Last updated: 29 September 2026
This privacy policy applies to Ergora Ltd, a company registered in England & Wales, trading as Ergora. We operate the marketing site at ergora.app, the product portal at ergora.cloud, and the cold-outreach domain try-ergora.com. For the purposes of UK GDPR and the Data Protection Act 2018 we are the data controller for personal data we process about our customers, prospects and website visitors.
You can contact us about anything in this policy, including to exercise your rights, at ops@ergora.cloud. Our data protection contact is reachable at the same address.
When you create an account we collect your name, email address, and (where set) a password hash. If you sign in via a social provider we receive your name, email and profile photo from that provider. We use this to authenticate you, contact you about the account, and personalise the experience.
You may add your company name, website, industry, brand assets, and connect third-party integrations (Shopify, Google, Meta, HubSpot, LinkedIn, Xero and others). When you do, we store the resulting access tokens encrypted and use them only to retrieve data on your behalf within the scope you approved.
Google is connected one feature at a time, and Google asks you to approve each one separately. We only request the access that feature needs:
Most Google data is fetched live when you ask for it and is not stored. We keep only what a feature needs to work: monthly traffic and advertising totals for forecasts, keyword positions in the Rank Tracker and, if you use the Smart Inbox, the emails it has synced. Access tokens are encrypted at rest. When you ask a question that needs this data, the relevant part is sent to the AI model that writes the answer, only to produce that answer. That model is always Google’s Gemini on Google Cloud or Anthropic’s Claude, and neither provider trains its models on the data we send.
We do not sell Google user data, use it for advertising, or use it to train or improve AI or machine learning models. Nobody at Ergora reads it unless you ask us to for support, or it is needed for security or to comply with the law. You can disconnect Google at any time in Settings, Integrations, which deletes the stored tokens.
Ergora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We process the prompts, files, voice notes, meeting recordings and other content you submit so the AI can respond. Voice and meeting audio is sent to Google Cloud for transcription and is not retained beyond what is needed to produce the transcript and downstream summaries you see in the product.
The product builds personalised memory layers (your personal seat context and your organisation’s shared company memory) from your interactions. These memories belong to your workspace, are not shared across customers, and can be cleared by you at any time.
We collect token consumption, image generation counts, feature usage, IP address, browser, device, session timestamps and similar technical data to operate the platform, enforce plan limits, prevent abuse and improve the Service. Stripe holds your payment-method details. We never see full card numbers.
If you choose “Accept all” in our cookie banner, on ergora.app or in the portal, Google Analytics 4 sets cookies that record usage patterns, and we enable Google Signals and Google’s advertising cookies so that Google can show you Ergora ads on other websites based on your visit. Choose “Essential only” and none of this loads. The full list, and how to change your mind, is in our Cookie Policy.
We process personal data on the following lawful bases under UK GDPR: performance of a contract (operating your account, delivering the Service, processing payments), legitimate interests (securing the Service, preventing fraud, improving the product, and reaching out to business prospects in line with PECR), consent (where required, for example for non-essential cookies and marketing email), and legal obligation (for example, retaining tax records).
We share data only with the third-party processors that help us run the Service, with integration providers you choose to connect, and where we are required to by law. We do not sell your data. The only advertising-related sharing is with Google, and only if you choose “Accept all” in our cookie banner (see Analytics and advertising cookies above).
| Processor | Purpose | What it receives | Region |
|---|---|---|---|
| Supabase | Database, authentication and file storage | Account info, project data, files, embeddings, OAuth tokens | EU (Frankfurt), primary |
| Stripe | Payment processing and subscription management | Name, email, billing address, card data (held by Stripe, not us) | US / EU |
| Loops | Transactional and lifecycle email | Email address, name, account events | US |
| Google Cloud (Vertex AI) | Our main AI models: Gemini for chat, answers and reports, Gemini and Veo for images and video, plus speech-to-text, text-to-speech and knowledge search. Google does not use this data to train its models | Prompts and the context sent with them, including data from your Google account when you ask about it, attached files, voice notes and meeting recordings | US (us-central1). Gemini 3 models and speech-to-text run on Google’s global service, which may process a request in any Google Cloud region |
| Anthropic | Claude, for the most demanding tasks such as Design Studio layouts, meeting summaries and the AI Visibility audit. Anthropic does not use this data to train its models | Prompts and the context sent with them | Stored in the US. A request may be processed in any region where Anthropic runs its models |
| DeepSeek | A fast, low-cost model for bulk work such as sorting, scoring and short drafts, and a backup for chat. Its terms let it use de-identified inputs to improve its services, so we never send it data from your Google account | Prompts and the context sent with them | China |
| Kling AI | Video generation in the Video Studio, and a backup for Creator videos. Kling does not use this data to train its models | Video prompts and the images or clips you add | Singapore |
| Atlas Cloud | A backup for Creator videos, using ByteDance’s Seedance model. Atlas passes the request to ByteDance under ByteDance’s own terms | Video prompts | US, and wherever ByteDance runs Seedance |
| Runway | The last backup for Creator videos. Runway’s terms let it use prompts and results to train its models | Video prompts | US |
| xAI | Searches X for posts that mention your brand or the topics you track, using Grok. xAI does not use this data to train its models | The brand names, handles and keywords you ask us to monitor | US |
| Browser Use | Only when you switch on Stealth mode in the built-in browser: runs that session on Browser Use’s cloud browsers | The pages you open and anything you type in that session | Mainly US (Amazon Web Services) |
| OpenRouter | A reserve route to other AI models if our direct providers are unavailable, and the Perplexity check in the AI Visibility audit. OpenRouter itself does not train on prompts | Prompts and the context sent with them, never data from your Google account | US |
| Hostinger | VPS hosting for the portal and supporting services | Encrypted application data and logs | UK / EU |
Where a processor offers data processing terms, they require it to keep your data confidential and secure and to use it only to provide its service to us. The table notes where a provider’s own terms allow more than that.
Your data is hosted primarily in the UK and EU. Some of the processors above handle it in other countries: the United States (Stripe, Loops, Google Cloud, Anthropic, xAI, Runway, Atlas Cloud, Browser Use and OpenRouter), Singapore (Kling) and China (DeepSeek). Google’s global AI service and Anthropic may also process a request in other regions where they run their models. Singapore and China do not have a UK adequacy decision. Where a processor offers them, we rely on the UK-US Data Bridge, the EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum to keep your data protected to UK GDPR standards. You can ask us for details of the safeguards for any processor at ops@ergora.cloud.
We keep your account data for as long as your account is active. If you close your account or ask us to delete it, we erase your personal data within 30 days, except where we are required to keep it for longer (for example, billing records that we must retain for tax purposes for up to 7 years).
Our web servers keep a standard log of requests (the page requested, the time, the browser type and the IP address) for 30 days, to keep the Service secure and to count visits. It is then deleted.
Backups are rotated on a 30-day cycle, so deleted data may persist in encrypted backups for up to 30 days after deletion before being permanently overwritten.
You have the right to access the personal data we hold about you, ask us to correct inaccurate data, request erasure, object to or restrict certain processing, withdraw consent where processing is based on it, and receive a copy of your data in a portable format.
You can exercise the most common rights yourself, instantly, from within the product:
GET https://ergora.cloud/api/account/export while signed in.POST https://ergora.cloud/api/account/delete while signed in.For anything else, email ops@ergora.cloud. We will respond within one month. If you are not satisfied with our response you have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk).
We capture session-start IP geo (city and country only, never precise GPS coordinates) for security purposes: detecting unfamiliar device locations on your account so we can ask your admin device to approve a new login. This data is retained for 90 days and is never sold or shared with third parties.
We use a small number of essential cookies to keep you signed in and to remember your preferences, plus optional analytics cookies that only load if you accept them. See our Cookie Policy for the full list.
The Service is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
We use encryption in transit (TLS) and at rest, row-level security in our database, encrypted OAuth tokens, access-controlled production secrets, and least-privilege access for our team. No system is perfectly secure; if we ever suffer a breach affecting your personal data we will notify you and the ICO in line with our legal obligations.
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be communicated by email or an in-product notice in advance.
For privacy questions, data subject requests, or to contact our data protection lead, email ops@ergora.cloud.