Privacy Policy
Effective [DATE OF PUBLICATION]
This policy explains what information SourceLace collects, why, where it is kept and for how long. SourceLace is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("SourceLace", "we", "us"). It covers the website sourcelace.com, the SourceLace app at sourcelace.ai, and the SourceLace MCP server that people add to AI apps such as Claude or ChatGPT (together, the "Service").
The short version
- SourceLace reads your business systems live and does not copy their data into a store of its own. For most systems each person signs in with their own account, so the system's own permissions apply.
- Query results are held in memory for up to 30 minutes so the AI can use them, then discarded. The one exception is chats in the SourceLace app, described next.
- Chats in the SourceLace app are saved automatically, including the answers and the rows they show, so you can come back to them. They and the files made in them are encrypted with a key unique to your organization and deleted after your organization's retention period (30 days after a chat was last used, unless your admin sets another).
- We never sell personal information and never use your data, or data from Google, to train AI models or for advertising.
Who this applies to
Most people use SourceLace through their employer or another organization that has an account (a "Customer"). For data that flows through the Service from a Customer's business systems, the Customer decides what is connected and who may use it, and we process that data on the Customer's behalf and on its instructions. Questions about that data should go to the Customer's administrator first. For our own website and for account and billing records, we decide how the information is used.
What we collect
- Account information. Your email address, the organization you belong to, your role there, who invited you, and when you last signed in. You sign in with Google, Microsoft or your organization's single sign-on; SourceLace asks them only for your name and email address and keeps the email address.
- Connection tokens and logins. When you connect a business system, that system gives SourceLace a sign-in token for you. For most systems you sign in on the system's own page, so we never see your password. For databases, which have no such page, you type your database login into SourceLace. Tokens and logins are encrypted with a key unique to your organization, used only to act for you, never shown back and never written to logs. A few systems an admin may add, such as Gong, Amazon S3 or a connector your organization built, use one shared access set up by the admin instead of a sign-in per person.
- Business data you ask about. Records, files, emails and other content returned by your connected systems when you, or an AI app acting for you, asks a question. It is read on demand and held in memory for up to 30 minutes. Files are read where they sit and never indexed. A change you are asked to confirm is held in memory for 10 minutes, then discarded if not confirmed.
- Chats and what you make in the app. Chats in the SourceLace app, saved automatically (your questions, the answers and the data shown in them), files generated in a chat (such as Word, PowerPoint or PDF reports), charts pinned to a project, projects with their instructions, and skills your organization writes.
- Organization settings. Settings your admins choose, such as chat retention and which AI model to use, and, if your organization brings its own AI provider key or single sign-on, that key or secret, stored encrypted and never shown again.
- Audit records. For every request: who made it, when, which tool and system, the object and record, the query text, the names of fields changed, how many rows came back, and whether it succeeded. The query text can include values you typed, such as a customer name. Audit records never contain the rows returned or the values written.
- Usage and billing information. Counts of requests per person and the AI usage of each question (token counts only, never the question or the answer), used to apply plan limits and to bill. Payment details, once billing is enabled, are handled by our payment processor; we do not store card numbers.
- Website and cookies. sourcelace.com sets no cookies and has no analytics. Its pages load fonts from Google Fonts, so your browser connects to Google's servers. The app at sourcelace.ai uses one cookie to keep you signed in. If you email us, for example to request a pilot, we keep that correspondence.
How we use it
- To provide the Service: sign you in, connect your systems, answer your questions, make the changes you confirm, and show your organization's admins its audit trail and usage.
- To keep the Service secure, prevent abuse and investigate problems.
- To bill your organization and enforce its plan.
- To contact you about the Service, such as security notices and changes to these terms.
We do not sell personal information, do not use it for advertising, and do not use your data or your systems' data to train AI models.
AI processing
If you use SourceLace from your own AI app (for example Claude or ChatGPT), SourceLace returns results to that app and sends nothing to an AI model itself; your app's own provider and terms apply. The assistant inside the SourceLace app sends your question, the chat so far and the relevant results to Anthropic, which provides the AI model that writes the answer: either through SourceLace's own Anthropic account, or through your organization's own Anthropic API key if your admin entered one, in which case your organization's agreement with Anthropic applies. Under Anthropic's commercial terms, Anthropic does not train its models on data sent through its API. If your admin chooses your organization's own OpenAI API key instead, the same content goes to OpenAI under your organization's agreement with OpenAI, and SourceLace asks OpenAI not to store it for later retrieval (OpenAI's own policies may still keep it for a limited time, for example for abuse monitoring).
If you use voice input in the app, your browser turns your speech into text with its own speech service (in Chrome and Edge that is Google's or Microsoft's; Safari uses Apple's or the device). SourceLace receives only the text.
Data from Google
If you sign in with Google, SourceLace asks only for your name and email address. If you connect Google sources, SourceLace requests only the access each source needs: reading mail and creating drafts in Gmail (it never sends email), reading Google Calendar, reading Google Drive files, reading and changing the Google Sheets you name, and running read-only BigQuery queries. SourceLace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google data only to provide the features you use in SourceLace, at your request.
- We do not transfer Google data to others except as needed to provide those features (for example to the AI model provider that writes the answer you asked for in the SourceLace app, or to the AI app you use SourceLace from), to comply with law, or as part of a merger or acquisition with notice to you.
- We do not use Google data for advertising, and we do not sell it.
- No person at SourceLace reads your Google data unless you ask us to for support, it is needed for security or to comply with law, or it has been aggregated and anonymized for internal operations.
- We do not use Google data to develop, improve or train generalized AI or machine learning models.
Google data is handled like any other source data: held in memory for up to 30 minutes, and kept longer only inside chats in the SourceLace app, as described above. You can remove SourceLace's access at any time by disconnecting the source in SourceLace, or from your Google Account's third-party connections.
Where it is stored and who helps us
The Service is hosted in the United States. We use these service providers, each bound by contract to protect the data and use it only to serve us:
| Provider | What for |
|---|---|
| Render | Hosting the Service, the website and the database (United States) |
| Anthropic | AI model for the SourceLace app's assistant, when your organization uses the AI included in its plan |
| OpenAI | AI model for the SourceLace app's assistant, only when your organization's admin enters the organization's own OpenAI key |
| Google Workspace | Our company email, including messages you send us |
| Cloudflare | Domain name service (DNS) for our websites |
| [PAYMENT PROCESSOR] | Billing, once enabled |
The business systems you connect, and the AI app you use SourceLace from, are chosen by you or your organization and are governed by your own agreements with them. We will update this list before adding a provider that handles Customer data.
How long we keep it
- Query results: up to 30 minutes, in memory only. Unconfirmed change previews: 10 minutes, in memory only.
- Chats and the files made in them: until you delete them, or automatically after your organization's retention period, counted from the chat's last use (30 days unless your admin sets another). Charts pinned from a chat go with it.
- Projects and skills: until you or your admin delete them.
- Connection tokens and logins: until you disconnect the system, the token expires, or your account is removed.
- Audit records and usage counts: for as long as your organization's account is active, because the audit trail is your organization's tamper-evident record.
- When an organization closes its account, we delete its data within 90 days, except where law requires us to keep something longer.
Security
Data is encrypted in transit (HTTPS) and at rest. Connection tokens and logins, chats, generated files, projects, skills and organizations' own AI keys are additionally encrypted with a key unique to each organization, which SourceLace manages. Every request is recorded in a hash-chained audit trail, so a changed or deleted entry shows. Where you sign in to a system with your own account, you see only what your permissions there allow; for shared-access sources an admin adds, admins can limit who may use them. No system is perfectly secure; if a breach affects your information, we will notify you and your organization as the law requires. SourceLace does not hold any security certification such as SOC 2 or ISO 27001.
Your choices and rights
You can disconnect any system, delete your chats, and ask us for a copy of your personal information, to correct it, or to delete it. Depending on where you live (for example the EU, UK or California), you may have further rights, including to object to or restrict processing and to complain to your data protection authority. If your account belongs to a Customer, we may refer your request to that Customer. Email privacy@sourcelace.com; we answer within 30 days.
If you are in the EU or UK, we rely on contract (to provide the Service), legitimate interests (security and improving the Service) and legal obligation. Where information moves outside your country, we use safeguards such as the European Commission's standard contractual clauses.
Children
The Service is for businesses and is not directed to anyone under 16. We do not knowingly collect their information.
Changes
We will post changes here with a new effective date, and tell account holders by email before a material change takes effect.
Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email privacy@sourcelace.com. Security reports: security@sourcelace.com.