Privacy
Draft — private beta
This policy is issued by Masora Inc (“Masora,” “we,” or “us”) and covers our website, application, desktop connector, and related services (together, the “service”).
The short version
For orientation only; the sections below govern.
- Your company’s connected content is processed on your company’s instructions to provide the service — nothing else.
- We never use your content to train models, ours or anyone else’s, and our model providers are contractually prohibited from doing so.
- We never sell personal data and we show no ads.
- Read‑only ingestion, your existing permissions enforced, per‑company isolation.
- Disconnect a source and its credential is erased at once; what was ingested is deleted as soon as you ask. Leave Masora and you take a full export with you.
What this covers
This policy explains how Masora handles personal data across the service. Your use is also governed by our Terms. Business customers additionally have a Data Processing Agreement, which controls where the two differ.
Two kinds of data
Customer Content is the material your organization connects: messages and threads from chat tools, files from document stores, Claude session data shared through our connector, and the questions and answers produced inside your workspace. For this, your organization is the controller and Masora is the processor — we act only on its instructions.
Account data is information about you as a user: name, work email, sign‑in identifiers, billing contact, and device and usage logs. For this, Masora is the controller.
If you work at a customer of ours and have a question about material that mentions you, your organization controls that data — start with your administrator, and we’ll assist them.
How we handle Customer Content
- Purpose. We index, distill, and retrieve it solely to answer your organization’s questions with citations and to maintain the audit trail your admins see.
- Read‑only. Our integrations request read‑only scopes wherever the provider offers one, and the connectors only ever read. Two exceptions worth naming: GitHub’s OAuth has no read‑only repository scope, so the token we hold is broader than our use of it; and Slack, where — if you enable it — the service replies in channels and posts the briefings you schedule.
- Permissions. Source‑system access controls are honored. Users are never shown answers, citations, or even the existence of material they can’t open at the source.
- Claude sessions are opt‑in. Session content synced through the desktop connector requires that individual’s opt‑in, is scoped to the projects they choose, and stays visible to them in the connector.
- No training. We don’t use Customer Content to train or fine‑tune any model available to anyone outside your organization, and our model providers are contractually barred from training on it.
- No selling, no ads. Neither Customer Content nor personal data is sold or used for advertising.
- Isolation. Content is segregated per organization, encrypted in transit and at rest, with access recorded in an audit trail.
- Deletion. Disconnect a source and its credential is erased immediately. Content already derived from it is kept until you ask for it to be deleted — a separate, explicit step, which then runs at once. Content deleted at the source is removed here through scheduled propagation. On termination you can export everything, after which we delete Customer Content within 30 days unless law requires otherwise.
Account data we collect
- Profile and contact: name, work email, organization, role, password or SSO identifiers.
- Billing: we collect no payment details during private beta. When billing begins it will run through a payment processor, and we will never store full card numbers.
- Device and log data: IP address, browser and OS, timestamps, and request records generated as you use the service.
- Communications: anything you send us, including support requests.
How we use it
To run, secure, and improve the service; to manage accounts and workspaces; to bill; to provide support; to send service and security notices, with marketing messages opt‑out at any time; to prevent abuse; and to meet legal obligations. We may derive aggregate operational metrics — query volumes, latency, feature usage — that contain no Customer Content and no identifiable personal data.
Who we share it with
- Service providers, bound by contract to confidentiality and purpose limitation: hosting, model inference (Anthropic), embeddings (Voyage AI), and email delivery. A payment processor joins this list when billing begins. Customers are notified of changes to it as set out in the DPA.
- At your direction, with third parties you authorize.
- Legal process, where required by law or to protect the safety and rights of users, the public, or Masora. Where legally permitted, we notify the affected customer before disclosing Customer Content.
- Corporate transactions, under obligations at least as protective as this policy, with notice of any material change.
We never sell personal data or share it for cross‑context behavioral advertising.
Cookies
Essential cookies only — authentication, security, preferences — plus privacy‑respecting product analytics. No advertising cookies or third‑party trackers. You can block cookies in your browser, though disabling the essential ones breaks sign‑in.
Security and retention
Our measures are described on the security page. No system is perfectly secure; we notify affected customers of a personal data breach as required by law and the DPA.
Customer Content is retained under your organization’s control, as above. Account data is kept while your account is active and afterward only as needed for billing records, security logs, or dispute resolution, then deleted or de‑identified.
Your rights
Depending on where you live you may have rights to access, correct, delete, restrict, or object to processing, to portability, to withdraw consent, and to complain to a supervisory authority — under the GDPR and its UK and Swiss equivalents, or under US state laws including California’s. We don’t sell or share personal data for cross‑context behavioral advertising, and we won’t treat you differently for exercising a right.
For account data, write to hello@masora.com and we’ll verify your identity and respond within the time the law allows. For Customer Content, we refer the request to your organization and assist them.
International transfers
Where personal data originating in the EEA, UK, or Switzerland moves to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with UK and Swiss addenda, incorporated into our DPA. Customers needing regional residency can run the service in their own cloud environment in the region they choose.
Children
The service is for business use and isn’t directed to children. We don’t knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to hello@masora.com and we’ll delete it.
Changes and contact
We’ll post updates here and, for material changes, notify you by email or in‑product before they take effect. The policy in force when data was collected governs that data.
Questions: hello@masora.com.