Privacy Policy

Your data, your control.

Last updated: 29 September 2026

1. Who we are

This privacy policy applies to Ergora Ltd, a company registered in England & Wales, trading as Ergora. We operate the marketing site at ergora.app, the product portal at ergora.cloud, and the cold-outreach domain try-ergora.com. For the purposes of UK GDPR and the Data Protection Act 2018 we are the data controller for personal data we process about our customers, prospects and website visitors.

You can contact us about anything in this policy, including to exercise your rights, at ops@ergora.cloud. Our data protection contact is reachable at the same address.

2. What data we collect, and why

Account information

When you create an account we collect your name, email address, and (where set) a password hash. If you sign in via a social provider we receive your name, email and profile photo from that provider. We use this to authenticate you, contact you about the account, and personalise the experience.

Business and project data

You may add your company name, website, industry, brand assets, and connect third-party integrations (Shopify, Google, Meta, HubSpot, LinkedIn, Xero and others). When you do, we store the resulting access tokens encrypted and use them only to retrieve data on your behalf within the scope you approved.

Data from your Google account

Google is connected one feature at a time, and Google asks you to approve each one separately. We only request the access that feature needs:

  • Google Search Console (read only): search queries, clicks, impressions, average positions and index status for the sites you have verified in Search Console. We use it to answer your questions about search performance, suggest SEO fixes, and track your own site’s rankings in the Rank Tracker.
  • Google Analytics (read only): traffic and conversion reports for your properties, for dashboards, answers and forecasts.
  • Google Business Profile: your business locations, reviews and listing performance.
  • Google Ads: campaign, spend and keyword performance, for reporting and budget advice.
  • Gmail (read only, only if you turn on the Smart Inbox): the messages in your inbox, so the Smart Inbox can sort, prioritise and summarise them for you.
  • Google Calendar (events only): when someone books a meeting with you, we add the event to your calendar with a Google Meet link. We do not read your other events.

Most Google data is fetched live when you ask for it and is not stored. We keep only what a feature needs to work: monthly traffic and advertising totals for forecasts, keyword positions in the Rank Tracker and, if you use the Smart Inbox, the emails it has synced. Access tokens are encrypted at rest. When you ask a question that needs this data, the relevant part is sent to the AI model that writes the answer, only to produce that answer. That model is always Google’s Gemini on Google Cloud or Anthropic’s Claude, and neither provider trains its models on the data we send.

We do not sell Google user data, use it for advertising, or use it to train or improve AI or machine learning models. Nobody at Ergora reads it unless you ask us to for support, or it is needed for security or to comply with the law. You can disconnect Google at any time in Settings, Integrations, which deletes the stored tokens.

Ergora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Content you provide to the AI

We process the prompts, files, voice notes, meeting recordings and other content you submit so the AI can respond. Voice and meeting audio is sent to Google Cloud for transcription and is not retained beyond what is needed to produce the transcript and downstream summaries you see in the product.

Generated content and memory

The product builds personalised memory layers (your personal seat context and your organisation’s shared company memory) from your interactions. These memories belong to your workspace, are not shared across customers, and can be cleared by you at any time.

Usage and billing data

We collect token consumption, image generation counts, feature usage, IP address, browser, device, session timestamps and similar technical data to operate the platform, enforce plan limits, prevent abuse and improve the Service. Stripe holds your payment-method details. We never see full card numbers.

Analytics and advertising cookies

If you choose “Accept all” in our cookie banner, on ergora.app or in the portal, Google Analytics 4 sets cookies that record usage patterns, and we enable Google Signals and Google’s advertising cookies so that Google can show you Ergora ads on other websites based on your visit. Choose “Essential only” and none of this loads. The full list, and how to change your mind, is in our Cookie Policy.

3. Lawful bases

We process personal data on the following lawful bases under UK GDPR: performance of a contract (operating your account, delivering the Service, processing payments), legitimate interests (securing the Service, preventing fraud, improving the product, and reaching out to business prospects in line with PECR), consent (where required, for example for non-essential cookies and marketing email), and legal obligation (for example, retaining tax records).

4. Who we share your data with

We share data only with the third-party processors that help us run the Service, with integration providers you choose to connect, and where we are required to by law. We do not sell your data. The only advertising-related sharing is with Google, and only if you choose “Accept all” in our cookie banner (see Analytics and advertising cookies above).

ProcessorPurposeWhat it receivesRegion
SupabaseDatabase, authentication and file storageAccount info, project data, files, embeddings, OAuth tokensEU (Frankfurt), primary
StripePayment processing and subscription managementName, email, billing address, card data (held by Stripe, not us)US / EU
LoopsTransactional and lifecycle emailEmail address, name, account eventsUS
Google Cloud (Vertex AI)Our main AI models: Gemini for chat, answers and reports, Gemini and Veo for images and video, plus speech-to-text, text-to-speech and knowledge search. Google does not use this data to train its modelsPrompts and the context sent with them, including data from your Google account when you ask about it, attached files, voice notes and meeting recordingsUS (us-central1). Gemini 3 models and speech-to-text run on Google’s global service, which may process a request in any Google Cloud region
AnthropicClaude, for the most demanding tasks such as Design Studio layouts, meeting summaries and the AI Visibility audit. Anthropic does not use this data to train its modelsPrompts and the context sent with themStored in the US. A request may be processed in any region where Anthropic runs its models
DeepSeekA fast, low-cost model for bulk work such as sorting, scoring and short drafts, and a backup for chat. Its terms let it use de-identified inputs to improve its services, so we never send it data from your Google accountPrompts and the context sent with themChina
Kling AIVideo generation in the Video Studio, and a backup for Creator videos. Kling does not use this data to train its modelsVideo prompts and the images or clips you addSingapore
Atlas CloudA backup for Creator videos, using ByteDance’s Seedance model. Atlas passes the request to ByteDance under ByteDance’s own termsVideo promptsUS, and wherever ByteDance runs Seedance
RunwayThe last backup for Creator videos. Runway’s terms let it use prompts and results to train its modelsVideo promptsUS
xAISearches X for posts that mention your brand or the topics you track, using Grok. xAI does not use this data to train its modelsThe brand names, handles and keywords you ask us to monitorUS
Browser UseOnly when you switch on Stealth mode in the built-in browser: runs that session on Browser Use’s cloud browsersThe pages you open and anything you type in that sessionMainly US (Amazon Web Services)
OpenRouterA reserve route to other AI models if our direct providers are unavailable, and the Perplexity check in the AI Visibility audit. OpenRouter itself does not train on promptsPrompts and the context sent with them, never data from your Google accountUS
HostingerVPS hosting for the portal and supporting servicesEncrypted application data and logsUK / EU

Where a processor offers data processing terms, they require it to keep your data confidential and secure and to use it only to provide its service to us. The table notes where a provider’s own terms allow more than that.

5. International transfers

Your data is hosted primarily in the UK and EU. Some of the processors above handle it in other countries: the United States (Stripe, Loops, Google Cloud, Anthropic, xAI, Runway, Atlas Cloud, Browser Use and OpenRouter), Singapore (Kling) and China (DeepSeek). Google’s global AI service and Anthropic may also process a request in other regions where they run their models. Singapore and China do not have a UK adequacy decision. Where a processor offers them, we rely on the UK-US Data Bridge, the EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum to keep your data protected to UK GDPR standards. You can ask us for details of the safeguards for any processor at ops@ergora.cloud.

6. Retention

We keep your account data for as long as your account is active. If you close your account or ask us to delete it, we erase your personal data within 30 days, except where we are required to keep it for longer (for example, billing records that we must retain for tax purposes for up to 7 years).

Our web servers keep a standard log of requests (the page requested, the time, the browser type and the IP address) for 30 days, to keep the Service secure and to count visits. It is then deleted.

Backups are rotated on a 30-day cycle, so deleted data may persist in encrypted backups for up to 30 days after deletion before being permanently overwritten.

7. Your rights under UK GDPR

You have the right to access the personal data we hold about you, ask us to correct inaccurate data, request erasure, object to or restrict certain processing, withdraw consent where processing is based on it, and receive a copy of your data in a portable format.

You can exercise the most common rights yourself, instantly, from within the product:

  • Download my data: settings → Privacy, or call GET https://ergora.cloud/api/account/export while signed in.
  • Delete my account: settings → Account, or call POST https://ergora.cloud/api/account/delete while signed in.

For anything else, email ops@ergora.cloud. We will respond within one month. If you are not satisfied with our response you have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk).

8. Login security signals

We capture session-start IP geo (city and country only, never precise GPS coordinates) for security purposes: detecting unfamiliar device locations on your account so we can ask your admin device to approve a new login. This data is retained for 90 days and is never sold or shared with third parties.

9. Cookies

We use a small number of essential cookies to keep you signed in and to remember your preferences, plus optional analytics cookies that only load if you accept them. See our Cookie Policy for the full list.

10. Children

The Service is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We use encryption in transit (TLS) and at rest, row-level security in our database, encrypted OAuth tokens, access-controlled production secrets, and least-privilege access for our team. No system is perfectly secure; if we ever suffer a breach affecting your personal data we will notify you and the ICO in line with our legal obligations.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be communicated by email or an in-product notice in advance.

13. Contact

For privacy questions, data subject requests, or to contact our data protection lead, email ops@ergora.cloud.