Privacy Policy

Last updated: June 11, 2026

Overview

This policy describes how Substantively Software LLC, a Georgia limited liability company ("Substantively," "we," "us"), handles personal data in connection with the Substantively application and the substantively.ai website (together, the "Service"). The Service is built for business use by audit teams; the single most important fact about our data handling is architectural:

Your audit evidence and documents never reach our servers. Files stay in your own Microsoft 365 / SharePoint tenant; we store references to them (names, links, identifiers), not their content. Our continuous-integration pipeline fails any code change that would handle file content server-side.

Our two roles

As a processor:the information your team puts into its workspace — projects, tasks, controls, issues, risks, time entries, comments, file references, and any personal data they happen to contain — is processed on your organization's behalf and under its instructions. Your organization is the data controller for that content; requests concerning it should go to your organization, and we will assist it. A data processing addendum (DPA) is available on request.

As a controller: we decide how to handle the narrower set of data needed to run the Service itself — account, billing, support, and website data — described below.

What we collect

Account data. Name, email address, and authentication identifiers, received from our sign-in provider (Clerk) when you sign in with a Microsoft work account or an email link. We never see or store passwords.

Workspace metadata. The audit-management content described above, scoped to your organization and isolated by database row-level security.

Microsoft integration tokens. If a user connects Microsoft 365, we store that user's OAuth refresh token, encrypted with AES-256-GCM, so the Service can act as that user (and only as that user) when they link files or run folder automation. Disconnecting deletes the token.

Billing data. Subscriptions are sold by our merchant of record, Paddle, which collects and processes payment details under its own privacy policy. We receive only what we need to operate your plan: subscription status, plan, and transaction identifiers — never card numbers.

Usage and log data. Standard server logs (IP address, browser type, timestamps, requested URLs) and an in-product activity trail of actions taken in your workspace (who changed what, when), which is part of the product's audit-trail functionality and is append-only.

Communications. Emails you send us (for example to hello@substantively.ai) and in-product notifications settings.

We do not collect data from data brokers, do not use advertising trackers, and do not engage in profiling or automated decision-making with legal effects.

What we deliberately do not collect

  • File content of any kind — evidence, workpapers, documents;
  • Payment card numbers (Paddle holds these);
  • Passwords (authentication is passwordless);
  • Special-category data — the Service is not designed for it, and you should not put it in workspace fields.

How we use data, and on what basis

We use the data above to:

  • provide, secure, and support the Service (performance of our contract with you);
  • operate accounts, billing, and renewals (contract; legal obligations);
  • send transactional email such as invitations, evidence-request notifications, and the optional weekly digest (contract; legitimate interests — digests can be turned off);
  • monitor for, prevent, and investigate abuse, fraud, and security incidents (legitimate interests; legal obligations);
  • improve the Service using aggregated, de-identified statistics (legitimate interests);
  • comply with law and enforce our terms (legal obligations).

We do not sell personal data, share it for cross-context behavioral advertising, or use customer data to train machine-learning models.

Cookies

The Service uses only cookies necessary for it to function: session and authentication cookies set by our sign-in provider, and a preference cookie for your theme. There are no advertising or third-party analytics cookies, so there is no cookie banner — there is nothing to opt out of.

Who we share data with

We share personal data only with the service providers (sub-processors) that host and operate the Service, each bound by data-protection terms:

ProviderPurposeLocation
VercelApplication hostingUnited States
NeonManaged PostgreSQL databaseUnited States
ClerkAuthentication & organization membershipUnited States
PaddleBilling (merchant of record)US / UK
ResendTransactional emailUnited States
Sentry (optional)Error monitoring, when enabledUnited States

Microsoft is not our sub-processor: when the Service talks to Microsoft Graph it is acting inside your tenant, as your signed-in user, under your agreement with Microsoft.

Beyond sub-processors, we disclose personal data only: with your direction or consent; to comply with law or valid legal process (we will notify you where lawful); to protect the rights, safety, or property of Substantively, our customers, or the public; or as part of a merger, acquisition, or asset sale, in which case this policy continues to apply until you are notified otherwise.

Retention

  • Workspace metadata: kept while your organization is active. For 30 days after termination, owners may export it; thereafter we delete it from production within 90 days, with backup copies expiring in the ordinary course (typically within 30 further days). Organization owners can also hard-delete the organization in-product at any time.
  • Microsoft refresh tokens: deleted on disconnect or organization deletion.
  • Account data: kept while your account exists, then deleted on the same schedule.
  • Billing records: retained as required by tax and accounting law (typically 7 years), primarily by Paddle.
  • Server logs: retained for a short rolling window.

Security

Measures include: TLS for all data in transit; encryption at rest for the database; AES-256-GCM application-layer encryption for integration tokens; per-organization isolation enforced by PostgreSQL row-level security policies that the application role cannot bypass; least-privilege database roles; an append-only activity log; passwordless authentication; and CI checks that enforce the no-file-content boundary. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you without undue delay, consistent with applicable law. Details are on our security page.

International transfers

We are a U.S. company and the Service is hosted in the United States. If you use the Service from the EEA, UK, or Switzerland, you are transferring personal data to the U.S.; where we act as your processor, our DPA incorporates Standard Contractual Clauses, and our sub-processors offer equivalent safeguards.

Your rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. You can exercise most of them directly: profile details are editable in-product, exports are available to organization owners, and organization deletion is self-service. For anything else, email hello@substantively.ai; we will verify your request and respond within the time required by law. We do not discriminate against anyone for exercising privacy rights.

If the data concerned lives inside an organization's workspace, we may refer the request to that organization (the controller) and assist it. EEA/UK residents may also lodge a complaint with their supervisory authority. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we collect only the categories described above for the purposes described above.

Children

The Service is for business use and not directed to anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us personal data, contact us and we will delete it.

Changes and contact

We will post any changes here with a new "Last updated" date, and give email or in-product notice of material changes at least 30 days before they take effect. Questions, requests, or complaints: hello@substantively.ai. Postal address available on request.