Legal · Privacy
Privacy Policy
Whitewater Intelligence LLC
Version 1.0 · Effective July 27, 2026
Whitewater Intelligence LLC ("Whitewater," "we," "us") is a Georgia limited liability company with its principal place of business in Chamblee, Georgia (metro Atlanta). This policy explains what information we collect when you use Whitewater OS (the "Service"), how we use it, who we share it with, and the choices you have.
Whitewater OS is business software. Your organization, the company that created or administers your workspace (your "Organization"), is our customer, and it controls the workspace and the business content inside it. This policy describes our practices honestly and specifically: it is written from how the Service actually works, and we have tried not to include anything here that the Service does not actually do.
Questions or requests: [email protected].
01 Who's who: your Organization and us
Whitewater OS is a multi-tenant, business-to-business service. Each workspace belongs to an Organization. Organization administrators control the workspace: they invite and remove members, assign roles and permissions, configure features, manage billing, and can export or archive the Organization's data.
For the business content your Organization puts into the Service (projects, tasks, meetings, metrics, goals, documents, and similar records), the Organization decides why and how that data is used, and we process it to provide the Service to the Organization. If you are a member of an Organization and want access to, correction of, or deletion of content held in that Organization's workspace, your Organization's administrators are the right first stop; they have the controls. We handle account-level requests (like deleting your personal account) directly; see Section 9.
You can belong to more than one Organization with a single account. Each Organization's workspace is isolated: members of one Organization cannot see another Organization's data.
02 Information we collect
Account and profile information. When you create an account: your name, email address, and a password (stored only as a secure hash; we cannot read it). Optionally: a profile photo you upload, or the profile picture provided by a sign-in provider. If you sign in with Google, Microsoft, or GitHub, we receive your name, email address, and profile picture from that provider. If you register a passkey, we store the passkey's public credential (not anything that lets us impersonate you elsewhere). Email verification status and sign-in method changes are recorded for security.
Organization content. The business records your Organization's members create in the Service: projects, tasks, comments, uploaded files, meeting agendas and minutes, scorecard metrics and entries, goals, priorities, vision plans, organizational charts and seat accountabilities, recurring-work boards, issues, headlines, and invitations (which include invitees' email addresses). Organizations may also record administrative data about members: for example, an administrator can enter member hourly rates for meeting-cost estimates; that data is entered by and belongs to the Organization, and the Service restricts who inside the Organization can see it.
AI feature content. When you use the AI assistant or coaches, we collect the messages you send, files you attach to AI conversations, and the responses and documents generated. See Section 5, which describes exactly where this content goes.
Billing information. Payments are handled by Stripe. Card and bank details are entered directly with Stripe on Stripe-hosted pages and never touch our servers. We store your Organization's subscription status, plan, seat count, Stripe customer/subscription identifiers, and (for metered AI usage) a usage ledger of token counts and model identifiers (not conversation content) used to compute usage-based charges.
Technical, security, and usage records. Session data (via a session cookie), IP address and browser user-agent as part of sign-in and request handling, an IP-derived time-zone suggestion when an Organization is created, audit logs of significant actions (sign-ins, permission changes, administrative operations), a change history of edits to Organization records, email delivery logs (what we sent, to whom, and whether it delivered), and AI usage metering records. These exist to run the Service securely and to give Organizations an accountability trail, not to profile you.
Support communications. If you contact support (including via the in-product support-ticket feature), we receive your message, your name and email, and basic context about your Organization and app version so we can help.
What we do not collect today: the Service currently runs no advertising trackers, third-party analytics SDKs, or cross-site tracking of any kind. See Section 6.
03 How we use information
We use the information described above to:
- Provide and operate the Service: authenticate you, render your Organization's workspace, sync data, deliver AI features, and store files.
- Secure the Service: verify emails, detect and prevent abuse and unauthorized access (including Cloudflare Turnstile bot protection on signup and password reset), require re-verification for sensitive actions, and maintain audit trails.
- Bill accurately: manage trials, subscriptions, seat counts, and consent-gated metered AI usage through Stripe.
- Communicate with you: transactional email (verification, password reset, security notices, billing notices) and notification email you can control per type (Section 9).
- Support you: respond to support requests.
- Monitor and improve reliability: operational logs, error capture, and job monitoring to detect failures. This is infrastructure telemetry about the system, not behavioral analytics about you.
- Comply with law: tax, accounting, and legal obligations.
We do not sell personal information, share it for cross-context behavioral advertising, or use customer content to build advertising profiles.
04 AI features and your content
The Service's AI features (the assistant "Miranda," the coach personas, and AI-assisted drafting) are powered by Anthropic's Claude models via Anthropic's commercial API. When you use an AI feature:
- The content needed to answer you is sent to Anthropic for processing: your messages, relevant workspace context the assistant retrieves on your behalf, and files you attach to AI conversations (attachments are transmitted to Anthropic's file-processing API).
- The AI operates with your permissions, not elevated ones: it can only read and (with your explicit confirmation) change what you yourself could.
- Anthropic processes this content to deliver the feature, as our service provider under our agreement with Anthropic, which incorporates Anthropic's Commercial Terms of Service as in effect. Under those terms, content submitted through Anthropic's commercial API is not used to train Anthropic's models. We cite Anthropic's terms by reference: consult Anthropic's published commercial terms for their current text. They are Anthropic's contractual commitments to us, not an independent promise by us about Anthropic's internal systems.
- We record token counts, model identifiers, and usage events for billing and platform-protection limits. These metering records do not contain conversation content.
- AI conversation history is stored in your account so you can revisit threads; you can delete conversations, and they are removed when your account is erased (Section 9).
AI features run only when a user invokes them. If your Organization does not use the AI features, its content is not sent to Anthropic. Organization administrators can also restrict AI access per member via the Service's permission controls.
05 Who we share information with (subprocessors)
We share personal information only with the service providers that operate the Service on our behalf, listed exhaustively below; with your Organization (your workspace content and membership records are visible to the Organization per its role and permission settings); as part of a corporate transaction (merger, acquisition, or asset sale, in which case this policy continues to apply to previously collected data unless you are notified otherwise); or when required by law (we will notify affected customers of legal demands unless legally prohibited).
| Provider | What it does for the Service | Data involved | Location |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting and delivery, file storage (R2), email delivery, bot protection (Turnstile) | Application traffic; uploaded files; outbound email content and addresses | Stored in the United States; traffic transits Cloudflare's global edge network |
| Cockroach Labs, Inc. (CockroachDB Cloud) | Managed database | Application and account data | United States (multi-region within the US) |
| Stripe, Inc. | Payment processing, checkout, billing portal, invoicing | Billing contact details and payment credentials (collected by Stripe directly); subscription and usage-charge data | United States |
| Anthropic, PBC | AI model processing (only when AI features are used) | Content submitted to AI features, including attached files (Section 4) | United States |
Sign-in providers (your choice). If you sign in with Google, Microsoft, or GitHub, that provider authenticates you and gives us your basic profile (name, email, picture). Your relationship with the provider is governed by its own privacy policy; it acts on your instruction, not as our subprocessor.
Infrastructure monitoring. We use an external uptime-monitoring service that checks whether our public endpoints respond. It receives no personal data.
We will update this table when our subprocessor list changes; material changes are announced per Section 12.
06 Cookies and tracking
As of this version, the Service uses:
- A session cookie (set by our authentication system) to keep you signed in. It is essential; the Service cannot work without it.
- Cloudflare Turnstile on the signup and password-reset forms, which may set its own technical state to distinguish humans from bots.
- Local browser storage for interface preferences (like theme) that stays on your device.
That is the complete list as of this version. The Service currently embeds no advertising trackers, no third-party analytics, no social-media pixels, and no session-replay tools, and does not track you across other sites, so today there is no tracking to disable: the Service behaves the same whether or not your browser sends "Do Not Track" or Global Privacy Control signals (and since we do not sell or share personal information, those signals impose no additional obligation we are not already meeting).
We may introduce product analytics or telemetry in the future to understand and improve the Service. If we do, we will first update this policy (with a new version number and the notice process described in Section 13) to describe what is collected and what choices you have, before it applies to you.
07 Where data lives; international use
We are a United States company and the Service is operated from the United States. Application data, uploaded files, and backups are stored in US regions of our providers; requests may transit Cloudflare's global edge network en route.
If you access the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those of your jurisdiction. We do not currently maintain an establishment in, or appoint a representative for, the European Union or the United Kingdom. Where our subprocessors offer recognized transfer safeguards (such as EU–US Data Privacy Framework certification or standard contractual clauses), we rely on those safeguards in our agreements with them. Organizations subject to EU/UK data-protection law should evaluate whether US processing meets their requirements before adopting the Service; we describe our actual practices in this policy so that evaluation can be honest.
08 How long we keep data
- Active and lapsed Organizations: data is retained for as long as the Organization's workspace exists. If a subscription lapses, the workspace goes read-only but the data is retained: nothing is deleted for non-payment, and export remains available. We do not delete Organization data on any automatic schedule: deletion happens on the Organization's explicit request or, after termination, at our discretion as described below.
- Deletion at your request: an Organization administrator can delete (archive) the Organization. A 30-day restoration window applies, during which the Organization can be restored on request. After that window, the Organization's data (database records, uploaded files, and files transmitted to Anthropic for AI processing) becomes eligible for permanent deletion, and any active subscription is cancelled. The 90-day guarantee below does not apply to data you have asked us to delete.
- After termination or closure: if your subscription or agreement ends other than by your own deletion request, we guarantee the Organization's data remains retrievable (read-only, with export available) for at least 90 days after the termination. Beyond 90 days, the data is liable to be deleted at any time at our discretion; we do not commit to a deletion date, and data may be retained until deletion occurs or the Organization requests it.
- Account erasure: described in Section 9 (unchanged by the above; user-level erasure is honored on verified request).
- Backups: our database is backed up daily by CockroachDB Cloud with backups retained up to 30 days, so deleted or erased data may persist in expiring backups until those backups age out. Uploaded files are stored in a single region and are not independently versioned or backed up; deleting a file deletes it.
- Email records: delivery logs are kept for operational troubleshooting. Suppression records (addresses that bounced or unsubscribed) are kept so we keep honoring them.
- Audit and change logs: kept for the life of the Organization as its accountability record.
- Billing and usage-ledger records: kept as long as needed for tax, accounting, and dispute-resolution obligations, including after account erasure (Section 9 explains why).
09 Your rights and choices
These capabilities exist in the product today; this section describes what we actually do, not aspirations:
- Access and portability. Organization administrators can export the Organization's complete data as JSON from the Service (the export is registry-driven, so it includes the Organization's records by default; a small set of server-internal fields, and compensation-sensitive values for callers without compensation visibility, are excluded or redacted). Individual members can see their own profile, content, and settings in the app.
- Correction. You can edit your name, avatar, password, and preferences in Account Settings. Organization content is corrected in the workspace by anyone with permission to edit it.
- Notification choices. The notification center lets you turn notification emails on or off per type and per channel. Transactional email required to operate your account (verification, password reset, security alerts, billing notices) cannot be disabled while the account is active, because the Service can't be operated safely without it. All our email is sent from [email protected]; unsubscribe and bounce handling are honored automatically via a suppression list.
- Account erasure ("right to be deleted"). Email [email protected] from your account email to request erasure. After verifying the request, we erase your personal data across every Organization you belonged to: your profile details, credentials (password hashes, passkeys, linked sign-in accounts), sessions, memberships, personal settings, notifications, AI conversations and attachments (including deletion of attachment files from storage and from Anthropic's file API), and search history are deleted, and your account record is reduced to an anonymous tombstone. Two things are deliberately not deleted, and we want to be straightforward about them: (1) business records you authored inside an Organization's workspace (tasks, comments, meetings, and similar) belong to that Organization and are preserved, attributed to "Deleted user" with your identity removed; (2) billing-ledger and audit entries are preserved without your identity details where needed to keep already-issued invoices and the Organization's compliance trail intact.
- Complaints. If you believe we have not honored these commitments, contact [email protected] and we will investigate. California residents may also have the rights described in Section 10.
If your request concerns content inside an Organization's workspace (rather than your personal account), we will route it to that Organization's administrators, who control that data, and we will tell you we did so.
10 United States state privacy laws (California and similar)
We believe we are currently below the applicability thresholds of the California Consumer Privacy Act (as amended by the CPRA) and similar state laws. We honor the substance of those rights for all users regardless:
- Right to know / access: Sections 2 and 9 describe what we collect and how to get it.
- Right to delete: Section 9 (account erasure).
- Right to correct: Section 9.
- Right to opt out of sale or sharing: we do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We have not sold or shared personal information, including in the preceding 12 months.
- Sensitive personal information: we do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.
- Non-discrimination: we will not discriminate against you for exercising these rights.
Requests: [email protected]. We will verify requests using your account email. Authorized agents may submit requests with proof of authorization.
11 Security
We protect information with measures that include: encryption in transit (TLS) and encryption at rest via our storage providers; tenant isolation enforced in the application for every data access; role-based access control with per-member permission overrides inside Organizations; required email verification; support for passkeys and step-up re-verification before security-critical actions; notification emails on sign-in-method changes; secrets held in a managed secret store, never in code; audit logging of significant actions; and continuous monitoring with alerting for failures and anomalies.
No system is perfectly secure, and we do not promise breach-proof security. If we learn of a breach of security affecting your personal information, we will notify affected Organizations and users without undue delay, consistent with applicable law, and tell them what we know, what we are doing, and what they can do.
12 Children
The Service is business software, not directed to children, and not intended for anyone under 16. We do not knowingly collect personal information from children under 16; if we learn we have, we will delete it. Contact [email protected] if you believe a child has provided us personal information.
13 Changes to this policy
This policy is versioned. We may update it as the Service or the law changes. For material changes, we will notify Organization administrators (and, where the change affects individual users directly, users) by email or in-product notice at least 30 days before the change takes effect. The version number and effective date at the top always identify the current policy. Continued use after the effective date constitutes acceptance; where the Service requires in-product re-acceptance of updated terms, that mechanism applies here too.
14 Contact
Whitewater Intelligence LLC
2965 Flowers Rd S, Suite 250
Chamblee, GA 30341, USA
Privacy requests and questions: [email protected]