Last updated: July 16, 2026
Fae Intelligence · Root Cause Analyzer
How we handle your data
Plain-English summary. See the Privacy Policy and Terms for the formal versions — if anything here differs from those documents, they control.
Your data is yours
You own the problem details, documents, and investigation content you put into the tool. We act as a processor of that data on your behalf — we don't claim ownership of it. You also own the reports generated from it (you're responsible for reviewing and approving them before use — see the Terms).
We do not train AI models on your data
Your investigation content and uploaded documents are not used to train AI models — not by us, and not by the AI provider. The AI model (Anthropic's Claude) is accessed via its commercial API, which under our agreement with Anthropic does not use submitted data to train models.
Where your data lives
Investigation data is stored in Google Cloud (Firebase / Firestore) in the United States. Investigation text is processed by Anthropic's Claude API to generate guidance and reports.
Who processes your data (sub-processors)
- Anthropic — provides the Claude AI model that powers the investigation. Processes your investigation content (problem descriptions, answers, uploaded document content) in the United States. Active. Anthropic's privacy policy.
- Google Cloud / Firebase — hosting and data storage for everything the service keeps (investigations, documents, account details, logs), in the United States. Active. Google Cloud privacy.
- Resend — delivers our emails, like sign-in links. Handles your email address and delivery details (sent, bounced, etc.), in the United States. Active. Resend's privacy policy.
- SendGrid (Twilio) — backup email delivery, used only if Resend is unavailable. Would handle the same email address and delivery details, in the United States. Contingency only. Twilio's privacy policy.
- Stripe — payment processing, once payment features are enabled (they are not yet). Will handle your payment and transaction details in the United States; your card number goes to Stripe directly and is never stored by us. Stripe's privacy policy.
We do not sell your data. Beyond these sub-processors, we share data only if the law requires it (e.g., a valid court order) or in a business transfer such as a merger — see the Privacy Policy for details.
Security
Data is encrypted in transit (HTTPS) and at rest (provided by Google Cloud). Access to stored data is limited to authorized personnel and systems that need it to operate and support the service.
Retention and deletion
We retain your investigations so you can return to them. You can request deletion at any time by contacting us — we delete investigations and uploaded documents within 30 days of a verified request (backup copies may persist up to 90 days before being purged).
What a deletion request involves:
- It's verified and in writing. We confirm the request came from you (or someone authorized by your organization) before deleting anything.
- Export first. We offer you an export of your investigations before deleting. Deletion is permanent — once done, neither you nor we can get the content or its reports back.
- Your record-keeping stays your responsibility. The tool is not your system of record. If your quality system or a regulation requires you to keep investigation records, deleting them here doesn't change that obligation.
- We keep a record of the request itself. After deletion we retain the deletion request, our confirmation that we carried it out, your terms acceptance and sign-off records, and purchase records — but none of your investigation content.
- Disputes pause deletion. If the data is under a legal hold or tied to a known or reasonably anticipated dispute, we hold off on deleting until that is resolved, and we'll tell you if that applies.
What you should not upload
- Only upload data you are authorized to share.
- Avoid personal data (PII) or protected health information (PHI) unless you have confirmed it is permitted — you can anonymize documents before uploading.
Data Processing Agreement
A Data Processing Agreement (DPA) is available on request for organizations that require one.
Contact
Questions about your data: rsnyder@faeintelligence.com.