Who we are.
LatentFrame LLC is a New Jersey company that runs the LatentFrame research app. Contact: hello@getlatentframe.com, [mailing address: Kyle to confirm]. This policy covers:
-
people who use the app;
-
visitors to getlatentframe.com;
-
people we contact about LatentFrame;
-
people named in AI answers we collect.
For account data, our website and our outreach, we decide how data is used, which makes us the controller. When a customer enters personal data into its workspace, we handle it for that customer under our Terms and, where signed, a data processing agreement. [Lawyer: confirm this split.]
What we collect
-
Account details. Your email address, a user ID and sign-in times. If you use Google or Microsoft to sign in, they send us your name, email and basic profile. We never create or store a password for you.
-
Workspace details. The workspaces you belong to, your role, and invitation status and dates.
-
What you enter. Company name and website, competitors, questions, descriptions of your company and buyers, saved views and notes.
-
Research data. The questions we send to AI services, their answers, the sources they cite, and our analysis. Answers sometimes name real people, such as executives or authors.
-
Technical data. The app keeps your sign-in token and a display setting in your browser. The app itself does not log IP addresses. Our hosting and database providers keep standard server and sign-in logs that include IP addresses [retention to confirm].
-
Messages. Emails you send us.
-
Prospect details. For people we contact about LatentFrame: name, work email, job title and company, from public professional sources, plus our correspondence.
-
Billing details (once paid plans start). Billing contact, plan and invoices. Our payment provider handles card and bank details.
We use no advertising tools. The current marketing site loads Cloudflare Web Analytics; the new Pages preview contains no analytics scripts in its source. We don't sell personal data and don't ask for sensitive data. Please keep personal and confidential information out of free-text fields.
Why we use it, and our legal bases (EU/UK)
| What we do | Legal basis |
|---|---|
| Sign you in and run the service | Contract with your organization; legitimate interests for its users |
| Keep the service secure and control spending | Legitimate interests |
| Support and service emails | Contract; legitimate interests |
| Improve the service with aggregated information | Legitimate interests |
| Store AI answers that name people | Legitimate interests in studying how AI describes companies |
| Contact potential customers | Legitimate interests; consent where local law requires it |
| Billing, tax and legal records | Contract; legal obligation |
Who receives it
-
Our service providers, listed on our Subprocessors page. They may use the data only to serve us.
-
Public AI services. ChatGPT, Gemini and Google Search receive your question set through our collection provider, as ordinary signed-out queries with no account or name attached. They handle it under their own terms and may keep it or use it to improve their models.
-
AI model providers. OpenAI and Anthropic models, reached through OpenRouter, receive company descriptions and research data for analysis. We restrict these requests to providers that OpenRouter lists as not collecting request data. Zero data retention is not yet on for every request, so a provider may keep request data briefly for abuse monitoring [confirm periods, or switch it on]. We do not use your data to train AI models.
-
Your email address and name are never sent to any AI service.
-
Google or Microsoft, if you sign in with them, under their own privacy terms.
-
Others. Advisers; authorities where law requires; a buyer if the business is sold, under the same protections.
How long we keep it
[No periods are approved yet. These are proposals.]
-
Account and workspace data: while the account is open, plus [30] days.
-
Research data: while the workspace exists, plus [30] days.
-
Backups: up to [35] days [to confirm].
-
Billing and tax records: [7] years.
-
Prospect data: until you opt out, or [24] months after last contact. If you opt out, we keep a minimal do-not-contact record.
Security.
Each workspace's data is kept separate. The app checks membership on every request, and database rules add a second barrier. Provider keys stay on our servers, and the app loads no third-party scripts. Data is encrypted in transit [and at rest by our providers, to confirm]. We hold no security certification. If a breach affects your data, we will tell affected customers without undue delay.
Your rights.
Depending on where you live, you can ask us to:
-
show you your data;
-
correct it;
-
delete it;
-
export it;
-
stop or limit our use of it.
Email hello@getlatentframe.com with "Privacy request". We verify requests through your account email and reply within 30 days. If you use LatentFrame through your employer's workspace, we may involve the workspace owner. If you are named in an AI answer we stored, you can ask us to hide or remove it. EU and UK residents may complain to their data protection authority. We do not sell or share personal data for targeted advertising. [Lawyer: confirm which US state laws apply. Most have revenue or volume thresholds LatentFrame does not yet meet.]
Cookies.
-
The app sets no cookies.
-
It uses your browser's local storage for your sign-in token and your last filter choice. It uses session storage for a one-time key that prevents duplicate submissions. These are needed for the app to work, so there is no consent banner.
-
There are no analytics, advertising or tracking cookies.
-
The app loads its fonts from Google Fonts, so Google receives your IP address and browser details.
-
The marketing site is being moved from Cloudflare Workers to Cloudflare Pages. The new site serves fonts locally and contains no analytics scripts or cookie-setting code. The current live site loads Cloudflare Web Analytics; verify the final Cloudflare configuration before publication.
International transfers.
We are based in the US, and the app runs on US servers (Render, Ohio region; database in North Virginia, us-east-1). Data from the EU, UK or Switzerland is transferred to the US. For those transfers we rely on the EU Standard Contractual Clauses with the UK Addendum, or on providers' EU-US Data Privacy Framework certification [confirm for each provider]. Bright Data is based in Israel [confirm contracting entity], which has an EU adequacy decision.
Children.
The service is for business use and is not directed at anyone under 16.
Changes.
We post updates here and email account holders before material changes take effect.
Contact.
LatentFrame LLC, [mailing address: Kyle to confirm], hello@getlatentframe.com. [Lawyer: whether an EU or UK representative is required.]