Skip to main content

Privacy Policy

Last updated: 2026-06-16

This Privacy Policy explains how Innovedge Labs Inc. ("Innovedge Labs", "we", "us") collects, uses, and shares information when you use Engrama (the "Service") at engrama.ai or visit our website.

1. Our role

For the documents and related metadata stored in a workspace ("Customer Content"), we process data on behalf of the customer organization that controls that workspace. That organization's administrators decide who can access the content and how long it is kept. If you have questions about Customer Content in a workspace, contact your organization first.

For account, usage, and billing information, Innovedge Labs is the organization responsible for the processing described in this policy.

2. Information we collect

We collect the following categories of information:

  • Account information: your name, email address, authentication credentials (stored as secure hashes by our authentication provider), language preference, and your workspace memberships and roles.
  • Customer Content: documents you upload or import from connected cloud storage, and the metadata your organization creates around them (assets, compliance cases, validity periods, and links between them).
  • Usage information: product analytics events (such as pages visited and features used), browser and device type, and approximate region derived from your IP address. We design our analytics events to exclude free text, document names, and email addresses.
  • Audit and log data: security-relevant actions (file access, sharing, permission and role changes, deletions) are recorded in an audit log, along with server logs needed to operate and secure the Service.
  • Payment information: payments are handled by our payment processor, Stripe. We receive billing status and limited card metadata; we never store full card numbers.
  • Cloud integration credentials: if you connect a cloud storage provider, we store the access credentials in encrypted form and access only the files and folders you select.
  • Communications: messages you send us, such as support requests.

3. How we use information

We use the information we collect to:

  • provide, operate, and secure the Service, including tenant isolation, access control, and audit trails;
  • process documents with AI as described in the next section;
  • manage subscriptions and billing;
  • send transactional emails (such as account confirmations and security notifications) and respond to support requests;
  • understand product usage in aggregate and improve the Service;
  • comply with legal obligations and enforce our Terms of Service.

4. AI processing of documents

When your organization uploads or imports documents, the Service processes them to extract text and structure, classify them into your workspace's asset graph, generate embeddings that power semantic search, and answer chat questions with citations to the source documents.

To do this, document content is sent over encrypted connections to our AI service providers, Anthropic and OpenAI, through their business APIs. These providers are contractually restricted from using your content to train their models. We do not use Customer Content to train AI models of our own.

We do not sell personal information, and we do not use your information for third-party advertising.

5. Service providers and disclosure

We share information with service providers that process it on our behalf, under contracts that restrict their use of it:

  • Supabase: database, authentication, and file storage.
  • Vercel: application hosting and delivery.
  • Amazon Web Services (AWS): asynchronous document-processing infrastructure.
  • Stripe: payment processing.
  • PostHog: product analytics, hosted in the European Union (Frankfurt).
  • Sentry: error monitoring.
  • Resend: transactional email delivery.
  • Anthropic: AI document understanding and chat.
  • OpenAI: text embeddings for search and retrieval.
  • Google, Microsoft, or Dropbox: only if you connect the corresponding cloud-storage integration, and only to read the files you select.

6. Other disclosures

We may also disclose information where required by law or legal process, to protect the rights, safety, and security of Engrama, our customers, or others, in connection with a merger, acquisition, or sale of assets (with notice to affected customers), or at the direction of your organization or with your consent.

7. Cookies and analytics

We use essential cookies (httpOnly session cookies) to keep you signed in and protect against request forgery. We do not use third-party advertising cookies.

Our product analytics are configured privacy-first: data is hosted in the EU, users are identified by an internal ID rather than name or email, event properties exclude document content and names, and session replay, used to diagnose usability issues, masks all text and input fields and excludes document-viewing surfaces entirely.

8. Data security

The Service is built security-first for regulated documents: all data access from the application goes through server-side APIs (browsers never query the database directly), tenant isolation is enforced at the database row level, files are delivered only through short-lived signed URLs issued after access checks, data is encrypted in transit (TLS) and at rest by our infrastructure providers, and security-sensitive actions are audit-logged.

We are actively working toward SOC 2 alignment as part of our security program. We are not yet certified and will not claim certification until it has been achieved.

9. Data retention

We retain information as follows:

  • Customer Content: for as long as the workspace is active or until your organization deletes it. After account termination, content is available for export for 30 days and is then deleted within a commercially reasonable period.
  • Account information: for the life of your account, plus a limited grace period after deletion.
  • Audit logs: at least one year, to support security review.
  • Error-monitoring events: approximately 90 days.
  • Backups: deleted data may persist in encrypted backups for a limited period before being aged out.

10. International data transfers

Your Customer Content and account data are stored and processed primarily in Canada, in the AWS Canada Central region near Montreal, where our database, authentication, file storage, and ingestion infrastructure are hosted. Certain sub-processors operate elsewhere: in the United States (for example, AI document processing, error monitoring, email delivery, and payment processing) and in the European Union (product analytics, hosted in Frankfurt). Where personal information is transferred across borders, we rely on our providers' data processing agreements, including standard contractual clauses where required.

11. Your rights

Depending on where you live, you may have rights under applicable privacy law (such as PIPEDA in Canada or the GDPR in the European Economic Area and the United Kingdom) to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority.

To exercise these rights for your account information, contact us at info@innovedgelabs.com. For Customer Content controlled by your organization, please direct your request to your workspace administrator; we support our customers in fulfilling such requests.

12. Children

The Service is a business tool and is not directed to individuals under 18. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and revise the "Last updated" date. If a change is material, we will provide reasonable advance notice, for example by email or in-app notice.

This policy may be made available in languages other than English for convenience; in the event of any discrepancy, the English version controls.

14. Contact

Innovedge Labs Inc. Privacy questions and requests can be sent to info@innovedgelabs.com.