Adequacy

How we handle data

Privacy policy

Last updated 4 October 2026

1. Who we are

This policy explains how Adequacy (“we”) processes personal data when you use the website, chat, REST API or MCP server. We built a data-protection product, so we hold ourselves to the standards we help you meet: we collect the minimum needed to run the Service, and nothing is sold or used for advertising.

2. What we collect

  • Account data — name, email address and authentication state, managed by our sign-in provider Clerk.
  • API keys and usage records — a hashed key, and per-request metadata: channel (chat, API or MCP), question length and token counts with a timestamp. We do not store the text of your questions in the usage log.
  • Queries while being answered — your question is processed in memory and passed to our AI subprocessors (below) to retrieve passages and generate the cited answer.
  • Billing data — if a paid plan is active, subscription status and payment details are handled by our billing provider; full card numbers never reach us.

3. Why, and on what legal basis

  • Providing the Service you asked for — performance of a contract.
  • Quotas, abuse prevention and security — our legitimate interests.
  • Billing and tax records — legal obligation and contract.

We do not use your queries or account data to train AI models, nor permit our subprocessors to.

4. Subprocessors

We share data only with the processors needed to run the Service:

  • Clerk — authentication and account management.
  • Anthropic — generates the cited answer to your question.
  • Voyage AI — converts text into search embeddings.
  • Railway — hosting infrastructure (US East).
  • Stripe (via Clerk Billing) — payments, when a paid plan is active.

Each is bound by a data-processing agreement. Where data leaves your jurisdiction (hosting is in the United States), transfers rely on the providers’ standard contractual clauses or applicable adequacy frameworks — the same mechanisms our transfer matrix documents.

5. Retention

  • Usage metadata — kept while your account is active; the dashboard shows a 30-day window.
  • Account data — until you delete your account with Clerk.
  • Question text — not retained after the answer is returned.

6. Your rights

Depending on where you live (GDPR, UK GDPR, DPDP Act, PDPO, Privacy Act 1988, Privacy Act 2020), you can ask for access, correction, deletion or a copy of your personal data, object to or restrict processing, and complain to your supervisory authority. Write to us and we will respond within the statutory deadline.

7. Cookies

We use strictly necessary cookies only: Clerk’s session cookies that keep you signed in and protect against request forgery. They are essential for the Service to function and are exempt from consent requirements. We set no analytics, advertising or cross-site tracking cookies. Your browser’s local storage holds only interface preferences (for example, dismissing the cookie notice).

8. Contact

Privacy questions and rights requests: contact details are available from the dashboard. Material changes to this policy will be announced on this page with an updated date.