Last updated: April 30, 2026
Privacy Policy
Resora Cortex ("we", "us") provides AI-powered executive intelligence. This policy explains what data we collect, why we collect it, and the choices you have.
1. Information we collect
Account data. When you sign up we store your email, name, and authentication identifiers (e.g. Google OAuth subject).
Workspace content. Datasets you upload, dashboards you build, and prompts you send to the assistant are stored in your workspace and are only accessible to members of that workspace.
Usage data. We log basic telemetry (page views, feature usage, error traces) to operate and improve the product.
2. How we use information
- To deliver and maintain the service.
- To generate AI responses based on your prompts and connected data.
- To diagnose issues, prevent abuse, and improve reliability.
- To communicate important account or service notices.
3. AI processing
Prompts and the schema/sample rows required to answer them are sent to third-party model providers (Google, Anthropic) through the Lovable AI Gateway. We use API-only model providers that do not train on your content:
- Google Gemini API: Google does not use content sent through the paid / API Gemini service to train models or improve products.
- Anthropic API: Anthropic does not train on API inputs by default and does not retain them for model improvement.
Your full datasets, documents, and raw rows are never sent to a model provider. Only the extracted metadata, schema, small sample rows, and the prompt itself are transmitted. All AI gateway calls are made from Resora's servers; the gateway API key is never exposed in the browser.
4. Sharing
We do not sell your data. We share data only with infrastructure subprocessors (hosting, database, AI gateway) under contract, or when required by law.
5. Retention
Workspace content is retained until you delete it or close your account. Backups are purged on a rolling 30-day basis.
6. Your rights
You may access, export, or delete your data at any time. Contact us to exercise rights under GDPR, CCPA, or similar laws.
7. Security
Data is encrypted in transit (TLS) and at rest. Access is gated by row-level security and workspace role. Report vulnerabilities to support@resoracortex.com.
8. Contact
Questions about this policy? Email support@resoracortex.com.