Last updated July 12, 2026
Privacy Policy
We build Nacre for people who care about what happens to their data, including data about people who never signed up with us. This policy explains, in plain language, what we collect, why we collect it, who we share it with, and the control you keep.
Who we are, and our two roles
nacre.ai is operated by Nacre Labs, Inc. ("Nacre", "we", "us"), a Delaware corporation based in the United States. This policy applies to nacre.ai and its subdomains, to the waitlist, and to the Nacre application during the private beta.
We act in two distinct roles, and your rights run to different places depending on which one applies. For information about our visitors, waitlist members, and account holders, we are the controller, which means we decide how and why it is processed. For the content our customers bring into their workspaces, including personal information about their contacts and about visitors to their sites, we act as a processor: we handle that data on the customer's instructions, and the customer is its controller.
Information you provide
- Contact details, such as your email address, when you join the waitlist or write to us.
- Account details when you create an account, such as your name and email address, and the workspace information you set up.
- Content and configuration you bring into the product, for example the website you connect, integration settings, chat messages, and the drafts you edit and approve.
- Anything you send us in support conversations or feedback.
Information from connected services
Nacre works by connecting services you already use, such as email, billing, code hosting, and your own website. We access data from a connected service only after you explicitly connect it and only within the scopes you grant. We use that access to operate the product's features for your workspace and for no other purpose. Disconnecting an integration stops further collection from it.
Nacre's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide and improve user-facing features of the product. It is never sold or used for advertising, and it is never used to train generalized machine-learning models.
Information about people who are not our customers
The product helps customers find and reach people who may want what they build. In doing that work on a customer's instructions, we process personal information about people who have no direct relationship with Nacre. This can include professional contact details and company context gathered from public sources and licensed data providers, such as a person's name, role, employer, and business email address. It can also include engagement signals, such as replies to a customer's outreach, and visits to websites the customer has instrumented.
For this data the customer is the controller and we are the customer's processor. We use the data only to provide the service to that customer. We do not pool one customer's contact data into a shared database, and we do not sell it or use it for our own marketing. If you believe a Nacre customer holds your information, the fastest path is to contact that customer directly. You can also write to privacy@nacre.ai, and we will route your request to the right controller and assist with its fulfillment.
Information collected automatically
When you use the site and the product, we collect standard technical information, including your IP address, browser and device characteristics, the pages you view, and interaction events. We also collect error and performance telemetry that helps us keep the service reliable.
Our website analytics are first-party. Measurement runs on our own domain and the data stays with us. We do not share it with advertising networks, and we do not use third-party advertising cookies or cross-site trackers.
How we use information, and on what legal bases
- To provide, operate, secure, and improve the product and the website.
- To communicate with you about your account, the beta, and material changes.
- To understand aggregate usage so we can prioritize what to build.
- To comply with legal obligations and enforce our terms.
Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract, when we operate the service you asked for; legitimate interests, when we secure and improve the service or write to the waitlist you joined; consent, where we ask for it specifically; and legal obligation, where retention or disclosure is required.
AI processing
Nacre uses machine-learning models to draft and evaluate work on your behalf. Your data is sent to model providers only to produce results for your workspace, under agreements that prohibit those providers from training their models on it. We do not use your private data to train foundation models, whether ours or a third party's.
What the system learns is recorded as explicit findings in plain language, scoped to your workspace. You can review these records and delete them. Learning is never stored as changes to a model's weights.
Retention
We keep personal information for as long as your account is active or as needed to provide the service. If you close your account, we delete or de-identify personal information within 90 days. We retain data longer only where the law requires it or where we need it to resolve a dispute. Residual copies in routine encrypted backups expire on their own schedule.
Waitlist emails are kept until you receive access or ask to be removed. If we retire the waitlist, we delete them.
Security
We use industry-standard safeguards, including encryption in transit, encryption at rest, narrowly scoped credentials for integrations, role-based access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, and to withdraw consent where processing rests on it. California residents may exercise the corresponding rights under the CCPA, including access, deletion, correction, and knowledge of disclosures. We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale to opt out of. We will never treat you differently for exercising a privacy right.
To exercise any of these rights, write to privacy@nacre.ai. We verify requests before acting on them and respond within the timelines applicable law requires. If we decline a request, we will explain why and how to appeal. If you are in the EEA or the United Kingdom, you also have the right to lodge a complaint with your supervisory authority.
International transfers
We are based in the United States and process data there and in the regions of our service providers. Where personal information leaves a jurisdiction that restricts transfers, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
Children
The service is built for business use and is not directed to anyone under 18. We do not knowingly collect their data. If you believe a person under 18 has provided us personal information, contact us and we will delete it.
Changes and contact
We will post changes to this policy on this page and update the date above. Material changes will be communicated to account holders before they take effect. Questions, requests, and complaints can be sent to privacy@nacre.ai.