This policy explains what information purpal (“purpal”, “we”, “us”) collects when you use purpal.ai and the purpal product, how we use it, who we share it with, and the choices you have. purpal is operated by Purpal.ai LLC, a Pennsylvania limited liability company.
Questions about this policy or your data: hello@purpal.ai.
1. What purpal does
purpal is a product management tool. It reads the customer feedback and documents you give it, groups that feedback into themes, drafts specs and engineering tickets, answers questions about your data in chat, and sends a daily brief. To do that it has to store and process the content you upload or connect.
2. Information we collect
Account information
- Your name, email address and password (passwords are stored hashed by our authentication provider, never in plain text).
- If you sign in with Google: the basic profile Google shares with us, which is your name, email address and profile picture. We do not request access to your Gmail, Drive or Calendar when you sign in.
- Workspace details you enter during setup, such as your company name, website and a description of your product, plus your workspace's time zone (used to send the daily brief at the right local hour).
- Email addresses of teammates you invite.
Content you upload or connect (“Customer Content”)
- Files you upload, such as CSV and Excel exports of customer feedback, PDFs, Word documents, slides and text files.
- Data from tools you choose to connect, for example support conversations (such as Intercom), messages from channels you select (such as Slack), call and meeting transcripts (such as Zoom, Google Meet or Gong), and issue trackers you push work to (such as Linear or Jira). We only access a tool after you connect it, and only for the purposes described here.
- What you create in purpal: chat messages, specs, decisions and notes, and the product memory purpal builds from them.
Customer Content often contains information about your own customers (for example names or email addresses inside support tickets). You control what you upload or connect, and you are responsible for having the right to share it with us.
Public web information
When you set up a workspace, purpal researches your company, market and competitors using publicly available web pages and search results, and it may run further web searches when you ask it to. This uses public information only.
Usage and technical information
- Product analytics. On purpal.ai we use an analytics service to understand how the site and product are used: pages viewed, buttons clicked, and session recordings. Recordings mask everything you type, and inside the product they also mask the text on screen, so your Customer Content is not captured.
- Error monitoring. We use an error-monitoring service to detect and fix errors. Error reports can include your user ID, IP address, browser details and the request that failed.
- AI request logs. We keep traces of requests made to AI models so we can debug and improve answer quality. These traces can contain the prompts and responses for that request, which may include Customer Content.
Cookies
We use a small number of cookies:
- Sign-in cookies that keep you logged in. These are strictly necessary.
- Functional cookies that remember settings:
pp_platform(tells your browser which of our backend services to talk to),pp_onboarded(skips a setup check on each page load) and a cookie that remembers how you left the setup checklist. We also store your light or dark theme choice in your browser's local storage. - Analytics identifiers set by our analytics service on purpal.ai, as described above.
We do not use advertising cookies and we do not sell or share your information for advertising. Analytics help us understand and improve purpal; you can block them with your browser's privacy settings or a content blocker, and purpal works normally without them.
3. How we use information
- To provide the service: processing your Customer Content into themes, specs, tickets, chat answers and the daily brief, and pushing work to the tools you connect.
- To run your account: sign-in, team invitations, and service and security emails.
- To send the daily brief by email. You can turn it off in Settings or with the unsubscribe link in any brief.
- To keep purpal secure and reliable, investigate errors, and prevent abuse.
- To understand how purpal is used and improve it, using the analytics described above.
- To comply with legal obligations.
4. AI processing
purpal uses AI models from established cloud providers to read and summarise your content, and to create the embeddings (numeric representations of text) that let purpal search your content and group feedback into themes.
We do not use your Customer Content to train AI models. Our primary AI provider's terms do not permit it to use the data we send to train its models.
AI output can be wrong. See our Terms of Service for more on reviewing it before you act on it.
5. Who we share information with
We do not sell your personal information. We share it only with service providers (“sub-processors”) that help us run purpal, under contracts that limit their use of it to providing their service to us:
- Cloud hosting and storage providers: application hosting, databases, sign-in and file storage.
- AI model providers: reading and summarising your content, and creating embeddings.
- Email delivery providers: sending emails such as invitations and the daily brief.
- Integration connectors: securely managing the sign-in connections to the tools you connect, such as Slack or Zoom.
- Web search providers: company and market research. We send them search queries and public URLs, not your Customer Content.
- Analytics, error-monitoring and AI request-logging services: as described above.
A current list of our sub-processors is available on request at hello@purpal.ai.
When you connect a third-party tool or push work to it, data flows to that tool under its own terms and privacy policy. We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different policy.
6. Google user data
purpal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features you asked for; we do not use it for advertising, we do not sell it, we do not use it to train AI models, and we do not let people read it except with your consent, for security purposes, or where the law requires.
7. Where your data is stored
purpal stores and processes data in the United States. If you access purpal from outside the United States, your information is transferred to the United States. For personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and their UK equivalent) in our agreements with service providers. Business customers can request a Data Processing Agreement at hello@purpal.ai.
8. How long we keep it, and deleting it
- We keep your account and Customer Content for as long as your account is active, or until you delete it.
- Deleting a file in purpal removes it from your workspace together with the feedback and search index built from it.
- A workspace owner can reset the workspace in Settings, which permanently deletes its feedback, themes, specs, documents, chat history and memory.
- To delete your account entirely, email hello@purpal.ai from the address on the account. We will delete it and its Customer Content within 30 days.
- Copies in backups and logs are removed as those age out, within 30 days. We may keep limited records where the law requires it.
9. Security
We protect your data with encryption in transit (HTTPS) and at rest, access controls that limit our staff's access to what is needed to run the service, and database-level row security that keeps each workspace's data separate from every other workspace's. Connected tools are authorised through OAuth or API keys that you can revoke at any time by disconnecting the tool. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to or restrict certain processing. To make a request, email hello@purpal.ai. We will respond within the time the law requires and may need to verify your identity first. You can also turn off the daily brief email at any time, disconnect any integration, and remove a teammate's access.
If your workspace was set up by your employer, they control the Customer Content in it, and we may refer your request to them.
11. Children
purpal is a business tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy as purpal changes. We will change the “Last updated” date above, and if a change is significant we will tell you by email or in the product before it takes effect.
13. Contact
Purpal.ai LLC
hello@purpal.ai