Privacy is a product surface, not a legal page. You can see and change what's collected from your workspace settings; the legal page at /privacy is the long form.
Consent categories
Essential
Auth, billing, core product telemetry. Always on — without it the product cannot function.
Product analytics
Anonymous usage signals that help us improve the workspace. Opt-in.
AI-graded competence
Lets the product use AI to grade your practice and feed your private Competence view. Off by default; explicit consent required.
Marketing
Nurture and product updates by email. Opt-in; welcome and security emails are transactional and unaffected.
For regulated buyers, the DPA includes customer-managed keys (CMK) on request andData Minimisation Mode on request. Talk to your account contact.
Delete your data
Open Account → Privacy
You can delete your workspace from the same place you manage consent.
We anonymise financial records
Invoices and tax records must be retained — they are anonymised so they no longer link to you.
Everything else is purged
Documents, cards, personas, skills, sessions, BYOK keys, and stored files are removed within the deletion window stated in the DPA.
You receive a deletion receipt
A signed confirmation that the deletion ran. Useful for your own records and audits.
If you're a member of an org workspace, deleting your individual account does not delete org-owned content created in your name. The org admin handles those — see Members.