into the applicable service agreement and governs that processing. Business customers may contact privacy@cinchapi.com for information about our sub-processors or data-processing practices.

10.5 Data Protection Contact

For privacy and data protection inquiries related to the processing of EEA or UK personal data, you may contact our Data Protection Contact at privacy@cinchapi.com with the subject line “Data Protection Inquiry.”

11. Children’s Privacy

Our Services are not directed to, or intended for, children under the age of thirteen (13). We do not knowingly collect personal data from children under 13. If you have reason to believe that a child under 13 has provided personal data to Cinchapi through the Services, please email us at privacy@cinchapi.com. We will investigate any such notification and, if appropriate, delete the personal data from our systems.

Users between the ages of thirteen (13) and eighteen (18) must have permission from their parent or legal guardian to use our Services. By permitting a minor to use the Services, the parent or guardian agrees to these terms on behalf of the minor and assumes responsibility for the minor’s use of the Services.

12. Third-Party Links and Services

Our Services may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our platform.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our website and updating the “Effective Date” above. We will provide additional or advance notice where required by applicable law. Your continued use of the Services after such changes constitutes your acceptance of the updated Privacy Policy.

A change to this Privacy Policy will not, by itself, authorize us to use Customer Data collected while Model Training was disabled for Model Training. Such use requires an affirmative enrollment or a separate written agreement as described in Section 3.1.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Cinchapi, Inc.
1175 Peachtree St NE
Atlanta, GA 30361
Email: privacy@cinchapi.com
Website: https://cinchapi.com

For GDPR-related inquiries, you may also contact us at the email address above with the subject line “GDPR Request.”

Operational AI for Work Across Systems

© 2026 Cinchapi Privacy Policy Terms of Use