Privacy Policy

This policy explains what Sorry Not Public collects, why, and what you can do about it. It applies to our website, the membership application, and the platform members use.

Effective September 6, 2026

  1. 1. What we collect
  2. 2. How we use it
  3. 3. AI features
  4. 4. Who can see member data
  5. 5. Service providers
  6. 6. Retention
  7. 7. Security
  8. 8. Your choices and rights
  9. 9. Children and international use
  10. 10. Changes and contact

1. What we collect

Application and contact details: your name, email, company, role, website, and what you write to us.

Account and profile information: name, email, job title, photo, time zone, password (stored only as a salted hash), and security settings such as two-factor authentication.

Member Content you and your team put into a workspace: projects, tasks, contacts and companies, documents, files, quotes, invoices, payments, messages, comments and activity history.

Connected-service data you choose to link: for example Gmail message metadata (subject, addresses, date, a short snippet) for contacts already in your CRM; Stripe account identifiers; Slack channel details; Canva design thumbnails and exports; and API keys you provide, which we store encrypted.

Technical data: log data such as IP address, browser, device, pages visited and timestamps, and cookies needed to keep you signed in and to protect the service.

2. How we use it

To review membership applications and reply to you.

To provide and operate the platform, including features you turn on and services our team performs inside your workspace.

To send transactional email: invitations, login links, notifications, reminders and digests. You can turn most notifications off in your profile.

To keep the platform secure, prevent abuse, and meet legal obligations.

To improve the platform. We look at usage in aggregate; we do not sell personal data and we do not run advertising.

3. AI features

If a workspace turns on the assistant, relevant Member Content (for example deals, tasks, documents and messages) is sent to the AI provider to answer the question asked. If a workspace connects its own AI key, that data goes to the workspace's own provider account under that provider's terms. Otherwise it goes to the provider under our account. We do not use Member Content to train models.

4. Who can see member data

People the workspace owner adds to the workspace, according to the permissions the owner sets. Clients invited to a portal see only what is explicitly shared with them.

Members of the Sorry Not Public team, when working with you inside your workspace or providing support, under confidentiality obligations.

Nothing about a member's work is public. Public pages only exist where you deliberately create them (for example a booking page or intake form).

5. Service providers

We use infrastructure providers to run the platform: hosting and database, file storage, email delivery, and, where you connect them, payment, messaging, design and AI providers. Each processes data only to provide its service and under its own data-processing terms. A current list is available on request.

6. Retention

Applications are kept while under review and for up to two years afterwards so we can consider re-applications and keep records. Account and workspace data are kept while the membership is active. After membership ends, the workspace remains available for export for at least 30 days and is then deleted, except where we must keep records (for example invoices) for legal or accounting reasons. Log data is kept for a limited period for security.

7. Security

Data is encrypted in transit. Passwords are hashed. Credentials for connected services are encrypted at rest. Access inside the platform is scoped to the workspace and the role each person has. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as the law requires.

8. Your choices and rights

You can edit your profile and notification settings at any time, export your workspace data from Settings, disconnect any connected service, and delete your account by contacting us. Depending on where you live, you may have rights to access, correct, delete or restrict the use of your personal data, and to complain to a data-protection authority. Write to us and we will respond within 30 days.

Cookies: we use only the cookies needed to keep you signed in and to protect the service. You can clear them in your browser; you will be signed out.

9. Children and international use

The platform is for businesses and is not directed at children under 16. We operate from the United States; if you use the platform from elsewhere, your data is processed in the United States and in the regions our providers use.

10. Changes and contact

We may update this policy. Material changes will be announced in the platform or by email. Questions or requests: hello@sorrynotpublic.com.