Privacy Policy

Effective May 5, 2026. This policy explains what information Sertainly collects, how we use it, who we share it with, and the choices you have.

Who we are

Sertainly is operated by [ARCHIVERIS_ENTITY] (“Sertainly,” “we,” “us”). Sertainly is a decision infrastructure platform that compiles business rules into deterministic decision APIs. This policy applies to the Sertainly websites at sertainly.ai and to the Sertainly product.

Information we collect

We collect three categories of information:

  • Account information. Name, email address, and authentication identifiers when you sign up. We use Clerk for authentication; if you sign in with Google, we receive your basic profile (name, email, picture). Enterprise customers typically authenticate via single sign-on (SSO/SAML) through their own identity provider, in which case we receive the identifiers that provider passes to Clerk.
  • Customer content. Source documents, rules, schemas, test scenarios, and other content you upload or create in the product (“Customer Content”).
  • Usage and operational data. Logs, evaluation traces, audit events, error reports, IP address, browser information, and feature interaction events used to operate and secure the service.
  • Billing data. Under your subscription or enterprise agreement, billing information is processed by Stripe. We store the Stripe customer ID, plan, and payment status; we do not store full payment card numbers.

How we use information

We use the information we collect to:

  • Provide, operate, and secure the Sertainly service.
  • Process AI-assisted compilation, testing, and review of your Customer Content when you initiate those actions.
  • Bill you and prevent fraud or abuse on the platform.
  • Respond to support requests and communicate about service changes, security, and legal notices.
  • Comply with legal obligations and enforce our Terms of Service.

Our commitments

We do not sell your data.

We do not sell, rent, or license Customer Content or personal information to anyone. Ever.

We do not train AI models on your content.

Customer Content is never used to train, fine-tune, or improve any AI model — ours or anyone else's. Our AI subprocessors are contractually prohibited from training on data we send them on your behalf.

Bring your own AI credentials.

If you configure Sertainly to use your own AI provider credentials (for example, your own Anthropic API key), AI calls for your account route directly from your account to that provider under your contract with them. We do not see, store, or process your Customer Content through our own AI provider relationship in that mode.

Service providers

We share data only with vendors who process it on our behalf to run the service, under written agreements that limit how they use it. Our current service providers are:

  • Clerk — user authentication and session management.
  • Stripe — subscription billing and payments.
  • Amazon Web Services (AWS) — cloud hosting, storage, and infrastructure.
  • Anthropic — AI model inference for compilation, testing, and review (only when using Sertainly-provided AI credentials; see “Bring your own AI credentials” above).

We may also disclose information if required by law, to protect against fraud or abuse, or as part of a corporate transaction (such as a merger or acquisition) — in which case we will notify affected users.

Data retention

We retain account information and Customer Content for as long as your account is active. When an account is deleted, we delete associated Customer Content within 30 days, except where we are required to retain specific records (for example, billing records for tax purposes). Operational logs and evaluation traces are retained for up to 90 days; audit logs for up to 365 days.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact us at [PRIVACY_CONTACT]. We will respond within the timeframes required by applicable law.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you may lodge a complaint with your local data protection authority.

Security

We use industry-standard technical and organisational measures to protect personal information and Customer Content, including encryption in transit, encryption at rest for sensitive fields, access controls, and audit logging. No system is perfectly secure; if we become aware of a security incident affecting your information, we will notify you as required by law.

Cookies and similar technologies

We use a small number of strictly necessary cookies for authentication and session management (set by Clerk). We do not use third-party advertising or tracking cookies.

International data transfers

Sertainly is operated from the United States. If you access the service from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. Where required, we use standard contractual clauses or other lawful transfer mechanisms.

Children

Sertainly is not directed to children under 16 and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you via the email associated with your account or through a prominent notice on the service before the changes take effect. The “Effective” date at the top of this page reflects the most recent update.

Contact us

For questions about this policy or our privacy practices, contact us at [PRIVACY_CONTACT], or by mail at:

[ARCHIVERIS_ENTITY]
[ENTITY_ADDRESS]

See also our Terms of Service.