# Privacy Policy

Your privacy is critically important to us. This policy explains how we collect, use, protect, and share your personal information.

Canonical page: https://gnosari.com/privacy

## What this policy covers

- Introduction
- Information We Collect
- How We Use Your Information
- Data Sharing and Disclosure
- Data Security
- Data Retention
- Your Privacy Rights
- International Data Transfers
- Children's Privacy
- Third-Party Links and Services
- Cookies and Tracking Technologies
- California Privacy Rights (CCPA)
- GDPR Compliance (European Users)
- Changes to This Privacy Policy
- Contact Us

## Questions about privacy at Gnosari

### Where does Gnosari store my data?

Gnosari stores your account data and the conversations your agents collect with cloud hosting providers under contract to Neomanex, the company that operates Gnosari and acts as data controller. Data in transit is encrypted with TLS and sensitive data at rest is encrypted. Transfers outside the European Economic Area rely on EU Standard Contractual Clauses or adequacy decisions, as the policy above sets out.

### Who owns the information my agents collect?

You do. The conversations a Gnosari agent holds on your behalf, and the records built from them, are your content. Gnosari processes them only to run the service you configured: storing records, sending notifications and delivering webhooks. You can export every record as CSV and delete a conversation and its record from your dashboard at any time.

### Which third parties process data for Gnosari?

Gnosari uses cloud hosting providers for storage and computing, Stripe for payments, AI model providers such as OpenAI and Anthropic to run the conversations, analytics services for usage patterns, and email providers for transactional messages. Each processes only what its role requires under contract. The full list and purposes are in the Data Sharing section of this policy.

### How long does Gnosari keep data, and can I delete it?

Gnosari keeps account data while your account is active and for a limited period after closure, transaction records for at least seven years for tax law, individual usage data for 24 months, and backups for up to 90 days. You can delete conversations yourself and request deletion of your personal information at dpo{'@'}neomanex.com; requests are answered within 30 days.

### Is Gnosari GDPR compliant, and how do I exercise my rights?

Gnosari operates under the GDPR for users in the European Economic Area and honours access, rectification, erasure, restriction, portability and objection rights, plus the CCPA rights of California residents. Neomanex is the data controller. Write to dpo{'@'}neomanex.com; identity is verified before a request is processed and a reply arrives within 30 days.

## In short

Gnosari privacy policy covering data collection, cookies, security, and your rights. GDPR and CCPA compliant. Learn how we protect your information.

## Where the full text lives

The complete privacy policy is published at https://gnosari.com/privacy. That page is the authoritative version; this file indexes it.

## Contact

Questions about this privacy policy: hello@gnosari.com
