Last updated: June 2026
This privacy policy explains how sanctor, a product of Sept & Stone, Inc., collects, uses, and protects your information when you use our platform.
Account information. When you create an account, we collect your name, email address, and password. If you provide a phone number for SMS notifications, we collect that as well.
Workspace information. When you create a workspace, we collect the company name, jurisdiction, entity type, and industry you provide during setup.
Billing information. When you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your credit card number, bank account details, or other payment credentials. Stripe's privacy policy governs the handling of your payment information.
Usage information. We collect basic usage data to maintain and improve the service: login timestamps, feature usage patterns, and error logs. This data is associated with your account and is not sold or shared with third parties.
Governance data. Your provisions, documents, classifications, people registries, role assignments, votes, resolutions, and all governance content are stored locally on your device. This data does not pass through our servers. We cannot access, read, or retrieve your governance data.
AI classification data. When you use the provision builder, your text is sent directly from your browser to Anthropic's API using your own API key. This communication does not pass through sanctor's servers. We do not see, store, or process the content of your provisions during classification.
Built local-first, sanctor stores your data in your browser's local storage (IndexedDB) on your device. The only data stored on our servers is:
Authentication. We use a cloud-hosted authentication service to manage account creation, login, and password recovery.
Billing. We use Stripe to process payments and manage subscriptions.
Notifications. We use third-party services to deliver email and SMS notifications. Notification content includes the minimum information necessary to inform you of a governance action. Full governance details are accessible only within the application.
AI classification. Provision classification uses Anthropic's Claude API. Your API key is stored encrypted in your browser. Calls go directly from your browser to Anthropic. Anthropic's privacy policy and data handling practices govern how your data is processed during classification.
Account credentials are encrypted in transit and at rest. Passwords are hashed and never stored in plain text. API keys are encrypted in your browser's local storage. All communication between your browser and our authentication and billing services uses TLS encryption.
You may access, update, or delete your account information at any time through the Profile section of the application. You may export your governance data at any time through the Settings section. You may delete your account by contacting support@sanctor.io.
If you delete your account, your account credentials and subscription data are removed from our servers. Your data, stored locally on your device, remains on your device until you clear it.
Account and billing data is retained for as long as your account is active. If you cancel your subscription, your account remains accessible in a read-only state for 90 days, after which account data is deleted from our servers. Data on your device is not affected by account cancellation.
The platform is for business use. We do not knowingly collect information from anyone under the age of 18.
We may update this policy to reflect changes in our practices or applicable law. If we make material changes, we will notify you by email or through the application. The "last updated" date at the top of this document indicates when it was last revised.
If you have questions about this privacy policy or how your data is handled, contact us at privacy@sanctor.io.