Skip to main content

Legal & transparency

Privacy notice

This notice explains what we collect, why we collect it, and what you can do about it. Browsing the public repository does not require an account.

Before you read this

Effective date
14 August 2026
Last updated
11 August 2026

Privacy notice

What we collect

  • Account data: name, email address, organisation and role, from registration or a workspace invitation.
  • Workspace content: the opportunities, use cases, scores, portfolios, roadmaps, benefits, comments and reports you create, plus files you upload.
  • Product events: which surfaces you use, exports you generate, AI requests you make and their outcome. These power fair-use metering, the audit trail and aggregate product analytics.
  • Support and feedback: the content of feature requests, bug reports and support messages you send, so we can respond and track them to resolution.
  • Technical data: IP address, browser and device information present in ordinary web requests and security logs.

Why we process it

  • To operate the product for you and your workspace.
  • To enforce entitlements and published fair-use limits.
  • To maintain an append-only audit trail of governance-relevant actions such as publishing, exporting, handoffs and membership changes.
  • To detect and stop abuse, credential misuse and cross-workspace access attempts.
  • To improve the product using aggregate, de-identified usage patterns.
  • To reply to you when you contact support.

Analytics and cookies

We do not run third-party advertising trackers and we do not sell personal data. Public browsing is not gated behind a consent banner because it does not set advertising or cross-site tracking cookies.

  • Strictly necessary cookies and local storage: your sign-in session, workspace selection and interface preferences. These are required for a signed-in session to work.
  • First-party product analytics: usage events recorded in our own database and tied to your account so admins can see workspace activity and we can see which surfaces are used. They are not shared with advertising networks.
  • You can clear this storage in your browser at any time; doing so signs you out.

Public and private content

  • The curated repository is public and indexable by search engines.
  • Everything inside your workspace is private by default and isolated by row-level security in the database, not only in the interface.
  • Content becomes visible outside your workspace only when you act: submitting a use case for publication, sharing a report link, inviting someone, running a workshop or approving a suite handoff.
  • Share links can be revoked. Revoking a link stops further access through it.

Who else processes your data

We use a small number of infrastructure providers to run the service: managed cloud hosting and database, transactional email, and AI model providers for AI features only. Providers act on our instructions. The AI notice lists what is sent when you invoke an AI feature.

How long we keep it

  • Workspace content: until you delete it or close the workspace.
  • Audit events: retained as an append-only record for governance purposes; they are not editable, including by us through the product.
  • Product and security events: retained for a rolling operational window, then aggregated.
  • Support conversations: retained while the request is open and for a reasonable period afterwards for continuity.

Your choices

You can access, export, correct or delete your content, and ask us to delete your account. The data export and deletion page explains exactly how, and what an audit trail means for deletion.

Security posture — stated plainly

We apply workspace-scoped row-level security, server-side authorisation on downloads and exports, signed URLs with short lifetimes, upload type and size limits, rate limits on AI endpoints, and alerting on repeated denied access attempts. Provider secrets are never present in browser code or public configuration.

We do not claim any certification, audit outcome or regulatory compliance status, and we do not promise that a breach cannot occur. Report a suspected vulnerability to the security contact below and we will investigate.

Contact

Privacy questions: privacy@usecasesx.ai. Product and support questions: support@usecasesx.ai. If you are in a jurisdiction with a statutory data protection authority, you may also complain to it.

Related pages