Shouldrs
Home Product About Getting Started Contact
Get in touch
Legal

Shouldrs, Inc. — Privacy Policy

Effective Date: August 4, 2026 • Last Updated: August 4, 2026 • Version 2.0

Applies to www.shouldrs.com and the Shouldrs AI operations platform

Shouldrs, Inc. ("Shouldrs," "we," "our," or "us") builds an AI operations system that helps businesses run their day-to-day work across multiple artificial intelligence models and connected business applications. This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, how long we keep it, and the choices and rights you have.

This Policy applies to our website at www.shouldrs.com, our marketing and sales activities, and our hosted software platform and related services (together, the "Service"). It does not apply to third-party products or websites that you connect to or reach through the Service, which are governed by their own privacy policies.

Summary of Key Points

This summary is provided for convenience only. It is not a substitute for the full Policy below.

TopicIn short
Do you train AI on our data?No. We do not use Customer Content to train, fine-tune, or improve any artificial intelligence or machine learning model, ours or a third party's. We contractually require our AI model providers to do the same. Anonymized, aggregated data that is no longer Customer Content may be used to train and improve our models and the Service; see Sections 4.2 and 4.4.
Do you sell our data?No. We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising, as those terms are defined under U.S. state privacy laws. See Section 7.1.
Who can see our content?Access is restricted to authorized personnel and only in the limited circumstances described in Section 4.5 — with your authorization, to meet a legal obligation, to address a security or fraud incident, or to enforce our agreements.
What is your role?For our website, marketing, and account administration, we act as a controller. For the business data our customers put into the Service, we act as a processor and service provider on the customer's instructions. See Section 1.
Where is data processed?In the United States, on cloud infrastructure operated by Amazon Web Services and other similar U.S. cloud providers, plus the AI model providers and other subprocessors described in Section 4.3.
What about text messages?Your mobile number and SMS consent are never shared with third parties or affiliates for marketing or promotional purposes, and are never sold. We send no marketing texts. Reply STOP to opt out, HELP for help. See Section 7.2.
How do we reach you?[email protected]. See Section 11 for rights requests and Section 17 for all contact routes.

1. Scope of This Policy and Our Role

1.1 Two different roles

Shouldrs handles personal information in two distinct capacities, and different parts of this Policy apply to each.

  • Shouldrs as controller / business. When you visit our website, request a demo, correspond with our sales or support teams, create an account, or pay for a subscription, we decide why and how that information is used. We are the "controller" (under laws that use that term) or "business" (under California law) for that information. Sections 2, 3, 6, and 7 through 17 govern this information.
  • Shouldrs as processor / service provider. When a business customer uses the Service, that customer uploads, connects, or generates business data — documents, records, messages, workflow instructions, and data drawn from connected applications (collectively, "Customer Content"). Customer Content may contain personal information about the customer's own employees, clients, vendors, and contacts. Shouldrs processes Customer Content to deliver the Service, on the customer's instructions and as set out in the customer's agreement with us and in this Policy, and for no other purpose. The customer is the controller or business for that information; we are its processor or service provider.

1.2 If your employer uses Shouldrs

If you are an employee, contractor, client, or contact of a business that uses the Service, that business — not Shouldrs — determines what information is placed into the Service and how it is used. Direct requests to access, correct, or delete that information to that business in the first instance. If you contact us directly, we will refer your request to the relevant customer and will assist that customer in responding, as required by applicable law and our contract with them.

1.3 Data Processing Agreement

Business customers that require a data processing agreement, a subprocessor notification commitment, or (where applicable to their operations) cross-border transfer terms may request them at [email protected]. Where a customer has executed an order form and our Master Terms with us (together, the "Customer Agreement"), or a data processing agreement, those documents govern our processing of that customer's Customer Content and prevail over this Policy to the extent of any conflict. This Policy applies to the extent it is consistent with them and addresses matters they do not.

2. Information We Collect

2.1 Information you provide to us

  • Identity and contact data — name, business email address, telephone number, job title, company name, and mailing address.
  • Account and authentication data — username, credentials (stored only in hashed, salted form), authentication tokens, multi-factor authentication settings, and role or permission assignments.
  • Billing data — billing contact, billing address, subscription tier, purchase history, and tax identifiers. Payment card numbers are collected and stored by our payment processor, not by Shouldrs.
  • Support and communications data — the content of your messages to us, support tickets, demo and sales correspondence, and survey or feedback responses.
  • Preference data — marketing preferences, communication settings, and configuration choices such as approval rules, tone and style preferences, and business policies you ask the Service to apply.
  • Mobile telephone number and SMS consent data — where you choose to use the Service by text message, the mobile telephone number you provide, the record and date of your opt-in, any opt-out request, and the content and delivery status of text messages exchanged with the Service. See Section 7.2.

2.2 Customer Content

Customer Content is the business data a customer places into or connects to the Service, including uploaded documents and templates, knowledge-base material, workflow definitions and instructions, prompts and requests submitted to the Service, data retrieved from connected third-party applications, and the outputs the Service generates. Customer Content may include personal information about individuals other than the account user. We process Customer Content as described in Section 1.1.

2.3 Information collected automatically

  • Usage data — features used, workflows and tasks executed, models and tools invoked, timestamps, session duration, task volume, error events, and interactions with our website.
  • Device and technical data — IP address, browser type and version, operating system, device identifiers, language settings, and referring and exit pages.
  • Cookies and similar technologies — as described in Section 8.
  • Security and audit logs — authentication events, administrative actions, permission changes, approval decisions, and the per-action audit records the Service maintains so customers can review what the Service did on their behalf.

2.4 Information from third parties

  • Connected applications — where you authorize an integration, we receive data from that application in accordance with the permissions you grant. See Sections 5 and 6.
  • Identity providers — where you sign in through a third-party identity provider such as Google, we receive the profile information described in Section 6.
  • Business sources — publicly available business information and information from business-contact data providers, marketing partners, resellers, and event hosts, used for sales and marketing to businesses.

2.5 Sensitive personal information

Shouldrs does not seek, and the Service is not designed to be used to process, sensitive personal information about consumers. We do not use or disclose sensitive personal information for any purpose other than those permitted without an opt-out under applicable law — namely, performing the Service, ensuring security and integrity, and complying with law. We do not collect biometric identifiers, neural data, precise geolocation, or government identification numbers about website visitors or account users, and we do not use any such data to infer characteristics about an individual.

Our customer agreements prohibit customers and their Users from uploading or transmitting sensitive personal data — including personal health information — to the Service, and the Service is not designed or intended to receive it. Customers are responsible for enforcing that restriction within their organizations, for the accuracy and legality of what they submit, and for providing any notices and obtaining any consents required for the data they do submit. Customers should not submit restricted categories of data — including protected health information subject to HIPAA, cardholder data subject to PCI DSS, information subject to the Gramm-Leach-Bliley Act or FERPA, biometric identifiers, classified or export-controlled information, and information about children under thirteen (13) — unless we have agreed in writing to receive it under appropriate terms.

2.6 Categories of personal information collected (California disclosure)

In the preceding twelve months, we have collected the following categories of personal information, as those categories are defined by the California Consumer Privacy Act.

Category (CCPA)CollectedBusiness purposeDisclosed to
Identifiers (name, email, telephone number, IP address, account ID)YesAccount creation, service delivery, support, billing, security, and marketing to business contacts. Mobile numbers provided for text messaging are used only to operate the messaging program — never for marketing — as set out in Section 7.2Cloud hosting, email, CRM, analytics, payment, support providers. Mobile numbers and SMS consent data go only to our messaging service provider and cloud infrastructure providers
Customer records (billing contact, company details)YesContracting, billing, tax, account administrationPayment processor, accounting and tax providers
Commercial information (subscription, purchase and usage history)YesBilling, plan administration, product analytics, ROI reportingPayment processor, analytics providers
Internet and network activity (usage, device, log data)YesService operation, troubleshooting, security, product improvementCloud hosting, analytics, security providers
Professional or employment information (job title, employer, role)YesAccount provisioning, role-based access, B2B marketingCRM and marketing providers
Inferences (product interest, feature usage patterns)LimitedProduct analytics and customer success; not used for profiling with legal or similarly significant effectsAnalytics providers
Sensitive personal informationNo — see Section 2.5Not applicableNot applicable
Biometric, geolocation, education records, audiovisual (other than support recordings you consent to)NoNot applicableNot applicable

3. How We Use Personal Information

We use personal information for the following purposes, and for no incompatible purpose without providing notice.

PurposeWhat this meansLegal basis (where applicable)
Provide and operate the ServiceAuthenticate users, execute workflows, route tasks to AI models and connected tools, deliver outputs, maintain audit logsPerformance of a contract
Support and account managementRespond to requests, troubleshoot, onboard and train users, manage subscriptions and renewalsPerformance of a contract; legitimate interests
Billing and financial administrationInvoice, collect payment, calculate overage, manage taxes, prevent payment fraudPerformance of a contract; legal obligation
Security, integrity, and abuse preventionDetect and investigate unauthorized access, fraud, abuse, and violations of our agreements; maintain backups and recoveryLegitimate interests; legal obligation
Product improvement and analyticsUnderstand aggregate feature usage, reliability, performance, and cost, and improve the Service. Performed on usage and technical data and on de-identified or aggregated data — not by training models on Customer ContentLegitimate interests
Communications about the ServiceSend administrative, security, billing, and change noticesPerformance of a contract; legal obligation
Marketing to businessesSend product news and offers to business contacts, with an unsubscribe link in every messageLegitimate interests; consent where required
Legal compliance and defenseMeet legal, tax, audit, and regulatory obligations; establish, exercise, or defend legal claimsLegal obligation; legitimate interests

Legal bases are identified for the benefit of individuals in jurisdictions whose law uses that concept. Shouldrs presently processes personal information in the United States and does not currently market the Service in the European Economic Area, the United Kingdom, or Switzerland.

4. Artificial Intelligence and Your Data

Because the Service is built on artificial intelligence, this section describes in specific terms how AI processing works and what we do and do not do with your data. It is provided in part to satisfy state privacy-law requirements, including Connecticut's requirement that a privacy notice disclose whether personal data is collected, used, or sold to train large language models.

4.1 How the Service uses AI

When a user submits a request, the Service plans the steps needed to complete it and routes each step to the artificial intelligence model and connected tool best suited to that step, balancing quality, speed, and cost. Doing so requires transmitting the relevant portion of the request and any necessary Customer Content to one or more third-party AI model providers for processing, and returning the result to the user. Model selection may change over time as models and pricing change.

4.2 We do not train AI models on Customer Content

Shouldrs does not use Customer Content, prompts, outputs, or any personal information contained in them to train, fine-tune, retrain, or otherwise develop or improve any large language model, machine learning model, or other artificial intelligence system, whether our own or a third party's. We do not sell, license, or otherwise make Customer Content available to any party for AI or machine learning training purposes. This commitment covers Customer Content and the personal information in it. It does not restrict our use of anonymized, aggregated data that is no longer Customer Content, as described in Section 4.4.

We contractually require the AI model providers we use to process our traffic on a no-training basis with zero or strictly limited retention, meaning that they may not use the content we transmit to them to train or improve their models and may retain it only for the period, if any, necessary for abuse monitoring under their terms. Where a provider's standard terms would permit training, we use the enterprise, API, or opt-out configuration that disables it, and we do not route Customer Content to any provider that will not commit to this.

4.3 AI model providers and subprocessors

We engage the following categories of subprocessor. A current list of named subprocessors is available on request at [email protected], and business customers may request advance notice of new subprocessors under a data processing agreement.

CategoryFunctionData involved
Cloud infrastructureHosting, storage, compute, backup, and tenant isolation for the Service. Amazon Web Services and other similar U.S. cloud providers, United States regionsAll categories, encrypted at rest and in transit
AI model providersExecute the reasoning, drafting, and analysis steps of a workflow, under no-training terms with zero or strictly limited retentionThe portions of prompts and Customer Content necessary for the requested task
Connected business applicationsApplications you authorize the Service to read from or act in on your behalfOnly the data covered by the permissions you grant
Payment processingSubscription billing and payment card handlingBilling contact and payment data (card data held by the processor)
Analytics and product telemetryAggregate usage, reliability, and performance measurementUsage, device, and technical data
Communications and supportTransactional email, marketing email, support ticketingIdentity and contact data, support correspondence
Text messagingTransmit SMS messages to and from users who have opted in to the messaging programMobile telephone number and message content only; never used for marketing (see Section 7.2)
Security and monitoringLogging, threat detection, vulnerability managementSecurity and audit log data

All subprocessors are bound by written agreements requiring them to process personal information only on our instructions, to apply appropriate security measures, and to comply with the same restrictions we accept in this Policy — including, for any subprocessor with access to Google user data, the Google API Services User Data Policy and its Limited Use requirements.

4.4 De-identified and aggregated data

We may create and use de-identified and aggregated data derived from use of the Service — for example, statistics on task volume, model performance, cost per task, workflow reliability, and industry benchmarks. To qualify, data must be stripped, using industry best practices, of every characteristic that would identify any individual, customer, user, or connected account; must contain no confidential or proprietary information and no customer intellectual property; and must consist of generalized information about business behavior and operations. We maintain it in de-identified form, do not attempt to re-identify it, and contractually require the same of any recipient.

We use de-identified and aggregated data to operate, secure, analyze, and improve the Service and our other products and services — including to train, tune, and improve the algorithms, routing logic, and machine learning models and systems underlying them — and to produce industry benchmarks. Because this data is no longer Customer Content and cannot be traced to any customer or individual, this use does not qualify the commitment in Section 4.2: Customer Content itself, and the personal information in it, is never used to train or improve any model.

Where a customer's agreement with us defines anonymized or de-identified data, or the permitted uses of it, that agreement controls.

4.5 Human access to your data

Shouldrs personnel and contractors do not read Customer Content, including any Google user data, except in these circumstances:

  • you or your administrator explicitly authorizes access to specific items, for example to resolve a support request;
  • access is necessary to comply with a legal obligation or valid legal process;
  • access is necessary to detect, prevent, or respond to security incidents, fraud, abuse, or technical problems that we cannot resolve otherwise; or
  • access is necessary to enforce our agreements where we have a good-faith basis to believe they have been violated.

Access under these exceptions is limited to the minimum necessary, is restricted to authorized personnel under role-based controls, and is logged.

4.6 Automated decision-making and profiling

Shouldrs does not use automated decision-making technology to make decisions that produce legal or similarly significant effects concerning an individual — including decisions about financial or lending services, housing, insurance, education enrollment or opportunity, employment or independent contracting opportunities or compensation, healthcare services, or essential goods and services. We do not engage in profiling in furtherance of such decisions, and we do not use personal information to infer characteristics about individuals for those purposes.

The Service is a general-purpose tool. If a customer configures the Service to assist with a decision of that kind, the customer is responsible for the resulting processing, for providing any pre-use notice, opt-out, explanation, and appeal rights the law requires, and for maintaining meaningful human review. Our Customer Agreement restricts such uses.

5. Third-Party Integrations You Authorize

The Service connects to third-party business applications through the Model Context Protocol and similar interfaces so that it can read information and take actions on your behalf. These connections are established only when you or your administrator authorizes them, and only within the scope of the permissions granted at the time of authorization. We request the minimum permissions necessary for the feature you have enabled.

Information we obtain through an authorized integration is used only to deliver the Service to you. It is not used for advertising, sold, or disclosed for any purpose unrelated to your instructions. You may revoke an integration at any time in your Shouldrs account settings or in the third-party application. Upon revocation, we cease accessing that application and delete data retrieved from it in accordance with Section 10, unless retention is required by law or the data has become part of a record you have asked us to keep.

Each connected application remains governed by its own terms and privacy policy. We are not responsible for the privacy practices of applications you choose to connect.

6. Google User Data and Limited Use

Shouldrs integrates with Google services for authentication and, where you authorize it, for workflow automation.

  • Google Sign-In. We access your name, email address, and profile picture solely to authenticate you and to operate your account.
  • Other Google services. We do not access Google Drive, Gmail, Calendar, or other Google account data unless you explicitly grant access for a specific feature, and we request only the minimum scopes necessary for that feature.

Limited Use. Shouldrs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we will not:

  • transfer or sell Google user data to third parties, advertising platforms, data brokers, or information resellers;
  • use Google user data for serving advertisements, including retargeted, personalized, or interest-based advertising;
  • use Google user data to determine creditworthiness or for lending purposes;
  • use Google user data to train, fine-tune, or improve any generalized or non-personalized artificial intelligence or machine learning model; or
  • permit humans to read Google user data except in the limited circumstances described in Section 4.5.

Disconnecting. You may disconnect your Google account and delete associated Google user data at any time by (1) revoking access at myaccount.google.com/permissions, (2) using the disconnect feature in your Shouldrs account settings, or (3) emailing [email protected]. Following disconnection or a deletion request, we delete Google user data within thirty (30) days unless a longer period is required by law.

Consent and in-product disclosure. Before requesting access to your Google account data, we identify the specific data requested, explain why it is needed and how it will be used, link to this Policy, and request your explicit consent. If our access to or use of Google user data materially changes, we will update this Policy and obtain renewed consent where required.

Incident reporting. If we experience a security incident affecting Google user data, we will notify the affected customer (through the administrative contact on the account), any affected individual with whom we hold the relationship directly, and Google, promptly and as required by applicable law and Google's policies.

7. How We Disclose Personal Information

We disclose personal information only as described below.

  • Service providers and subprocessors — the categories listed in Section 4.3, each under a written contract limiting their use of the information to providing services to us.
  • Within your organization — administrators of your Shouldrs account can access account, usage, and audit information for users in their organization, and can access Customer Content within the permissions their organization has configured.
  • Third-party applications you connect — as directed by you, when you authorize an integration or instruct the Service to take an action in a connected application.
  • Professional advisors — attorneys, accountants, auditors, and insurers, under duties of confidentiality.
  • Corporate transactions — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to confidentiality protections and continued application of this Policy or a materially equivalent policy. A successor in such a transaction remains bound by the mobile-information commitment in Section 7.2.
  • Legal and safety — where we believe in good faith that disclosure is required by law, subpoena, court order, or other valid legal process, or is reasonably necessary to protect the rights, property, or safety of Shouldrs, our customers, or the public. Where we are legally permitted to do so, we will notify the affected customer before disclosing Customer Content in response to legal process, and we will seek to redirect the request to the customer.
  • With your consent — for any other purpose disclosed to you at the time consent is requested.

7.1 We do not sell or share personal information

Shouldrs does not sell personal information, and does not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under the California Consumer Privacy Act and other U.S. state privacy laws. We have not sold or shared personal information in the preceding twelve months, including personal information of individuals we know to be under sixteen years of age.

7.2 Mobile information and SMS consent

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, and are not sold, rented, or licensed to anyone.

If you choose to use the Service by text message, we collect and use your mobile telephone number, your SMS consent record, and the content of messages you exchange with the Service solely to operate the messaging program described in our SMS Messaging Terms at https://www.shouldrs.com/terms — that is, to deliver the messages you request, to send the account and workflow notifications you have opted into, to honor your opt-out, to provide customer care, and to keep records demonstrating your consent.

We disclose mobile telephone numbers and message content only to the vendors that operate the messaging program on our behalf — our messaging service provider and our cloud infrastructure providers — solely so that they can transmit messages for us, and only under written contracts that prohibit them from using the information for any other purpose. We also disclose this information where required by law or valid legal process. We do not send marketing or promotional text messages, we do not use the messaging program to advertise, and we do not send text messages on behalf of any third party. We do not use the content of text messages to train or improve any artificial intelligence or machine learning model. If we are ever party to a merger, acquisition, or sale of assets, any successor will remain bound by this Section 7.2.

How to stop. Reply STOP — or END, CANCEL, UNSUBSCRIBE, or QUIT — to any text message from us to opt out at any time. Reply HELP or INFO to any text message for help, or START to rejoin. You may also turn off SMS in your Shouldrs account settings, or contact us using the customer care details in our SMS Messaging Terms or at [email protected]. Consent to receive text messages is not a condition of purchase or of using the Service, and every function available by text message is also available through the Shouldrs web application, Slack, and email. Message and data rates may apply; message frequency varies.

8. Cookies, Analytics, and Tracking

We use cookies and similar technologies on our website and in the Service.

TypePurposeCan you disable it?
Strictly necessaryAuthentication, session management, load balancing, security, and fraud preventionNo — the Service will not function without these
PreferenceRemember your settings, language, and interface choicesYes, through your browser settings
Analytics and performanceMeasure aggregate usage, page performance, and errors so we can improve the ServiceYes, through your browser settings, a universal opt-out signal, or a request to [email protected]

We may use Google Analytics or Google Tag Manager for performance analysis. We do not use advertising cookies, we do not participate in cross-context behavioral advertising, and we do not disclose personal information to advertising networks or data brokers.

8.1 Universal opt-out signals and Global Privacy Control

We honor the Global Privacy Control and other browser- or device-based universal opt-out preference signals recognized under applicable state law. When we detect such a signal from your browser or device, we treat it as a valid request to opt out of any sale or sharing of personal information and of targeted advertising for that browser or device. Because opt-out preference signals are tied to a browser or device, they must be enabled on each browser and device you use. Information on enabling the Global Privacy Control is available at globalprivacycontrol.org.

8.2 Do Not Track

Browser "Do Not Track" headers have no uniform industry standard, and we do not respond to them. We do respond to universal opt-out preference signals as described in Section 8.1.

9. Data Security

We maintain an information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Current measures include:

  • encryption of data in transit using TLS and of data at rest;
  • logical tenant isolation, so each customer's data is segregated from every other customer's;
  • role-based access control, least-privilege provisioning, and mandatory multi-factor authentication for personnel with access to production systems;
  • a controlled deployment pipeline with automated testing and rollback;
  • centralized logging, security monitoring, vulnerability management, and periodic penetration or vulnerability testing;
  • per-action audit logging within the Service, so customers can review what actions were taken on their behalf and by whom;
  • encrypted, access-controlled backups and documented recovery procedures;
  • background-screened personnel bound by confidentiality obligations and required security training; and
  • a documented incident response plan, tested periodically.

Incident notification. If we determine that a security incident has compromised personal information, we will notify affected customers and, where required, affected individuals and regulators, without undue delay and within the timeframes required by applicable law. Notification to a business customer is made to the administrative contact on the account.

No system is perfectly secure. We encourage you to use strong, unique passwords, enable multi-factor authentication, restrict administrative privileges, and promptly notify us at [email protected] of any suspected compromise of your account.

10. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, or as required by law. Our standard periods are:

DataRetention period
Account and contact dataFor the life of the account, then up to twenty-four (24) months after closure
Customer ContentFor the life of the account. Available for export for thirty (30) days after termination (subject to the applicable Customer Agreement), then deleted as described under "Deletion requests" below. Where a customer agreement specifies different export or deletion terms, that agreement controls
Usage and technical dataUp to twenty-four (24) months, then deleted or irreversibly de-identified
Security and audit logsUp to eighteen (18) months in the live production environment and up to seven (7) years in archived storage, used only for security, audit, compliance, legal, dispute-resolution, and regulatory or certification purposes (including SOC 2 and comparable frameworks). Longer where required by law or subject to a legal hold
Data retrieved through an IntegrationDeleted within thirty (30) days after the customer revokes the Integration, unless it has become part of a record the customer has asked us to keep
Google user dataDeleted within thirty (30) days of disconnection or a deletion request; otherwise retained on the same schedule as other Customer Content
Billing, tax, and transaction recordsSeven (7) years, as required by tax and accounting rules
Marketing contact dataUntil you unsubscribe or request deletion, plus a suppression record retained indefinitely so we can honor your opt-out
SMS consent and opt-out recordsFor the life of the account and four (4) years after the last message, as evidence of consent. An opt-out (STOP) record is retained indefinitely so we can honor it
SMS message contentHandled as Customer Content on the schedule stated above
De-identified and aggregated dataRetained indefinitely in de-identified form
BackupsPurged on a rolling cycle not exceeding ninety (90) days

Deletion requests. Upon a valid deletion request, we begin removing data within thirty (30) days and complete deletion from active production systems within ninety (90) days. Residual copies in encrypted backups are purged on their normal rolling cycle, which does not exceed ninety (90) days after deletion from active systems, and are not restored to active use in the interim. Deletion may be delayed only where retention is required by law, necessary to establish or defend legal claims, or necessary to complete a transaction you requested. Data on legal hold is retained until the hold is released. This Section does not apply to the security and audit records described in the table above, which we may retain on the schedule stated there and in customer agreements notwithstanding termination or a deletion request, or to de-identified and aggregated data under Section 4.4.

11. Your Privacy Rights

11.1 Rights available to you

Depending on where you live, you may have some or all of the following rights. We extend the core rights below to all U.S. residents regardless of state, as a matter of practice.

RightWhat it means
Know / AccessConfirm whether we process personal information about you and obtain a copy, including the categories collected, sources, purposes, and categories of recipients
CorrectCorrect inaccurate personal information we maintain about you
DeleteRequest deletion of personal information we collected from you, subject to legal exceptions
PortabilityReceive a copy in a portable, machine-readable format where technically feasible
Opt out of sale, sharing, and targeted advertisingWe do not engage in these activities; the right is preserved for you regardless
Opt out of profilingOpt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not conduct such profiling
Limit use of sensitive personal informationLimit our use of sensitive personal information to permitted purposes. We do not use it beyond those purposes
List of third partiesWhere state law provides (for example, Connecticut, Oregon, and Minnesota), obtain a list of the third parties or the categories of third parties to which we have disclosed your personal information
Non-discriminationExercise your rights without being denied service, charged a different price, or given a different level of quality, except that we may charge a reasonable fee for a request that is manifestly unfounded, excessive, or repetitive, as permitted by law and described in Section 11.3
AppealAppeal a denial of a rights request
Withdraw consentWithdraw any consent you previously gave, without affecting processing already carried out

11.2 How to exercise your rights

  • Email [email protected] with the subject line "Privacy Rights Request."
  • In-product — access and update most account information directly in your Shouldrs account settings.
  • Marketing — click the unsubscribe link in any marketing email, or email [email protected]. You cannot opt out of transactional and administrative email while you hold an account, but you can always stop text messages — see Section 7.2.
  • Integrations — revoke a connected application in your Shouldrs account settings or in the third-party application.
  • Export — obtain a portable, machine-readable copy of your account data and Customer Content through the export functionality in the Service, or by request to [email protected].
  • Text messages — reply STOP to any text message from us to stop receiving them, or HELP for help. See Section 7.2.

11.3 Verification, timing, and appeals

We will acknowledge your request promptly and respond within forty-five (45) days, and may extend that period once by an additional forty-five (45) days where reasonably necessary, with notice to you. To protect your information, we must verify your identity before acting; we generally do this by matching information you provide against information already in our records, and for sensitive requests we may require additional verification. We do not charge a fee for the first two requests in a twelve-month period, and may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive.

If we decline your request in whole or in part, we will explain why. You may appeal by replying to our decision or emailing [email protected] with the subject line "Privacy Rights Appeal." We will decide the appeal and inform you in writing within forty-five (45) days, including our reasoning. If the appeal is denied, we will provide a method to contact your state attorney general to lodge a complaint.

11.4 Authorized agents

You may use an authorized agent to submit a request. We require written proof of the agent's authority and, unless the agent provides a valid power of attorney, direct verification from you.

11.5 Requests about Customer Content

Where the personal information at issue is contained in Customer Content, Shouldrs acts as a processor and cannot act on the request directly. We will promptly route the request to the relevant customer and assist that customer in responding, as required by law and our contract with them. See Section 1.2.

12. State-Specific Disclosures

12.1 California

This Policy serves as our notice at collection and our full CCPA notice. The categories of personal information we collect, the purposes, and the categories of recipients are set out in Sections 2.6, 3, and 7; our retention periods are in Section 10; and our rights process is in Section 11. We do not sell or share personal information and we do not use or disclose sensitive personal information beyond the purposes permitted without an opt-out. California residents may also request information under California's "Shine the Light" law (Civil Code § 1798.83) by emailing [email protected]; we do not disclose personal information to third parties for their own direct marketing purposes.

12.2 Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia

Residents of states with comprehensive consumer privacy laws have the rights described in Section 11, including the right to appeal a denial. We recognize universal opt-out preference signals as described in Section 8.1. We do not sell personal data, do not process personal data for targeted advertising, and do not engage in profiling in furtherance of decisions producing legal or similarly significant effects. We do not collect or process sensitive data as defined by those laws except as incidental to Customer Content placed into the Service by our customers, in which case we act as a processor. Consistent with Connecticut law, we confirm that we do not collect, use, or sell personal data to train large language models.

Minnesota residents additionally have the right to obtain a list of the specific third parties to which we have disclosed their personal data, and to question the result of any profiling. Oregon residents may request a list of the specific third parties or the categories of third parties to which we have disclosed personal data. Requests may be sent to [email protected].

12.3 Nevada

Nevada residents may direct us not to sell certain covered information. We do not sell covered information as defined by Nevada Revised Statutes Chapter 603A, and we do not collect or process consumer health data as defined by Nevada Senate Bill 370.

12.4 Consumer health data

Shouldrs does not collect, process, sell, or share consumer health data as defined by the Washington My Health My Data Act, and does not use geofencing around any healthcare facility.

12.5 Texas

Shouldrs is not a small business as defined by the Texas Data Privacy and Security Act exemption, and complies with that Act. As stated above, we do not sell personal data, including sensitive personal data or biometric identifiers.

13. International Users and Data Transfers

Shouldrs is based in the United States and processes personal information on United States infrastructure. The Service is offered to businesses in the United States, and we do not currently target or market the Service to individuals in the European Economic Area, the United Kingdom, or Switzerland.

If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. If we begin offering the Service in jurisdictions requiring a transfer mechanism, we will implement an appropriate mechanism — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — appoint any required local representative, and update this Policy before doing so. Business customers requiring these terms today should contact [email protected].

14. Children's Privacy

The Service is a business product intended for use by organizations and by individuals eighteen (18) years of age or older. It is not directed to children, and we do not knowingly collect personal information from any Service user under eighteen (18). This Section addresses individuals who use the Service; it does not restrict Customer Content that a customer chooses to place into the Service, for which that customer is responsible under Section 1.1 and under its Customer Agreement. Consistent with the Children's Online Privacy Protection Act, we do not knowingly collect personal information from children under thirteen (13), and we do not permit the use of Google Sign-In or other Google services by users under thirteen.

If we learn that we have collected personal information directly from a Service user under eighteen, we will delete it promptly and revoke any associated third-party account access. If you believe a minor has provided us personal information, contact [email protected].

15. Third-Party Websites and Services

Our website and the Service may link to, or interoperate with, websites and services we do not control. This Policy does not apply to them. We encourage you to review the privacy policy of any third-party service before providing it with your information.

16. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. The current version is always posted at https://www.shouldrs.com/privacy with the effective date and version number at the top.

If we make material changes, we will provide notice by email to the address associated with your account, by prominent notice within the Service, or both, at least thirty (30) days before the changes take effect. If a material change affects how we access or use Google user data, or otherwise requires your consent under applicable law, we will obtain your renewed consent before the change applies to you. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated Policy, except where consent is required. Where a customer has a Customer Agreement with us, that agreement governs the customer's rights with respect to changes affecting the commercial relationship.

17. Contact Us

For questions, concerns, or privacy rights requests:

EntityShouldrs, Inc., a Delaware corporation
Privacy inquiries and rights requests[email protected]
Security incidents and vulnerability reports[email protected]
General inquiries[email protected]
Mailing address[email protected]
Websitehttps://www.shouldrs.com
This Policyhttps://www.shouldrs.com/privacy
Website and SMS Messaging Termshttps://www.shouldrs.com/terms

We are committed to resolving privacy concerns directly. If you are not satisfied with our response, you may lodge a complaint with your state attorney general or, for California residents, the California Privacy Protection Agency.

Accessibility. If you need this Policy in an alternative accessible format, contact [email protected] and we will provide one.

Shouldrs
Product About Getting Started Contact Privacy Terms
© 2026 Shouldrs, Inc. All rights reserved.
shouldrs.com  |  [email protected]