Privacy Policy
Your privacy matters to us. This privacy policy explains how UltimateIntel collects, processes, stores, and protects your personal and business data. We are committed to transparency about our data practices and to giving you control over your information.
Data Collection We collect only the data necessary to provide intelligence services. This includes business data from your connected SaaS tools (synced via authenticated connectors), account information (name, email, company, role), usage analytics (queries asked, features used, session duration), and technical data (browser type, IP address for security purposes). We do not collect data beyond what is required to deliver and improve our services.
Data Processing Your data is processed exclusively on Google Cloud Platform infrastructure. We maintain strict processing boundaries to ensure your data is handled appropriately at every stage. PII is filtered before any LLM processing using automated pattern detection. We never train AI models on your data. Your business data is used solely to answer your queries and generate your intelligence briefs. Cross-tenant data is never mixed, shared, or used for aggregate analysis without explicit consent.
All data processing occurs within defined geographic regions. By default, data is processed in US regions. Enterprise and Strategic plan customers can configure EU or other regional data residency to meet local regulatory requirements.
Data Flow When you connect a SaaS tool, our connector service authenticates using your credentials (OAuth token or API key) and begins syncing data. Raw data is stored in Cloud SQL with row-level security isolation. Processed analytics data is stored in BigQuery with tenant-scoped access controls. Temporary processing data is held in memory only and never persisted. Query results are cached for 5 minutes in Firestore and then automatically expired.
Sub-processors We use a limited set of sub-processors to provide our services. Google Cloud Platform provides infrastructure, storage, and compute. Anthropic provides primary LLM services for query processing. OpenAI provides fallback LLM services. Stripe processes payments. Resend delivers transactional emails. All sub-processors are bound by data processing agreements and are regularly reviewed for security and compliance.
International Transfers For customers outside the United States, data may be transferred to US-based infrastructure for processing. We rely on Standard Contractual Clauses and other approved transfer mechanisms to ensure adequate protection for international data transfers. Enterprise customers can configure regional data residency to minimize international transfers.
Data Retention Active data is retained while your account is active and your subscription is current. Configurable retention policies allow you to set maximum data ages per data type. When data reaches its retention limit, it is automatically purged. Complete data deletion is available via DSAR request at any time. Crypto-shredding ensures permanent and verifiable deletion. Upon account termination, all data is deleted within 30 days in accordance with GDPR requirements.
Cookie Policy Summary Our website uses essential cookies for authentication and session management, analytics cookies for understanding usage patterns (opt-out available), and preference cookies for remembering your settings. We minimize third-party cookies and provide full cookie controls. See our dedicated Cookie Policy page for complete details.
Your Rights Under applicable privacy regulations including GDPR, you have the right to access your data through a Data Subject Access Request, the right to deletion with certified cryptographic proof of destruction, the right to data portability in standard machine-readable formats, the right to restrict processing of your personal data, the right to rectification of inaccurate personal data, and the right to object to processing based on legitimate interests. For privacy-related requests, contact us through our support form. We process all privacy requests within 30 days.