Privacy Policy
Effective date: August 9, 2026
1. Introduction
Calibrant is operated by Trees and Rain, LLC ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Calibrant platform at calibrant.ai, including all associated services, APIs, and integrations (collectively, the "Service").
By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access the Service.
2. Information We Collect
Account Information
When you create an account, we collect your email address, display name, and organization name. Accounts are created through Supabase Auth, and we support Microsoft (Entra ID) and Google single sign-on (SSO) for authentication. Whichever provider you choose authenticates you and returns your email address, name, and profile picture URL to us. We do not collect or store your Microsoft or Google password, and we do not request access to any other service from either provider.
Service Data
As you use Calibrant, we store data you create and configure within the platform, including:
- Workspace, team member, and role configuration
- Relay deployment registration and status
- Scan results, findings, and assessment scores
- Control attestations, rule overrides, and their change history
Usage Data
We record the operational usage needed to provide account features and enforce limits, such as scheduled-run state and daily AI narrative counts. Tenant scans are not metered. We do not use this operational state to track which pages you visit or how you move through the site.
Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We retain Stripe references and subscription state needed to manage access, reconcile billing events, and show billing status.
Analytics Data
None. Calibrant runs no product analytics and no third-party tracking of any kind. There is no analytics SDK in the application, so nothing records which pages you view, and no behavioural data about you leaves your browser. If we introduce analytics in future we will update this policy and its effective date before doing so.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate your identity and manage your account and subscription
- Connect to your Microsoft 365 environment to run configuration and security assessments
- Process transactions and send billing-related communications
- Respond to support requests and communicate important service updates
- Detect, prevent, and address technical issues or abuse
We do not sell your personal information. We do not use your data for advertising purposes. We do not train AI models on your tenant configuration, findings, or assessment results.
4. Data Storage & Security
Your data is stored in Supabase, hosted on Amazon Web Services (AWS) in the US West (Oregon, us-west-2) region. We implement the following security measures:
- Encryption in transit: Supported connections between your browser, the relay, and our service use HTTPS/TLS.
- Encryption at rest: Our database provider encrypts stored database data and managed backups at rest.
- Credential minimization: Calibrant does not retain the delegated Microsoft OAuth token used by the optional tenant-identity connection. Relay API keys are shown once; Calibrant stores a one-way hash used to verify later relay requests.
- Tenant isolation: Customer-facing data uses database row-level controls, column restrictions, and server-only write paths. Private operational tables are not exposed to browser accounts.
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
5. Third-Party Services
We integrate with the following third-party services to operate Calibrant. Each service receives only the data necessary to perform its function:
- Microsoft — The optional Microsoft 365 connection uses a delegated OAuth token once to read the organization name and directory ID, then discards that token. Tenant scans are separate: they run through a customer-deployed relay and a Managed Identity in the customer's Azure subscription. Microsoft (Entra ID) is also one of our two sign-in providers; if you sign in with Microsoft, it authenticates you and returns your email address, name, and profile picture URL.
- Google — Our second sign-in provider. If you choose to sign in with Google, Google authenticates you and returns your email address, name, and profile picture URL to us. We request basic profile and email access only, we never receive your Google password, and we do not access Gmail, Drive, or any other Google service. If you sign in with Microsoft instead, Google receives nothing.
- Anthropic — Used for AI-powered analysis in two places. Tenant Healthcheck and Security Baseline send scan and assessment metadata only — rule and control identifiers, titles, categories, severities, pass/fail status, and numeric scores. Findings text, attestation notes, collected configuration, administrator names, and your domain names are not sent. The weekly insights summary sends score history and category names only. Calibrant has not opted these API inputs into model training. Anthropic's current commercial policy says API inputs and outputs are not used for training by default and are normally deleted from its backend within 30 days, subject to its safety, legal, and separately agreed exceptions.
- Stripe — Handles all payment processing, including credit card storage, subscription billing, and invoicing. We share your email and organization name with Stripe to create and manage your billing account. Stripe is PCI DSS Level 1 certified.
- Supabase — Provides our database, authentication, and managed database backups. Application records are stored in Supabase. Supabase is SOC 2 Type II compliant.
- Vercel — Hosts the Calibrant web application. Vercel processes HTTP requests and may log IP addresses and request metadata for security and performance purposes.
6. Cookies & Analytics
Calibrant uses a minimal approach to cookies and tracking:
- Authentication cookies: We use essential cookies to maintain your login session. These are strictly necessary for the Service to function and cannot be disabled.
- No analytics or tracking: Calibrant runs no analytics SDK, so nothing writes analytics cookies, local storage, or session storage to your device, and nothing recognizes you on a return visit or across websites. We do not fingerprint your browser.
- No advertising cookies: We do not use any third-party advertising or remarketing cookies. We do not participate in ad networks or serve targeted advertisements.
7. Data Retention
We retain your data according to the following guidelines:
- Account data: Retained while your account is active. An owner-confirmed workspace deletion begins immediately: Calibrant cancels the linked subscription, removes live workspace data, and removes the workspace members' Calibrant sign-in accounts. If an identity-provider deletion cannot finish immediately, a private retry record retains only the identifiers and bounded status needed to finish it. We do not offer a 30-day undo window.
- Assessment scores and trends: Scan-level results from Healthcheck and Security Baseline — overall scores, category scores, and finding counts — are retained for the life of your account so that posture trends remain complete. You may delete individual scans at any time from within the application.
- Assessment finding detail: Per-rule findings for each scan — the result, description, and remediation guidance — are retained for 14 days when there is no active subscription, 60 days on Essential, and 2 years on Pro. Findings from your most recent completed scans are always retained while your account is active.
- Raw scan output: Configuration data collected from your Microsoft 365 tenant — the unprocessed scan output and the evidence payloads attached to individual findings — is retained according to your subscription tier, up to a maximum of 90 days, and is then deleted automatically.
- Credentials: Relay credential hashes are deleted when the relay deployment or workspace is deleted. The optional delegated Microsoft connection token is discarded after its one organization lookup and therefore has no later retention period in Calibrant.
- Analytics data: None is collected, so none is retained.
- Billing records: Transaction and invoice records are retained by Stripe in accordance with financial reporting requirements. We retain subscription status records for the duration of your account.
- Backups: Deleted live database records may remain in provider-managed daily backups until those backups expire under the configured backup-retention window. Backups are used for disaster recovery and are not a customer-accessible deletion undo feature.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Export: Request a machine-readable export of your data.
- Restriction: Request that we limit how we process your data in certain circumstances.
- Objection: Object to our processing of your personal data where we rely on legitimate interest as our legal basis.
To exercise any of these rights, please contact us at the address listed in Section 12 below. We will respond to your request within 30 days.
9. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will promptly delete such information from our systems.
10. International Users
Calibrant is operated from the United States, and our data is hosted in AWS us-west-2 (Oregon). If you access the Service from outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your data to the United States.
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data protection laws, you may have additional rights under applicable law. We process your data based on your consent (provided at account creation) and our legitimate interest in operating the Service. You may withdraw your consent at any time by deleting your account.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by updating the "Effective date" at the top of this page and, where appropriate, by sending you an email notification or displaying a notice within the Service.
We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
12. Contact Information
If you have any questions about this Privacy Policy, your personal data, or would like to exercise your data rights, please contact us:
Trees and Rain, LLC
Email: privacy@calibrant.ai
Website: calibrant.ai