Skip to content
Substrate
HomeHow it worksPricingMemory quality
Login / Sign up

Legal

Privacy Notice

How Sightline Technologies Inc. handles personal data for the Substrate website, hosted product accounts and services.

Last updatedSeptember 24, 2026

On this page

1. Scope2. Our role3. Data we collect4. Data in the adaptive application5. AI processing6. Gmail and Google user data7. Sources of data8. How we use data9. Legal bases10. Service providers and other disclosures11. Analytics12. Retention13. Security14. Your choices and privacy rights15. International data transfers16. Children17. Changes to this notice18. Contact us

1. Scope

This Privacy Notice applies when you visit the Substrate marketing site, communicate with us, create an account, use the hosted product, or otherwise interact with a service that links to this notice (collectively, the “Services”).

“Substrate,” “we,” “us,” and “our” refer to Sightline Technologies Inc.. This notice does not cover third-party products, websites, or services that have their own privacy notices. An order form, data processing addendum, or other written agreement may supplement this notice. If those terms conflict, the applicable signed agreement controls for that engagement.

Hosted serviceAvailable sources, features, and data flows can differ by plan and configuration. You choose which supported sources to connect.

2. Our role

We generally decide why and how personal data is handled for site visits, communications, accounts, and service administration.

When an organization authorizes us to process source data, it generally sets the purposes and scope; we provide the agreed service. It is responsible for its instructions, permissions, notices, and lawful basis. Applicable agreements address jurisdiction-specific roles.

For hosted accounts, the customer chooses supported sources and remains responsible for the data it connects and the individuals represented in it.

3. Data we collect

Depending on how you interact with the Services, we may handle:

  • Contact and professional data, such as name, work email, employer, role, and information included in a message or meeting request.
  • Account and relationship data, such as your plan, use case, company context, source availability, onboarding notes, billing status, and support history.
  • Account and access data, such as login identifiers, authentication events, plan, and account associations.
  • Website and device data, such as pages viewed, page-entry and page-exit events, approximate timestamps, browser or device information, referring information, and network metadata ordinarily transmitted in a web request.
  • Communications data, including emails, meeting notes, feedback, requests, and support records.
  • Connected source and application data, described below, when an account holder deliberately connects or provides it.

Please do not send credentials, private keys, authentication tokens, or sensitive datasets through ordinary email. Use only the product connection methods provided for that purpose.

4. Data in the adaptive application

Substrate transforms authorized signals into qualified, source-aware context. Depending on your configuration, application data may concern people, organizations, roles, communications, meetings, commitments, preferences, projects, products, accounts, support matters, and changes over time.

The adaptive application may create and maintain several kinds of records:

  • Source records and references used to establish where information came from, subject to the agreed ingestion and storage design.
  • Canonical entity records that associate authorized information with a person, organization, project, product, or other durable entity.
  • Qualified memory that can distinguish observed facts, explicit directions, hypotheses, uncertainty, conflict, current context, and superseded or historical context.
  • Derived context and outputs, such as summaries, retrieved context, suggested preparation, or a managed founder briefing.
  • Corrections, review records, and provenance used to inspect, challenge, update, or trace application context.
  • Operational records such as processing status, errors, configuration, access events, and quality-review notes.

Derived context is probabilistic and may be incomplete or wrong. It is not psychological fact or a complete profile. Customers must review and use outputs lawfully and appropriately.

5. AI processing

We use OpenAI ChatGPT models with training disabled. The service sends excerpts of the content you connect or upload to these models to extract facts, work out which person, organization, or project they concern, and write your Wiki pages. Model output is checked before it is stored, and the model never chooses record identifiers or which account data belongs to.

We do not use your content to train generalized AI models.

6. Gmail and Google user data

Substrate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Access. Gmail access is read-only. Nothing is imported until you choose how much mail to import: the last 90 days, only conversations you took part in (threads where you sent a message, from the last 12 months), full history, or only new mail from now on. You can widen that choice later; widening never re-imports mail that is already there.
  • What we keep. A copy of each imported message (sender, recipients, subject, date, labels, and body text) and the facts and Wiki pages derived from it. Spam and Trash are never imported. Attachments are not imported. By default, newsletters and other automated mail are stored but set aside from AI processing.
  • How it is used. Only to provide the features you use: your memory, your Wiki pages, search by you and by agents you connect, and pages you choose to share. We do not use Gmail data for advertising, do not sell it, and do not use it to train generalized AI models.
  • Who processes it. We access Gmail in two ways: through Composio, which holds the Google authorization and relays messages to us, and directly through the Google Gmail API with our own authorization. Excerpts are processed by OpenAI as described in Section 5. We do not otherwise transfer Gmail data except as required by law, for security, or with your permission.
  • Human access. Our staff do not read your mail except to provide support you ask for, when necessary for security, or when law requires it.
  • Disconnecting. Disconnecting Gmail stops access and deletes the stored authorization. Messages already imported stay in your account; see Section 12 for retention and deletion. You can also revoke access in your Google Account permissions.

7. Sources of data

We may receive data:

  • directly from you when you browse, create an account, email us, schedule a meeting, provide feedback, or use the service;
  • from your organization and its authorized administrators or users;
  • from third-party services or data sources deliberately connected to an account, which may include communications, calendar, CRM, support, documents, work systems, or product-usage sources where supported;
  • from service providers that help us operate the website and service; and
  • from the Services themselves through events, derived context, corrections, and operational records.

Sources vary by deployment; listing a category does not mean every connector is available or collected from every participant.

8. How we use data

We use personal data as reasonably necessary to:

  • operate, secure, troubleshoot, and improve the website and Services;
  • administer accounts and manage prospective and current customer relationships;
  • configure and deliver the service, including ingestion, entity resolution, memory qualification, bounded retrieval, briefings, and other agreed outputs;
  • maintain provenance, enable review and correction, and evaluate memory quality;
  • provide support and send operational or relationship communications;
  • understand website usage and the effectiveness of our content;
  • protect users, organizations, the Services, and our rights; prevent misuse; and comply with law;
  • enforce agreements and establish, exercise, or defend legal claims; and
  • perform another purpose disclosed when data is collected or authorized by the relevant organization or individual.

We do not use organizational source data to expand a different customer’s memory. Any use of customer data to improve generalized systems, models, or evaluation methods must follow the applicable agreement and approved data boundary; this point must be stated expressly in customer contracting.

9. Legal bases

Where law requires a basis, we rely as appropriate on contract performance or requested pre-contract steps; legitimate interests in operating, securing, evaluating, and improving the Services and managing relationships; consent; and legal obligations or protection of legal rights.

For legitimate interests, we consider purpose, necessity, and effects on people. Consent may be withdrawn prospectively without affecting prior lawful processing.

10. Service providers and other disclosures

We may disclose data to providers that process it for us under instructions, contractual restrictions, and security obligations appropriate to their role. Current website and hosted-service providers include:

ProviderCurrent roleData potentially involved
Microsoft AzureHosting, database, and file storage for the Substrate app.Account data, connected and uploaded content, memory, Wiki pages, and operational logs.
OpenAIAI models that extract facts and write Wiki pages, with training disabled; see Section 5.Excerpts of connected and uploaded content.
ComposioOne of two Gmail connection paths (the other is direct Google API access): holds the Google authorization and relays Gmail messages; see Section 6.Gmail authorization and the messages you choose to import.
ClerkSign-in and account authentication for the app.Name, email address, login identifiers, and authentication events.
StripeSubscription billing and payment processing. We do not receive full card numbers.Email address, billing details, payment method, and subscription status.
NeonMarketing-site database for early-access applications.Submitted application records and related metadata.
ResendEmail delivery for applications, share invitations, and feedback reports.Email address, message content, delivery status, and related communication metadata.
PostHogProduct analytics for the marketing site and the app, only when configured with an active key and host.Page-view, page-leave, explicitly named interaction and submission events, error events, and associated technical metadata; see Section 11.
GoogleGoogle Analytics 4 marketing-site analytics. Google processes analytics data for us as a service provider and processor.Usage, device, referral, and approximate-location data, plus cookie identifiers; see Section 11.

We may also disclose data:

  • to professional advisers and contractors who need it to support our business and are bound by appropriate duties;
  • to the account holder and its designated users within the account scope;
  • to people you choose to share Wiki pages with, including anyone you give a share link (recipients must sign in);
  • when we reasonably believe disclosure is required by law, valid legal process, or to protect rights, safety, and service integrity;
  • in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate safeguards; or
  • at your direction or with appropriate authorization.

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising as those terms are defined under applicable United States state privacy laws. We do not use organizational source data or authorized memory content to train generalized models.

11. Analytics

Site code initializes PostHog only when a public key and host are configured. When enabled, it records $pageview, $pageleave,cta_clicked, mobile_menu_toggled,contact_route_clicked, application_submitted, and client-side error events. It also records autocapture events, which are generic interactions such as clicks on links and buttons. Form contents, applicant emails, and internal application IDs are not attached. Session recording is disabled, so we do not replay your screen. Analytics runs only on the production site; local, preview, and /lab environments are excluded.

To recognize a repeat visit and to measure how many pages a visit covers, PostHog stores a randomly generated analytics identifier in a first-party cookie and in browser local storage on this domain. A person profile is created for each visitor so that the first referring source of a visit can be attributed. If you sign in to the Substrate app, the same PostHog project links that profile to your account identifier and email address, so we can see which visit led to sign-up. In the app, analytics events carry identifiers, counts, and durations only, never memory content, page text, search text, or email bodies. We do not sell this data or use it for cross-context behavioral advertising.

To remove the identifier, clear cookies and site data for this domain in your browser. Browser "Do Not Track" and global privacy control signals are respected where the browser sends them. PostHog and network infrastructure may also process ordinary request metadata. Requests use a first-party path on this domain rather than going directly to PostHog.

Except on /lab, we also use Google Analytics 4 (“GA4”) to understand use of the marketing site. GA4 records information such as pages viewed, interactions, referring pages and campaigns, approximate timestamps, browser and operating-system details, device type, language, screen information, and approximate location. Google receives the IP address as part of the web request and uses it to derive approximate location; GA4 does not log or store individual IP addresses. GA4 sets cookies, including _ga and _ga_*, to distinguish visits and maintain session state. These cookies generally expire after up to two years unless you delete them sooner.

Google LLC provides GA4 and processes this analytics data for us as our service provider and processor under the Google Analytics terms. User-level event data is retained for the period configured in our GA4 property (GA4 supports two-month and 14-month settings); aggregated reports may remain available longer. You can use the Google Analytics Opt-out Browser Add-on and review the Google Privacy Policy.

12. Retention

We retain data only as reasonably necessary for this notice, applicable agreements, legal obligations, disputes, security, and enforcement. Duration depends on data type, source configuration, relationship status, law, and whether we hold it for an organization.

Account and inquiry records are kept while needed to provide the service, communicate, and maintain a reasonable relationship record, then deleted or irreversibly anonymized when no longer reasonably necessary, subject to legal obligations. Memory content (copies of connected and uploaded sources, the facts derived from them, and Wiki pages) is kept for the life of the account. Closing an account stops all access immediately, but its memory content is currently retained after closure. Self-service deletion is not yet available; until it is, email pavel@trysubstrate.co to request deletion and we will respond within 30 days. Operational and security logs are kept up to 12 months. Aggregated, de-identified analytics not linkable to an individual may be kept indefinitely.

Deletion from active systems may not immediately remove data from security, continuity, or disaster-recovery backups. We isolate or allow backup copies to expire according to applicable procedures and agreements, unless preservation is legally required.

13. Security

We use administrative, technical, and organizational measures intended to protect data in light of its nature and the current service boundary. No service or transmission method can be guaranteed completely secure. Product design goals such as source-aware memory, bounded retrieval, and scope separation are not certifications or guarantees of security, privacy, or compliance.

If you believe you have found a vulnerability, do not include personal data or exploit a system beyond what is necessary to demonstrate the issue. Report it to pavel@trysubstrate.co. We will acknowledge a good-faith report and will not pursue action against research that follows this notice.

14. Your choices and privacy rights

Depending on law and location, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; appeal a decision; or complain to a regulator. Rights may require verification and have exceptions.

For organization-controlled data, ask that organization first; we will assist as required by agreement and law. For data we control, use Section 18. We may verify identity, authority, and the data involved.

You may decline optional marketing messages using the method provided in the message. We may still send service, security, legal, or relationship messages that are not promotional.

15. International data transfers

We and our providers may process data in countries other than the country in which it was collected. Those countries may have different data-protection laws. Where required, we use an applicable transfer mechanism and supplementary measures appropriate to the transfer, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply.

16. Children

The Services are designed for business and professional use, not for children. You must be at least 18 years of age to use the Services. We do not knowingly collect personal data from children or invite them to apply for or use the Services. If you believe a child has provided data to us, contact us and we will delete it.

17. Changes to this notice

We may update this notice as the website, service, providers, or legal requirements change. We will post the revised notice and update the “Last updated” date. If required, we will provide additional notice or request consent before a material change takes effect.

18. Contact us

Questions or requests concerning this notice may be directed to pavel@trysubstrate.co.

Sightline Technologies Inc.
Security reports: pavel@trysubstrate.co
Legal notices: pavel@trysubstrate.co

Substrate

Company context for you and your agents.

By Sightline Technologies Inc.

Product

HomeHow it worksPricingMemory quality
Login / Sign upNow in open beta

Explore

FAQSecurityReliability

Company

AboutContactPrivacyTerms

© 2026 Sightline Technologies Inc.

SecurityReliabilityMemory quality