Last Updated: April 19, 2026

Effective Date: April 19, 2026

Privacy Policy

SANICE.AI — operated by SANICE STAR LTD

This Privacy Policy describes how SANICE STAR LTD (trading as SANICE.AI, "SANICE", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you access our platform, website, or services (collectively, the "Services").

This Policy should be read together with our Terms and Conditions. By using the Services, you acknowledge that you have read and understood this Policy.


1. Who We Are and How to Contact Us

SANICE STAR LTD is a company registered in New Zealand, trading as SANICE.AI, providing an intelligence orchestration platform for AI-assisted research, analysis, monitoring, and strategic decision support.

For any privacy-related questions, requests, or concerns:

Email: privacy@sanice.ai

Mail: SANICE STAR LTD — The Data Privacy Team, Christchurch, New Zealand

We aim to respond to privacy requests within 30 days, or within the shorter period required by applicable law in your jurisdiction.

2. Scope of This Policy

This Policy applies to personal information collected through:

  • The SANICE.AI website (sanice.ai and subdomains)
  • Authenticated product surfaces (Glass, Counsel, Pulse, Collective)
  • Account registration, login, and billing flows
  • Transactional and marketing email communications

This Policy does not apply to third-party websites linked from the Services, third-party model providers accessed through integrations, or any data handled directly by a user outside the Services.

3. Information We Collect

3.1 Information You Provide Directly

When you register, use, or pay for the Services, you may provide:

  • Identity data — name, email address, display name, profile preferences
  • Authentication data — password (hashed, never stored in plaintext), OAuth identifiers if you sign in via a third-party provider
  • Billing data — billing name, billing address, payment card details (handled directly by Stripe — SANICE does not store full card numbers), subscription tier, billing history
  • Content data — prompts, chat messages, uploaded files, research briefs, Glass session inputs, Counsel debate questions, Pulse monitor configurations, and any other content you voluntarily submit
  • Communications data — correspondence with our support team, feedback, and bug reports

3.2 Information Collected Automatically

When you interact with the Services, we automatically collect:

  • Technical data — IP address, device type, browser type and version, operating system, screen resolution, referrer URL, and timezone
  • Usage data — pages visited, features used, clicks, session duration, time and date of access, credit consumption events, error events
  • Session data — short-lived authentication tokens, session identifiers, CSRF tokens
  • Log data — server logs capturing request metadata (not content) for security, debugging, and fraud prevention

3.3 Information Generated by the Services

As you use SANICE, the platform generates:

  • Output data — Glass research reports, Counsel verdicts, Pulse alerts, Collective chat responses
  • Derived data — embeddings (vector representations of third-party research content retrieved in response to your queries — see Section 7), usage patterns, credit balance history
  • Inference data — relevance scores, matching results, and other computed signals derived from your inputs

3.4 Information We Do Not Collect

We do not collect:

  • Biometric data
  • Precise geolocation (we approximate only from IP address, never device GPS)
  • Sensitive personal data such as religious beliefs, political opinions, sexual orientation, or trade union membership — unless you voluntarily include such information in your content, in which case it is processed only to fulfill your research request
  • Children's data (see Section 17)

4. How We Use Your Information

We process personal information for the following purposes:

4.1 To Provide the Services

Authenticate users, route requests to appropriate AI models, generate research reports, deliver chat responses, trigger Pulse alerts, run Counsel debates, manage credit balances, and deliver search results.

4.2 To Operate and Improve the Platform

Monitor service health, diagnose errors, analyze aggregate usage patterns, develop new features, optimize performance, and prevent system abuse.

4.3 To Communicate With You

Send transactional emails (welcome emails, receipts, password resets, billing notices, security alerts), respond to support requests, and — only with your explicit consent — send product updates.

4.4 To Process Payments

Process subscription fees, top-up purchases, refunds, and chargebacks through our payment processor (Stripe).

4.5 To Ensure Security and Prevent Fraud

Detect unauthorized access attempts, prevent credential stuffing, identify abusive usage patterns, enforce rate limits, and investigate suspected misuse.

4.6 To Comply with Legal Obligations

Respond to lawful requests from authorities, comply with tax and financial reporting obligations, and enforce our Terms and Conditions.

5. Legal Basis for Processing (GDPR / UK GDPR)

For users located in the European Economic Area (EEA), the United Kingdom, or other jurisdictions with similar laws, the legal bases under which we process personal information are:

  • Performance of a contract — to deliver the Services you have subscribed to or requested
  • Legitimate interests — to secure our platform, prevent fraud, improve our Services, and operate our business, balanced against your rights and freedoms
  • Legal obligation — to comply with applicable laws and regulations
  • Consent — where you have given explicit consent, such as for optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.

6. Zero Data Training — Our Core Commitment

This is the central commitment of SANICE.AI.

6.1 We Do Not Train Our Own Models on Your Content

SANICE STAR LTD does not use your prompts, uploaded files, chat messages, Glass reports, Counsel verdicts, or any other content you submit or generate to train, fine-tune, or improve any foundational AI model operated by SANICE.

6.2 Third-Party AI Providers — Training and Retention

When we send content to third-party AI providers through their paid API services, we configure those services so that customer content is not used to train their foundation models by default. This applies to all four of our current AI model providers (Anthropic, OpenAI, Google, and xAI) under their respective paid API terms.

Some providers may temporarily retain prompts, responses, or limited metadata for abuse monitoring, security investigation, debugging, legal compliance, or optional features under their own policies. Retention periods are for limited periods under each provider's published policy (typically 30 days or less) and may vary by provider, API, and enabled feature. Where available and appropriate, SANICE disables optional storage features and uses the stricter retention settings each provider offers.

We review each provider's data handling terms before integration and monitor material changes (see Section 8.7). Third-party provider terms referenced in this section were last reviewed on April 19, 2026.

6.3 We Do Not Sell Your Data

We do not sell, rent, or lease your personal information or content to any third party for advertising, marketing, or model-training purposes.

6.4 Aggregated and De-Identified Insights

We may derive aggregated, de-identified statistical insights (for example, "X% of Glass reports are about finance topics") for internal product analytics and public reporting. These aggregates cannot be used to identify any individual user and are not personal information.

6.5 What SANICE Does Not Learn From You

To be explicit about what the platform does and does not do with your content:

  • We do not train, fine-tune, or improve any AI model — our own or a third-party's — using your content.
  • We do not read your prompts, chats, or reports for "product improvement" purposes.
  • Our product analytics capture only metadata — which features you used, credit consumption, model routing, error events — never the content of your prompts, chats, or generated reports.
  • Your content is strictly isolated to your own account via Row-Level Security enforced at the database layer.

7. How SANICE Uses Your Content — Embeddings and Semantic Retrieval

SANICE uses a technique called "semantic retrieval" to help produce higher-quality research reports. This section explains exactly how that works and what it means for your data.

7.1 What Is Embedded

During a Glass research session, SANICE fetches content from third-party web sources (news articles, company reports, regulatory filings, academic literature, and similar public sources) in response to your query. That retrieved third-party content is:

  • Split into small chunks (typically 250 to 1,500 words per chunk);
  • Converted into numerical vector representations ("embeddings") using our embedding provider, Voyage AI;
  • Stored in our vector database scoped to your account via Row-Level Security.

When your Glass report is being generated, SANICE performs a vector search within your own session's embeddings to identify the most relevant retrieved content for the analysis.

7.2 Third-Party Source Content Ownership

Retrieved third-party source content remains the property of its respective owners. SANICE processes such content only to provide session-specific retrieval and analysis on your behalf. SANICE claims no ownership over third-party source material.

7.3 What Is Not Embedded

The embeddings described above represent third-party content that SANICE fetched on your behalf. They do not contain your prompt text itself.

Your prompts, chat messages, and final generated reports are stored as plain text in their respective session records (to allow you to view your history on your dashboard). They are strictly isolated via Row-Level Security and are never used to train any AI model, ours or a third-party's.

7.4 Transient Embeddings

In a few limited cases, SANICE generates short-lived embeddings of short query strings or expertise-gap descriptions during a Counsel debate (see Section 18.1). These embeddings are used to match experts for the debate session and are not persisted after the matching step.

7.5 Retention and Deletion

Your embeddings follow the same retention and deletion rules as the source content they represent. Deleting a Glass session deletes the associated embeddings. Deleting your account deletes all embeddings associated with your account.

7.6 Your Responsibility for Submitted Content

You are responsible for ensuring you have the necessary rights to upload, submit, or process any content (including any personal information about third parties) through the Services. If you submit personal information about another person into the Services, you represent that you have the right to do so and that such submission is lawful.

8. Sub-Processors

We work with the following third parties who process personal information on our behalf ("sub-processors"). Each is bound by contractual data protection obligations, and each uses data only to provide its services to SANICE.

8.1 Core Infrastructure

  • Supabase — Database, authentication, and vector storage. Primary data residency: Singapore (AWS ap-southeast-1).
  • Railway — Backend application hosting (USA).
  • Vercel — Frontend application hosting (USA and global edge).
  • Cloudflare — Edge security and Web Application Firewall (WAF). Receives IP addresses and request metadata in transit. Global edge network.

8.2 Billing and Communications

  • Stripe — Payment processing (USA, EU, global depending on payer location). Handles card details directly; SANICE never stores full card numbers.
  • Resend — Transactional email delivery (USA, us-east-1).

8.3 Observability

  • Sentry — Error and exception monitoring (USA).
  • PostHog — Product analytics and usage events (USA).

8.4 AI Model and Embedding Providers

  • Anthropic — Claude model API (USA).
  • OpenAI — GPT model API (USA).
  • Google — Gemini model API (USA / global).
  • xAI — Grok model API (USA).
  • Voyage AI — Embedding model API, used for semantic search and retrieval (USA).

8.5 Third-Party Data Providers

We also integrate with third-party data sources (financial market data providers, academic literature databases, and news aggregators) used solely to ground research reports. No user personal information is transmitted to these providers — they receive only generic, non-user-identifying queries such as stock tickers, company names, or research keywords.

8.6 Sub-Processor Changes

We may add, remove, or replace sub-processors over time. Material changes will be reflected in an updated version of this Policy.

8.7 Provider-Change Safeguard

If a third-party sub-processor materially changes its data handling, retention, or training terms in a way that would weaken SANICE's commitments in this Policy (in particular, our Zero Data Training commitment in Section 6), we will:

  • Update this Policy to reflect the change;
  • Where necessary to maintain our commitments, stop sending customer content to that provider until an acceptable configuration is available; and
  • Notify affected users where the change has a material impact on how their personal information is processed.

9. International Data Transfers

SANICE operates from New Zealand, serves a global user base, and relies on sub-processors in multiple jurisdictions. As a result, your personal information may be transferred to, stored in, and processed in countries outside your country of residence, including:

  • Singapore (primary database residency via Supabase)
  • United States (Railway, Vercel, Stripe, Resend, Sentry, PostHog, Anthropic, OpenAI, Google, xAI, Voyage AI)
  • Global edge network (Cloudflare, Vercel)

Where personal information is transferred from the EEA, UK, or other jurisdictions with international transfer restrictions, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) or equivalent mechanisms as required by the General Data Protection Regulation (GDPR), UK GDPR, or local law.

10. Data Retention

10.1 General Principle

We retain personal information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and operate backups.

10.2 Specific Retention Periods

  • Account data — retained while your account is active. If you delete your account, we remove identifying account data from live production systems within 90 days, subject to legal retention requirements and the backup policy described below.
  • Content data (chat messages, Glass reports, Counsel verdicts, Pulse configurations) — retained indefinitely while your account is active, to support your history and retrieval features. You may delete individual items at any time via the Services.
  • Embeddings — derived from third-party retrieved content. Deletion of the source session or content triggers deletion of the corresponding embeddings from live systems.
  • Billing and tax records — retained for 7 years after the transaction date, as required by New Zealand Inland Revenue and financial reporting law, regardless of account status.
  • Server logs — retained for up to 90 days for security and debugging purposes.
  • Security event logs — retained for up to 12 months for incident response and forensic analysis.

10.3 Backups

Data deleted from live systems may persist in encrypted backups until those backups are purged on their normal lifecycle (typically up to 30 days). Legal holds may extend retention where required by law.

11. Your Rights

Subject to applicable law, you have the following rights over your personal information. You may exercise these rights by emailing privacy@sanice.ai.

11.1 Rights Available to All Users

  • Access — Request a copy of the personal information we hold about you.
  • Correction — Request correction of inaccurate or incomplete information.
  • Deletion — Request deletion of your account and associated personal information, subject to the retention exceptions in Section 10.
  • Export — Request a machine-readable export of your content (prompts, chats, reports).

11.2 Additional Rights under GDPR and UK GDPR

If you are in the EEA or UK, you also have the right to:

  • Restriction of processing — Request that we limit how we process your information in specific circumstances.
  • Data portability — Request that we transfer your information to another service provider where technically feasible.
  • Objection — Object to processing based on legitimate interests, including profiling.
  • Withdrawal of consent — Where processing is based on consent, withdraw that consent at any time.
  • Complaint to a supervisory authority — Lodge a complaint with the data protection authority in your country of residence.

11.3 Additional Rights under CCPA / CPRA

If you are a California resident, you also have the right to:

  • Know what categories of personal information we collect, use, disclose, and sell (we do not sell personal information).
  • Delete personal information subject to applicable exceptions.
  • Correct inaccurate personal information.
  • Opt out of the "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising).
  • Limit the use and disclosure of sensitive personal information.
  • Non-discrimination — We will not deny you Services or provide a different level of service for exercising your rights.

11.4 Compliance with the New Zealand Privacy Act 2020

SANICE STAR LTD is an "agency" under the New Zealand Privacy Act 2020 and operates in accordance with the 13 Information Privacy Principles (IPPs).

  • IPPs 1–11 (collection, storage, access, correction, accuracy, retention, use, and disclosure) — We collect personal information only for lawful purposes, directly from you where practicable, maintain appropriate security safeguards, take reasonable steps to ensure accuracy, respect your rights of access and correction, and use and disclose personal information only for the purposes for which it was collected or a directly related purpose.
  • IPP 12 (cross-border disclosure) — Before transferring personal information outside New Zealand, we ensure the receiving jurisdiction or the recipient provides comparable privacy protection. Each of our sub-processors (listed in Section 8) is bound by a Data Processing Agreement that imposes privacy obligations materially equivalent to those under the New Zealand Privacy Act 2020, including on data security, purpose limitation, onward transfer restrictions, and incident notification.
  • IPP 13 (unique identifiers) — We assign an internal unique identifier (your Supabase user UUID) solely to operate the Services. This identifier is used internally to associate your account with your data, sessions, billing history, and audit records. It is not shared with third parties except where necessary to deliver the Services through sub-processors under Section 8.

You may lodge a privacy complaint with our Privacy Team at privacy@sanice.ai. You also have the right to make a complaint directly to the Office of the Privacy Commissioner of New Zealand.

11.5 Verification

To protect your information, we may verify your identity before acting on a privacy request. We may also decline or limit a request where required or permitted by law.

12. Customer Controls

In addition to the statutory rights described in Section 11, SANICE provides operational controls you can use directly, either through the platform or by contacting us:

  • Export your data — Request a machine-readable export of your prompts, chat history, Glass reports, and Counsel verdicts by emailing privacy@sanice.ai.
  • Delete individual sessions — Delete individual Glass reports, chats, and Pulse monitors via your dashboard at any time.
  • Delete your account — Close your account via account settings or by emailing privacy@sanice.ai. Deletion proceeds as described in Section 10.2.
  • Manage marketing preferences — Update marketing email preferences via your account settings or the unsubscribe link in any marketing email.
  • Request a privacy review — If you believe your personal information is being processed in a way that violates this Policy, request a review by emailing privacy@sanice.ai. Privacy reviews are handled by a human member of our Privacy Team, not automated systems.

13. Security

We maintain technical and organizational safeguards appropriate to the sensitivity of the information we hold. Current controls include:

  • Encryption in transit — All traffic served over HTTPS with modern TLS.
  • Encryption at rest — Database, file storage, and backups are encrypted at rest by our infrastructure providers.
  • Tenant isolation — Database queries are scoped to the authenticated user via Supabase Row-Level Security (RLS), enforced at the Postgres layer.
  • Authentication — Short-lived RS256 JSON Web Tokens (JWTs) verified cryptographically on every request, with automatic refresh rotation. Separate cryptographic keys per purpose (session, CSRF, email verification, API).
  • Secrets management — Application secrets stored in managed secrets infrastructure and are not committed to source control.
  • Edge protection — Cloudflare Web Application Firewall, bot management, rate limiting, and DDoS mitigation at the edge.
  • Access control — Principle of least privilege for staff access to production systems. Administrative access is restricted and logged where supported by our infrastructure.
  • Audit trails — Authentication, billing, and sensitive account actions are logged for security review.
  • Vulnerability management — Dependencies are scanned for known vulnerabilities; critical patches are applied promptly.

13.1 Security Incidents

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the appropriate supervisory authority as soon as practicable. Notification timelines vary by jurisdiction: statutory windows include 72 hours under GDPR and UK GDPR from the time we become aware of the breach, and "as soon as practicable" under the New Zealand Privacy Act 2020 notifiable privacy breach regime.

13.2 Your Responsibilities

You are responsible for keeping your login credentials confidential, using a strong and unique password, and promptly notifying us at privacy@sanice.ai if you suspect unauthorized access to your account.

14. Cookies and Similar Technologies

We use a minimal set of cookies and similar technologies, primarily for essential Service functionality and to understand aggregate usage.

14.1 Types of Cookies We Use

  • Strictly necessary — Authentication tokens, session identifiers, CSRF tokens. These are required for the Services to function and cannot be disabled.
  • Functional — Preferences such as interface theme or language. These can be cleared via your browser.
  • Analytics — Aggregate usage signals via PostHog and Vercel Analytics. We do not use cookies for advertising or cross-site tracking.

14.2 Your Choices

You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent the Services from functioning.

14.3 Do Not Track

The SANICE.AI website does not respond to Do Not Track (DNT) browser signals, as there is no industry consensus on how such signals should be interpreted. We do not track users across third-party websites.

15. Marketing Communications

We only send marketing communications to users who have explicitly opted in. Transactional emails (receipts, billing notices, password resets, security alerts, required product updates) are sent regardless of marketing preferences, as they are necessary for the Services.

You may unsubscribe from marketing emails at any time via the unsubscribe link in any marketing email or by contacting privacy@sanice.ai.

16. Law Enforcement and Emergency Disclosure

SANICE may disclose personal information in response to lawful requests from government, regulatory, or law enforcement authorities, including subpoenas, court orders, warrants, or statutory information requests. We may also disclose information where we reasonably believe disclosure is necessary to prevent serious harm to a person or to prevent or investigate fraud or security incidents.

Where permitted by law and operationally feasible, we:

  • Review requests for legal validity and scope before responding;
  • Narrow disclosures to the minimum information required to comply with the request; and
  • Notify affected users where not prohibited by law.

17. Children's Privacy

The Services are not directed to, and not intended for, children under the age of 18. We do not knowingly collect personal information from children under 18.

If you believe a child under 18 has provided personal information to SANICE, please contact privacy@sanice.ai and we will promptly delete the information and close the associated account.

18. AI-Generated Output and Its Limitations

SANICE's Services generate output produced by AI models. You should be aware:

  • AI systems can make mistakes, omit facts, or produce inaccurate results. Output is for general informational purposes only.
  • Output should not be relied upon for legal, medical, financial, tax, or other regulated professional advice without independent verification.
  • You are responsible for how you use output. See Section 8 of our Terms and Conditions for a full description of output limitations.
  • If you submit personal information about another person into the Services, you represent that you have the right to do so and that such submission is lawful.

18.1 How Counsel "Experts" Work

Counsel summons "experts" to debate your question. These experts are AI-generated persona templates (for example, "CFO with SaaS experience" or "Clinical Trial Methodologist") maintained by SANICE. They are not real individuals, do not represent any real person's professional profile or identity, do not receive or process any user's personal content outside the scope of your own debate session, and no personal information about any real person is used to generate or match them.

Matching an expert to your question involves a short-lived embedding of the expertise-gap description; this embedding is used only for the matching step and is not persisted after the debate.

19. Automated Decision-Making and Profiling

We do not subject you to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect you. AI-assisted output generated through the Services supports your decision-making but does not replace human judgment and is not used by SANICE to make binding decisions about you.

20. Business Transfers

If SANICE STAR LTD is involved in a merger, acquisition, sale of assets, financing, corporate restructuring, or insolvency proceeding, personal information held by SANICE may be transferred to the acquiring or successor entity as part of that transaction. Any such transfer will remain subject to this Policy or to equivalent privacy protections, and — where required by law — we will provide notice of the transfer to affected users.

21. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date and — where required by law or where the changes are significant — notify you by email or through an in-product notice.

Continued use of the Services after an update constitutes acceptance of the revised Policy. If you do not agree with an update, you should stop using the Services and may request account deletion as described in Section 11.

22. Contact Us

If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or your personal information:

SANICE STAR LTD — The Data Privacy Team

Email: privacy@sanice.ai

Location: Christchurch, New Zealand

Website: sanice.ai

You also have the right to lodge a complaint with the data protection authority in your country of residence:


© 2026 SANICE STAR LTD (trading as SANICE.AI). All rights reserved.