SourceLace
Legal

Privacy Policy

Effective [DATE OF PUBLICATION]

This policy explains what information SourceLace collects, why, where it is kept and for how long. SourceLace is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("SourceLace", "we", "us"). It covers the website sourcelace.com, the SourceLace app at sourcelace.ai, and the SourceLace MCP server that people add to AI apps such as Claude or ChatGPT (together, the "Service").

The short version

Who this applies to

Most people use SourceLace through their employer or another organization that has an account (a "Customer"). For data that flows through the Service from a Customer's business systems, the Customer decides what is connected and who may use it, and we process that data on the Customer's behalf and on its instructions. Questions about that data should go to the Customer's administrator first. For our own website and for account and billing records, we decide how the information is used.

What we collect

How we use it

We do not sell personal information, do not use it for advertising, and do not use your data or your systems' data to train AI models.

AI processing

If you use SourceLace from your own AI app (for example Claude or ChatGPT), SourceLace returns results to that app and sends nothing to an AI model itself; your app's own provider and terms apply. The assistant inside the SourceLace app sends your question, the chat so far and the relevant results to Anthropic, which provides the AI model that writes the answer: either through SourceLace's own Anthropic account, or through your organization's own Anthropic API key if your admin entered one, in which case your organization's agreement with Anthropic applies. Under Anthropic's commercial terms, Anthropic does not train its models on data sent through its API. If your admin chooses your organization's own OpenAI API key instead, the same content goes to OpenAI under your organization's agreement with OpenAI, and SourceLace asks OpenAI not to store it for later retrieval (OpenAI's own policies may still keep it for a limited time, for example for abuse monitoring).

If you use voice input in the app, your browser turns your speech into text with its own speech service (in Chrome and Edge that is Google's or Microsoft's; Safari uses Apple's or the device). SourceLace receives only the text.

Data from Google

If you sign in with Google, SourceLace asks only for your name and email address. If you connect Google sources, SourceLace requests only the access each source needs: reading mail and creating drafts in Gmail (it never sends email), reading Google Calendar, reading Google Drive files, reading and changing the Google Sheets you name, and running read-only BigQuery queries. SourceLace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

Google data is handled like any other source data: held in memory for up to 30 minutes, and kept longer only inside chats in the SourceLace app, as described above. You can remove SourceLace's access at any time by disconnecting the source in SourceLace, or from your Google Account's third-party connections.

Where it is stored and who helps us

The Service is hosted in the United States. We use these service providers, each bound by contract to protect the data and use it only to serve us:

The business systems you connect, and the AI app you use SourceLace from, are chosen by you or your organization and are governed by your own agreements with them. We will update this list before adding a provider that handles Customer data.

How long we keep it

Security

Data is encrypted in transit (HTTPS) and at rest. Connection tokens and logins, chats, generated files, projects, skills and organizations' own AI keys are additionally encrypted with a key unique to each organization, which SourceLace manages. Every request is recorded in a hash-chained audit trail, so a changed or deleted entry shows. Where you sign in to a system with your own account, you see only what your permissions there allow; for shared-access sources an admin adds, admins can limit who may use them. No system is perfectly secure; if a breach affects your information, we will notify you and your organization as the law requires. SourceLace does not hold any security certification such as SOC 2 or ISO 27001.

Your choices and rights

You can disconnect any system, delete your chats, and ask us for a copy of your personal information, to correct it, or to delete it. Depending on where you live (for example the EU, UK or California), you may have further rights, including to object to or restrict processing and to complain to your data protection authority. If your account belongs to a Customer, we may refer your request to that Customer. Email privacy@sourcelace.com; we answer within 30 days.

If you are in the EU or UK, we rely on contract (to provide the Service), legitimate interests (security and improving the Service) and legal obligation. Where information moves outside your country, we use safeguards such as the European Commission's standard contractual clauses.

Children

The Service is for businesses and is not directed to anyone under 16. We do not knowingly collect their information.

Changes

We will post changes here with a new effective date, and tell account holders by email before a material change takes effect.

Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email privacy@sourcelace.com. Security reports: security@sourcelace.com.