Legal
Privacy Policy
Last updated: July 27, 2026
1. Introduction
ESR AI Corp., of PO Box 341, Farmingdale, NY 11735 (“ESR,” “we,” “us,” or “our”), is committed to protecting your privacy. ESR is the controller of the personal data described in this policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the ESR platform (the “Service”). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
We collect information you provide directly and information generated by your use of the Service:
- Account information: name, email address, and password when you register
- Company information: business name, type, and details you provide during onboarding
- Usage data: tasks assigned to agents, knowledge base content, and activity logs
- Payment information: processed securely by Stripe; we do not store full card numbers
- Technical & analytics data: IP address, browser type, device information, session data, and product-usage/interaction data collected via analytics cookies (see Section 5)
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Process transactions and manage your subscription and Power balance
- Send you service-related emails (receipts, updates, security notices) via Resend
- Personalize and operate your AI agent interactions
- Monitor and analyze usage patterns to improve the platform
- Detect, investigate, and prevent fraud and abuse, and ensure security
4. AI and Your Data
Content you submit to AI agents (tasks, knowledge base entries, business context) is sent to our AI model provider, Anthropic, to generate responses and carry out routed tasks. We do not use your business data to train general-purpose AI models. Your data is processed strictly to provide you with AI responses and agent actions, subject to Anthropic’s own data-handling terms as our subprocessor.
5. Cookies & Analytics
We use essential session cookies to keep you logged in and maintain your preferences. We also use analytics cookies/scripts, PostHog (product usage analytics) and Microsoft Clarity (heatmaps and session recording, production/staging only), to understand how the Service is used and improve it. These are product-analytics tools, not third-party advertising or cross-site ad-tracking cookies, and we do not sell the data they collect. You can disable non-essential cookies in your browser settings, though this may affect some functionality.
6. Third-Party Service Providers (Subprocessors)
We share the minimum data necessary with the following subprocessors to operate the Service. All are bound by confidentiality and data-protection obligations appropriate to the data they process:
- Stripe: payment processing and billing
- Supabase: database, authentication, and data storage
- Vercel: application hosting and infrastructure
- Anthropic: AI models that power ESR’s agents
- Voyage AI: processes memory embeddings (turns your agents’ memories into search vectors)
- Resend: transactional email delivery
- Sentry: error monitoring and diagnostics
- PostHog & Microsoft Clarity: product analytics (see Section 5)
7. Data Sharing
We do not sell your personal information. We share data only with the subprocessors listed in Section 6, as necessary to operate the Service, and as required by law (for example, in response to a valid legal request). We do not share your data with third parties for their own independent marketing purposes.
8. Data Retention
We retain your account data for as long as your account is active. If you cancel or delete your account, we will delete your personal data within 90 days, except where retention is required by law or for legitimate business records (e.g. billing history). You can export your data at any time from Settings.
9. Your Data, Domain & Business Ownership
You own your business, brand, domain(s), and the content and data you or your agents create in the Service. We process that data as described in this policy solely to operate and improve the Service on your behalf: we do not claim ownership of it, and you can export or delete it at any time.
10. Your Rights (GDPR, CCPA & Other Regional Rights)
Depending on your location, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), including the right to:
- Access and receive a copy of your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Opt out of the “sale” or “sharing” of personal information: we do not sell or share personal information as those terms are defined under CCPA/CPRA
Our lawful bases for processing (GDPR/UK GDPR). Where the GDPR applies, we rely on: performance of a contract, to create and operate your account, run your agents, and process your subscription; legitimate interests, to secure the Service, prevent fraud and abuse, monitor errors, and analyze product usage so we can improve it, balanced against your rights; consent, for non-essential analytics cookies and marketing email, which you may withdraw at any time without affecting processing already carried out; and legal obligation, to keep tax, accounting, and billing records.
How to exercise your rights. Email support@esr.co from the address on your account, or use the export and delete controls in Settings. We may need to verify your identity before acting on a request, and we will only ask for information necessary to do so. We respond within 30 days under the GDPR (extendable by two further months for complex requests, with notice) and within 45 days under the CCPA/CPRA (extendable once by 45 days, with notice). An authorized agent may submit a request on your behalf with proof of authorization. Requests are free unless manifestly unfounded or excessive.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months, including with respect to anyone under 16. We therefore do not offer a “Do Not Sell or Share My Personal Information” mechanism, because there is nothing to opt out of. We will not discriminate against you for exercising any privacy right. If we decline a request, we will tell you why, and you may appeal by replying to our response: some US state privacy laws give you a right of appeal. You also have the right to lodge a complaint with your local data protection authority (in the EU, your national supervisory authority; in the UK, the Information Commissioner’s Office).
11. International Data Transfers
ESR is based in the United States, and the subprocessors listed in Section 6 process data in the United States and, in some cases, other countries. If you use the Service from the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred to and processed in a country that may not provide the same level of data protection as your own.
How we protect those transfers. Where a transfer requires a safeguard, we rely on one of the following: the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data and the equivalent addendum for Swiss data); the recipient’s certification under the EU-US Data Privacy Framework and its UK Extension and Swiss-US framework, where the recipient is certified; or an adequacy decision covering the destination country. We carry out a transfer risk assessment where one is required, and we contractually require each subprocessor to apply appropriate technical and organizational security measures.
Business customers. If you need a Data Processing Addendum, for example, because you are processing your own customers’ personal data through the Service and need ESR to commit as your processor, email support@esr.co and we will put one in place. You may also request a current list of subprocessors and the specific transfer mechanism relied on for each.
12. Children’s Privacy
The Service is not directed to, and we do not knowingly collect personal information from, individuals under 18. If we learn we have collected such information, we will delete it promptly.
13. Security
We implement industry-standard security measures including encryption in transit (TLS), secure password hashing, and access controls. No method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password for your account.
14. Data Breach Notification
We maintain an internal process for detecting, investigating, containing, and recording security incidents affecting personal data. If we become aware of such an incident, we will act on the following timelines:
- Regulators (GDPR/UK GDPR): where the incident is a personal data breach likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it
- You: where the breach is likely to result in a high risk to your rights and freedoms, we notify you directly without undue delay
- US state law: we notify affected residents and any required state authorities in the most expedient time possible and without unreasonable delay, consistent with the breach-notification law of each affected state, including, for New York residents, the SHIELD Act
- If you are a business customer and the affected data is personal data you process through the Service, we notify you without undue delay so you can meet your own notification obligations
Our notice will describe, to the extent known, what happened, the categories and approximate volume of data involved, the likely consequences, the steps we have taken or propose to take, and what you can do to protect yourself. Notification may be delayed where a law enforcement agency determines that notice would impede a criminal investigation.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact
Questions about this Privacy Policy, or requests to exercise your data rights? Email us at support@esr.co, or write to us at:
ESR AI Corp.PO Box 341FarmingdaleNY 11735ESR has not appointed a Data Protection Officer, as one is not required for our processing under Article 37 of the GDPR. Privacy requests are handled by ESR directly at the address above. If ESR later becomes required to designate an EU or UK representative under Article 27, we will name that representative here.