1. Introduction
ESR AI Corp., of PO Box 341, Farmingdale, NY 11735 (“ESR,” “we,” “us,” or “our”), is committed to protecting your privacy. ESR is the controller of the personal data described in this policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the ESR platform (the “Service”). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
We collect information you provide directly and information generated by your use of the Service.
- Account information: name, email address, and password when you register.
- Company information: business name, type, and details you provide during onboarding.
- Payment information: processed securely by Stripe. We do not store full card numbers.
- Usage data: tasks assigned to agents, knowledge base content, and activity logs.
- Technical and analytics data: IP address, browser type, device information, session data, and product usage or interaction data collected via analytics cookies. See Section 6.
- Information about other people that you provide. You may put information about other people into the Service, for example customer records, leads, contacts, candidates, or suppliers. Where you do, you decide what is collected and why, and we process it on your instructions. See Section 5.
- Information your agents collect on your behalf. When an agent researches something for you, it reads publicly available web pages and writes up what it found. Where that research is about a person, for example a lead writeup, the result may contain that person’s name, job title, and employer. See Section 5.
- Affiliate information. If you join the paid affiliate program, we record your acceptance of the affiliate agreement, the version you accepted, the date and time, and the IP address the acceptance came from. We also record a payout method you supply. See Section 12.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Process transactions and manage your subscription and AI budget balance
- Send you service-related emails (receipts, updates, security notices) via Resend
- Personalize and operate your AI agent interactions
- Monitor and analyze usage patterns to improve the platform
- Detect, investigate, and prevent fraud and abuse, and ensure security
- Send, publish, and schedule on your behalf through connections you authorise, and only for actions you have approved
- Calculate and pay affiliate commissions, where you participate in that program
4. AI and Your Data
Content you submit to AI agents, including tasks, knowledge base entries, and business context, is sent to our AI model provider, Anthropic, to generate responses and carry out approved actions. We do not use your business data to train general-purpose AI models. Your data is processed strictly to provide you with AI responses and agent actions, subject to Anthropic’s own data-handling terms as our subprocessor.
Web research. When an agent researches on your behalf, the search and page-fetching are performed by Anthropic as part of the same processing. No separate search provider receives your information.
Ava’s voice. Where Ava speaks, we send the text she is going to say to Cartesia, which streams audio back and plays it. This is one direction only. Ava speaks; she does not listen. No audio from you is captured, transmitted, or processed, Cartesia never receives a recording of you, and the audio returned is played rather than stored.
5. Information About Other People
Some of the information in your account is about people other than you. There are two ways it gets there.
Information you provide. When you add a customer list, a lead, a contact, a candidate, or a supplier, you are giving us personal data about someone else. For that information, you are the controller and we are your processor. You decide what to collect and why, and we process it only on your instructions and only to provide the Service to you. You are responsible for having a lawful basis to provide it, and for any notice or consent your own obligations require.
Information your agents collect. When an agent researches on your behalf, it reads publicly available web pages and writes up what it found, citing where it came from and when it was read. We do not store copies of the pages themselves, only the writeup the agent produced. Where the subject of that research is a person, that writeup may contain their name, job title, and employer. Agents read only publicly available pages. They do not bypass paywalls, login walls, or any other access control.
Legal basis. Where the GDPR applies, our processing of this information is carried out on your instructions as your processor, and the lawful basis for the underlying collection is yours to establish. Where we determine the purpose ourselves, we rely on legitimate interests in providing the Service, balanced against the interests of the people concerned.
Retention. Information about other people is retained for as long as your account is active, and is deleted when your account is deleted, as described in Section 10. You may delete any of it at any time from your account.
Requests from people we hold data about. If someone whose data is in your account contacts us directly, we will normally direct them to you, because you decide what happens to it. Where the law requires us to act ourselves, we will, and we will tell you.
6. Cookies and Analytics
Here is every cookie the Service sets, what it does, and how long it lasts.
Session. A Supabase authentication cookie keeps you signed in. It lasts up to 400 days in your browser. Signing out ends the session.
Affiliate attribution. If you arrive through an affiliate link, we set a cookie recording which affiliate referred you. It lasts 30 days and its only purpose is to credit the correct affiliate if you later subscribe. It is not used for advertising or profiling.
Support access. If you have given someone at ESR permission to access your account, two short-lived cookies record which account is being viewed. They last 24 hours and only exist while that access is in effect. See Section 17.
Analytics. PostHog records product usage, and Microsoft Clarity records heatmaps and session replays, so we can see how the Service is used and improve it. In session replay, the contents of form fields are masked. Text displayed on the page is not necessarily masked, so a session replay may include business content that is visible on screen. These are product analytics tools, not third-party advertising or cross-site ad-tracking, and we do not sell the data they collect.
Where we record the IP address of a click on an affiliate link, we store it as a salted hash rather than in the clear, so it can be used to detect fraud without being readable as an address.
You can disable non-essential cookies in your browser settings, though this may affect some functionality.
7. Third-Party Service Providers (Subprocessors)
We share the minimum data necessary with the following subprocessors to operate the Service. All are bound by confidentiality and data-protection obligations appropriate to the data they process:
- Anthropic: AI models that power ESR's agents, including web search and page fetching performed on your behalf
- Supabase: database, authentication, and data storage
- Vercel: application hosting and infrastructure
- Cloudflare: runs our web addresses and passes requests on to us. It sees which page was asked for and the internet address it was asked from. It does not store the things you write in ESR.
- Stripe: payment processing and billing
- Resend: transactional email delivery
- Voyage AI: processes memory embeddings so your agents' memories are searchable
- Cartesia: text-to-speech for Ava's voice. Receives text, returns audio. No audio from you is sent to them.
- bundle.social: social publishing. Receives post content and the access tokens for social accounts you connect.
- Google: only if you connect a Google account, for sending email and managing calendar events on your behalf
- Sentry: error monitoring. When something breaks, Sentry gets the error and the lines of code it came from, so we can fix it. We turn off the parts that would send your details: no cookies, no sign-in tokens, and no form contents. If an email address or a key still shows up in an error message, we blank it out before it leaves. You are identified by an account number, never by name or email.
- PostHog: product analytics — which pages and features are used
- Google Analytics: counts page views so we can see which pages people use. It gets the page address and basic browser details. It does not get your name, your email, or anything you type into ESR.
- Microsoft Clarity: product analytics — which pages and features are used
8. Google Account Connection
When you connect a Google account, ESR requests four permissions. This section explains exactly what each one covers.
openid and email. Identity only. These let Google confirm who you are and tell us your email address.
Sending mail (gmail.send). Lets ESR send an email composed inside ESR, from your connected account, after you approve it. No message is ever sent without your approval. ESR does not read, search, modify, label, delete, download, or store the contents of your mailbox, and has no ability to browse your inbox.
Calendar events (calendar.events). Lets ESR create, update, and remove calendar events on your behalf, after you approve each one.
If you connected your Google account before this policy was updated, you granted all four of these permissions at that time. You can see them, and revoke them, at myaccount.google.com/permissions.
The calendar permission today. Calendar actions are gated behind your approval: an agent proposes an event and it goes to your approval queue rather than to Google. Nothing is created unless you approve it. As of the date of this policy, no calendar event has been created through ESR by anyone. Settings shows the capability’s current availability.
Nothing else. ESR does not request or receive access to Drive, Contacts, or any other Google service, and cannot access them.
What we store. Your connected Google account address, the permissions you granted, and the access tokens that let ESR act on your behalf. Tokens are encrypted at rest using AES-256-GCM before being written to our database. The encryption key lives only on ESR’s server, and a token is never sent to your browser or written to a log in plain text.
How to disconnect. From ESR Settings, or independently at myaccount.google.com/permissions, where Google lets you revoke ESR’s access directly. Either path stops ESR from acting on that account immediately. If you delete your ESR account, the connection and its stored tokens are deleted with it, consistent with Section 10.
Limited Use. ESR’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, and we do not use it to train AI models, general purpose or otherwise.
9. Data Sharing
We do not sell your personal information. We share data only with the subprocessors listed in Section 7, as necessary to operate the Service, and as required by law (for example, in response to a valid legal request). We do not share your data with third parties for their own independent marketing purposes.
10. Data Retention
We retain your account data for as long as your account is active.
If you cancel or delete your account, your data is archived for 90 days and then deleted, except where retention is required by law or for legitimate business records such as billing history.
You can export your data at any time from Settings, including immediately on cancellation. Your ability to export survives cancellation for the length of the archive period. Nothing is deleted without that window first.
Work your agents produced, and information about other people held in your account as described in Section 5, is deleted on the same schedule.
11. Your Data, Domain and Business Ownership
You own your business, brand, domain(s), and the content and data you or your agents create in the Service. We process that data as described in this policy solely to operate and improve the Service on your behalf: we do not claim ownership of it, and you can export or delete it at any time.
12. Affiliate and Referral Data
If you join the paid affiliate program, we collect and keep the following.
Your acceptance of the affiliate agreement, including which version you accepted, the date and time, and the IP address the acceptance was made from. We keep the IP address so we have a record of who accepted what and when. It is used for that purpose and no other.
A payout method you supply, so we know where to send money.
Referral activity: clicks on your link, signups attributed to you, and commissions recorded, held, paid, or reversed. Where we record the IP address of a click, we store it as a salted hash rather than in the clear, so it can be used to detect fraud without being readable as an address.
What we do not hold. Affiliate payouts are made manually. We do not hold tax documents, tax identification numbers, or bank details in the platform. Where tax documentation is required before a payout, it is collected outside the product and is not stored in the Service.
If that changes, this policy changes with it, and we will tell you before it does.
13. Automated Decision-Making
Under the GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
We do not make such decisions about you. ESR’s agents produce work for you to review. Nothing leaves your account without your approval, so a person is always in the loop before an action has effect.
Where you use the Service to make decisions about other people. If you use output from the Service to inform a decision that materially affects a person’s employment, credit, housing, healthcare, insurance, legal rights, or education, you are required by our Acceptable Use Policy to review that output yourself before acting on it. You are the decision-maker. ESR produces research and work product; it does not make or supply determinations about any person. Meeting any legal obligation attached to a decision of that kind, including notice, disclosure, adverse action, bias auditing, or record-keeping requirements, is your responsibility.
14. Your Rights (GDPR, CCPA & Other Regional Rights)
Depending on your location, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), including the right to:
- Access and receive a copy of your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Opt out of the “sale” or “sharing” of personal information: we do not sell or share personal information as those terms are defined under CCPA/CPRA
Our lawful bases for processing (GDPR/UK GDPR). Where the GDPR applies, we rely on: performance of a contract, to create and operate your account, run your agents, and process your subscription; legitimate interests, to secure the Service, prevent fraud and abuse, monitor errors, and analyze product usage so we can improve it, balanced against your rights; consent, for non-essential analytics cookies and marketing email, which you may withdraw at any time without affecting processing already carried out; and legal obligation, to keep tax, accounting, and billing records. Where we process information about other people that you have provided or your agents have collected, our role and lawful basis are described in Section 5.
How to exercise your rights. Email privacy@esr.co from the address on your account, or use the export and delete controls in Settings. We may need to verify your identity before acting on a request, and we will only ask for information necessary to do so. We respond within 30 days under the GDPR (extendable by two further months for complex requests, with notice) and within 45 days under the CCPA/CPRA (extendable once by 45 days, with notice). An authorized agent may submit a request on your behalf with proof of authorization. Requests are free unless manifestly unfounded or excessive.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months, including with respect to anyone under 16. We therefore do not offer a “Do Not Sell or Share My Personal Information” mechanism, because there is nothing to opt out of. We will not discriminate against you for exercising any privacy right. If we decline a request, we will tell you why, and you may appeal by replying to our response: some US state privacy laws give you a right of appeal. You also have the right to lodge a complaint with your local data protection authority (in the EU, your national supervisory authority; in the UK, the Information Commissioner’s Office).
15. International Data Transfers
ESR is based in the United States, and the subprocessors listed in Section 7 process data in the United States and, in some cases, other countries. If you use the Service from the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred to and processed in a country that may not provide the same level of data protection as your own.
How we protect those transfers. Where a transfer requires a safeguard, we rely on one of the following: the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data and the equivalent addendum for Swiss data); the recipient’s certification under the EU-US Data Privacy Framework and its UK Extension and Swiss-US framework, where the recipient is certified; or an adequacy decision covering the destination country. We carry out a transfer risk assessment where one is required, and we contractually require each subprocessor to apply appropriate technical and organizational security measures.
Business customers. If you need a Data Processing Addendum, for example, because you are processing your own customers’ personal data through the Service and need ESR to commit as your processor, email privacy@esr.co and we will put one in place. You may also request a current list of subprocessors and the specific transfer mechanism relied on for each.
16. Children’s Privacy
The Service is not directed to, and we do not knowingly collect personal information from, individuals under 18. If we learn we have collected such information, we will delete it promptly.
17. Security and Access to Your Account
We implement industry-standard security measures including encryption in transit (TLS), secure password hashing, and access controls. Our database provider encrypts stored data at rest as a platform default. Access tokens for connected accounts are additionally encrypted at the application layer before they are stored, as described in Section 8.
No method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password for your account.
Who at ESR can access your account. This depends on your plan, and it is enforced in code rather than by policy.
On Launch, nobody at ESR can access your account unless you grant it. A grant is explicit, time-limited, and you can revoke it instantly. Staff cannot create a grant for themselves and cannot delete one; only you can open that door and only you can close it.
On Managed, ESR operates your account on your behalf. That is what the plan is. Access is continuous, it is by contract, and it is disclosed when you sign up.
Support staff have no account access at all, on any plan. Support is handled through tickets and our community.
Every access is written to an audit log recording who accessed the account and when, and that log is visible to you. We do not notify you separately each time, because on Launch nothing happens without a grant you created, and on Managed access is the service you are paying for.
18. Data Breach Notification
We maintain an internal process for detecting, investigating, containing, and recording security incidents affecting personal data. If we become aware of such an incident, we will act on the following timelines:
- Regulators (GDPR/UK GDPR): where the incident is a personal data breach likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it
- You: where the breach is likely to result in a high risk to your rights and freedoms, we notify you directly without undue delay
- US state law: we notify affected residents and any required state authorities in the most expedient time possible and without unreasonable delay, consistent with the breach-notification law of each affected state, including, for New York residents, the SHIELD Act
- If you are a business customer and the affected data is personal data you process through the Service, we notify you without undue delay so you can meet your own notification obligations
Our notice will describe, to the extent known, what happened, the categories and approximate volume of data involved, the likely consequences, the steps we have taken or propose to take, and what you can do to protect yourself. Notification may be delayed where a law enforcement agency determines that notice would impede a criminal investigation.
19. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
20. Contact
Questions about this Privacy Policy, or requests to exercise your data rights? Email us at privacy@esr.co, or write to us at:
PO Box 341
Farmingdale, NY 11735
ESR has not appointed a Data Protection Officer, as one is not required for our processing under Article 37 of the GDPR. Privacy requests are handled by ESR directly at the address above. If ESR later becomes required to designate an EU or UK representative under Article 27, we will name that representative here.
21. Text Messages (SMS)
If you opt in to account alerts by text, we use your mobile number only to send those alerts. We do not share or sell your mobile number or SMS opt-in data with third parties for marketing or promotional purposes. Program details are on our SMS Terms page.
