Privacy Policy

Last updated June 25, 2026

Overview

SignalStory (“we”, “us”) helps companies turn internal signals into thought-leadership content. This policy explains what we collect, how we use it, and the choices you have.

Information we collect

  • Account data: your email, name, and organization details, managed through our authentication provider.
  • Content you provide: signals, founder/brand context, company knowledge documents, and any text you submit for processing.
  • Company knowledge store: documents and URLs you add to the knowledge base (case studies, changelogs, transcripts, posts) are stored, chunked, and embedded so the pipeline can cite them. These may contain your intellectual property or personal data about your customers, so only submit what you have the right to store. Knowledge documents are retained until you delete them from the Knowledge page or purge your organization.
  • Auto-ingested events: if you connect an integration (Pipedrive, Attio, Linear, GitHub, or a generic webhook), the events those tools send us become signals in your workspace.
  • Usage & billing data: pipeline runs, costs, and subscription status needed to operate and bill the service.

How we use it

We use your data to run the content pipeline, provide and improve the service, enforce usage limits, process payments, and communicate with you (e.g. “content ready” notifications). We do not sell your personal data.

Sub-processors

We share data with the following providers strictly to operate the service; each processes data only as needed to provide its function:

  • Supabase — database, authentication, file storage
  • OpenAI / Anthropic — LLM providers that process your signals, context, and knowledge excerpts to generate content and embeddings
  • Vercel — application hosting
  • Inngest — durable job queue for pipeline runs
  • Stripe — payment processing
  • Resend — transactional email
  • Upstash — rate-limit store
  • Sentry — error monitoring
  • LinkedIn — only if you connect it, to publish posts you schedule

Retention & your rights (GDPR/CCPA)

We keep your data while your account is active. Deleted signals go to your workspace Trash before permanent removal; knowledge documents are removed immediately when you delete them. You can exercise your data rights self-serve:

  • Access / portability: export your entire organization as JSON from Settings (or GET /api/account).
  • Erasure: permanently delete your organization and all of its data (signals, assets, context, knowledge store, connections) from Settings (or DELETE /api/account). Deletion cascades to every child record.

For anything else, contact us at the address below.

Security

Connection secrets are encrypted at rest, access is scoped per organization, and transport is encrypted in transit. No method of storage or transmission is perfectly secure, but we work to protect your data.

Contact

Questions about this policy? Email privacy@signalstory.app.