In plain language: Noorle is the controller of information used to run our website, accounts, billing, and business. For Customer Content processed through agents, Programs, Workflows, Gateways, and Capabilities, Noorle generally acts on the Customer’s instructions. We do not sell personal data or share it for cross-context behavioral advertising. The full Policy below controls.
1. Scope and who is responsible
This Privacy Policy explains how Noorle Inc., a Delaware corporation (“Noorle,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal data when you visit our websites, create or administer an account, communicate with us, or use the Noorle platform and related services (collectively, the “Services”).
Noorle is the controller of personal data used for our website, account administration, billing, security, support, and business operations. When a Customer submits personal data in prompts, files, Knowledge, messages, tool calls, agent output, or other Customer Content, Noorle generally acts as the Customer’s processor or service provider. The Customer determines why that data is processed and is responsible for its own notices, permissions, and responses to individuals.
If you use a service, agent, or application operated by a Noorle Customer, that Customer’s privacy notice—not this Policy—primarily explains its practices. You should direct requests about its use of your data to that Customer. We assist Customers with those requests as required by law and our agreement with them.
2. Personal data we collect
The table below describes the categories of personal data we may collect, including during the preceding 12 months, where it comes from, why we use it, and the categories of recipients to which it may be disclosed.
| Category and examples | Sources | Main purposes | Recipient categories |
|---|---|---|---|
| Identifiers and account data — name, email, company, account and user IDs, role, authentication records | You; your organization’s administrators; identity providers | Create and secure accounts; provide the Services; communicate; support | Cloud and identity providers; security and support providers; authorized account administrators |
| Commercial and billing data — plan, billing contact, transaction records, usage charges, payment status; payment-card details are handled by our payment processor | You; your organization; payment processors | Billing, credits, tax, accounting, fraud prevention, customer service | Payment processors; accounting and professional advisers; authorities where required |
| Device, network, and activity data — IP address, browser and device type, timestamps, pages viewed, API requests, capability use, errors, diagnostics, and performance data | Collected automatically from browsers, clients, APIs, and infrastructure | Deliver, secure, debug, meter, and improve the Services; optional analytics | Hosting, observability, security, and analytics providers |
| Communications — contact-form submissions, emails, support tickets, call notes, and feedback | You; your organization; support channels | Respond, provide support, maintain business records, improve the Services | Support and communications providers; professional advisers |
| Customer Content and run records — prompts, messages, files, Knowledge materials, Programs, plugin code, configurations, tool inputs and outputs, model output, journal events, approvals, and artifacts | You; authorized users; agents; connected systems and integrations | Execute Customer instructions; provide memory, durability, governance, audit, and support | Infrastructure and model providers; connected services selected by the Customer; authorized account users |
| Credentials and connection data — API keys, OAuth tokens, connector secrets, service-account credentials, permitted hosts, and integration configuration | You; account administrators; connected services | Authenticate requests and perform the external operations you configure | Security and infrastructure providers; the connected service for the requested operation |
We also create operational records such as resource identifiers, cost attribution, admission decisions, fraud signals, and aggregated service metrics. We may combine information across the Services when needed to secure an account, reconstruct a Run, provide support, or meet legal obligations.
Customer Content may contain sensitive personal data if a Customer chooses to submit it. Noorle does not intentionally collect sensitive personal data for its own purposes except where needed for account security, authentication, payments, fraud prevention, or legal compliance. Customers should not submit sensitive data unless it is necessary, lawful, and protected by appropriate controls.
3. Customer Content and autonomous systems
Noorle processes Customer Content to execute the Customer’s instructions and provide the configured Agent, Program, Workflow, Gateway, Capability, Knowledge, memory, Workspace, or channel behavior. This can include sending selected content to model providers or external services chosen by the Customer.
The journal may preserve prompts, model and Capability attempts, approval decisions, outputs, costs, principal chains, and operational evidence needed for durability, governance, billing, security, and troubleshooting. Customers control which users and resources can access those records through account roles and grants.
Noorle does not use content ingested into Knowledge to train Noorle or third-party foundation models. We may use aggregated or de-identified operational information that cannot reasonably identify a Customer, user, or individual to measure, secure, and improve the Services.
Noorle does not use personal data about website visitors or account holders to make automated decisions that produce legal or similarly significant effects for Noorle’s own purposes. Customers may configure autonomous systems that make or assist with decisions. The Customer is responsible for any notice, explanation, consent, human review, appeal, or risk assessment required for that use.
4. How and why we use personal data
We use personal data for the following purposes:
- Provide and perform the Services: create accounts, execute configured work, maintain threads and Workflows, connect external systems, store files, provide support, and fulfill our contract with you.
- Authenticate and secure: verify identity, enforce permissions, detect abuse and fraud, investigate incidents, protect infrastructure, and preserve journal evidence.
- Meter and bill: calculate model, runtime, compute, storage, and outside-world costs; maintain balances; process payments; and provide receipts.
- Operate and improve: monitor reliability, diagnose failures, understand feature performance, and develop improvements using service data and appropriately de-identified information.
- Communicate: send transactional notices, service updates, security alerts, support responses, and—with your choice where required—product or marketing communications.
- Comply and protect: meet legal, tax, accounting, sanctions, and regulatory duties; respond to lawful requests; and establish, exercise, or defend legal claims.
Where European or UK data-protection law applies, our legal bases are:
- Contract: processing needed to provide the Services or take requested steps before entering a contract;
- Legitimate interests: securing and improving the Services, preventing abuse, supporting Customers, and operating our business, where those interests are not overridden by your rights;
- Consent: optional analytics, marketing, or another use where we ask for consent; and
- Legal obligation: processing required by applicable law.
You may withdraw consent at any time. Withdrawal does not affect processing already completed. You may object to processing based on legitimate interests as described under Your privacy rights.
5. How we disclose personal data
We disclose personal data only as needed for the purposes described in this Policy:
- Vendors and subprocessors: hosting, storage, databases, model inference, observability, security, analytics, communications, support, and payment providers working under contract.
- Services you connect or direct us to use: model providers, MCP servers, APIs, channels, websites, and other third-party systems selected or configured by a Customer.
- Your account and authorized users: administrators, collaborators, clients, or other principals granted access to the relevant resources and journal records.
- Professional advisers: auditors, lawyers, insurers, accountants, and advisers subject to confidentiality duties.
- Legal and safety recipients: courts, regulators, law enforcement, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, and service integrity.
- Corporate transactions: a prospective or completed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.
- With your direction or consent: when you ask us to disclose information or clearly authorize the disclosure.
We do not sell personal data for money. We do not share personal data for cross-context behavioral advertising or use it for targeted advertising. We do not use sensitive personal data to infer characteristics about individuals for advertising.
If a Customer intentionally publishes a Gateway, artifact, plugin, registry listing, or other resource, the information selected for publication may become public according to that feature’s settings.
6. Cookies, analytics, and similar technologies
We use strictly necessary technologies for site delivery, security, session management, and remembering privacy choices. With consent where required, we use PostHog analytics to understand visits and product interactions. We configure analytics without session recording and do not enable advertising profiles through the website.
We also use security and error-monitoring technologies to detect failures and protect the Services. These may receive device, network, and diagnostic information needed to identify the event.
You can accept, reject, or manage optional analytics through the cookie controls presented on the website. Browser settings can also block or delete cookies, although necessary features may not work correctly. Because Noorle does not sell or share personal data for behavioral advertising, opt-out preference signals such as Global Privacy Control do not change those practices; we honor such signals where applicable law requires them.
7. Retention and deletion
We keep personal data only as long as reasonably necessary for the purpose collected, including to provide the Services, maintain security and durability, comply with law, resolve disputes, and enforce agreements. Retention depends on the data and context:
- Account and profile data is generally kept while the account is active and for a limited period afterward for recovery, support, fraud prevention, and legal claims.
- Customer Content, run records, Workspaces, memory, and Knowledge follow the account, feature configuration, documented deletion behavior, and our agreement with the Customer.
- Billing and transaction records are kept for the period required by tax, accounting, anti-fraud, and financial laws.
- Security, access, and diagnostic logs are kept in rolling operational periods and may be retained longer when connected to an incident, abuse investigation, or legal obligation.
- Support and legal records are kept for the time needed to resolve the matter and preserve relevant business or legal history.
- Consent and privacy-request records are kept as needed to demonstrate compliance and honor future choices.
When the purpose ends, we delete, de-identify, or isolate the data unless continued retention is required or permitted by law. Deletion from active systems may not immediately remove data from encrypted backups; backup copies age out under our backup lifecycle and are not restored except for recovery.
8. Security
We use administrative, technical, and organizational safeguards designed to protect personal data. Depending on the service and data, these include encryption in transit and at rest, account-scoped tenancy, role and grant enforcement, secret handling, execution isolation, logging, monitoring, and incident-response procedures.
No system is completely secure. You are responsible for protecting your credentials, configuring least-privilege access, and using approval and budget controls appropriate to your work. If you believe your account or data may have been compromised, contact [email protected] promptly.
For more about the platform’s control model, see Trust and governance.
9. International transfers
Noorle is based in the United States, and we and our providers may process personal data in the United States and other countries. Those countries may have data-protection laws different from the laws where you live.
Where applicable law requires a transfer mechanism, we use legally recognized safeguards, such as adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid mechanism. Contact [email protected] for information about safeguards relevant to your data.
10. Your privacy rights
Depending on where you live and our role for the data, you may have the right to:
- confirm whether we process your personal data and access a copy;
- correct inaccurate personal data;
- delete personal data;
- receive portable data in a usable format;
- restrict or object to certain processing;
- withdraw consent;
- opt out of sale, targeted advertising, or qualifying profiling;
- appeal our response to a request; and
- receive equal service and pricing without retaliation for exercising a privacy right.
Submit a request by emailing [email protected] or using our contact form. Put “Privacy request” or “Privacy appeal” in the subject and tell us the account or email involved and the right you want to exercise.
We may ask for information reasonably necessary to verify your identity, authority, and the data involved. An authorized agent may submit a request where permitted by law; we may ask for proof of authorization and may verify the request directly with you. We will respond within the period required by applicable law and explain any denial and available appeal.
If Noorle processes the relevant data only for a Customer, we may direct the request to that Customer or ask you to identify it so we can assist.
You may unsubscribe from marketing email through the link in the message. Transactional, security, billing, and service notices are not marketing and may continue while you have an account.
11. Regional disclosures
11.1 California
The categories in Personal data we collect describe the personal information we collected, the sources, purposes, and categories of recipients during the preceding 12 months. The section How we disclose personal data describes our disclosure practices.
California residents may have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to receive equal treatment for exercising those rights. Noorle does not sell personal information or share it for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16.
We use sensitive personal information only for permitted operational purposes—such as authentication, security, payments, fraud prevention, and providing requested Services—or as directed by a Customer. We do not use it to infer characteristics for advertising.
Requests and authorized-agent submissions can be made through the methods in Your privacy rights. We verify requests in proportion to their sensitivity and the risk of unauthorized access or deletion.
11.2 Other U.S. states
Residents of U.S. states with comprehensive privacy laws may have rights to access, correct, delete, and obtain portable personal data, and to opt out of sale, targeted advertising, or certain profiling. Noorle does not engage in sale or targeted advertising as described above.
If we deny your request, you may appeal by emailing [email protected] with “Privacy appeal” in the subject. We will explain our decision and any method available to contact your state regulator.
11.3 European Economic Area, United Kingdom, and Switzerland
Individuals in these regions may have rights of access, correction, erasure, portability, restriction, objection, and withdrawal of consent. You may also complain to the data-protection authority where you live or work. Where Noorle acts only as a processor, the Customer is responsible for responding and Noorle will assist it as required.
12. Children
The Services are designed for businesses and adults and are not directed to children under 18. We do not knowingly collect personal data directly from a child under 13. If you believe a child has provided personal data to Noorle without appropriate authorization, contact [email protected].
Customers may not use the Services to process children’s personal data unless they have a lawful basis, provide required notices and protections, obtain any required parental consent, and comply with the Terms of Use and applicable child-safety and privacy laws.
13. Third-party sites and services
The Services may link to or connect with third-party sites and services. Their privacy practices are governed by their own notices. A Customer’s decision to connect a service instructs Noorle to exchange the data needed for that operation, but does not make Noorle responsible for the third party’s independent practices.
14. Changes to this Policy
We may update this Policy when our Services, practices, or legal obligations change. We will post the revised Policy, update the “Last updated” date, and provide additional notice when a change materially affects how we use personal data or when law requires it.
15. Contact us
Questions, requests, or complaints about this Policy or our privacy practices may be sent to:
- Privacy: [email protected]
- Legal: [email protected]
- Company: Noorle Inc., a Delaware corporation
Where applicable, you may also contact the data-protection or consumer-protection authority in your jurisdiction.