applicable.ai
Product AI Agents Regulatory Coverage Regulatory Sources Resources
Coming Soon Get Notified Sign In

Draft, pending attorney review — not yet in effect. AI-drafted, not reviewed by a licensed attorney. Highlighted VERIFY and COUNSEL notes are open questions that must be resolved before this page is published.

Privacy Notice

Version 2026-09-14

Effective date: 2026-09-14 VERIFY: this must be the date this version first goes live at https://getapplicable.ai/privacy, or later. If publication slips, change the date before publishing. That alone does not create a new version, because this version has never been live.

1. Who we are

applicable.ai is a product of Vera Compliance VERIFY: exact registered legal name with suffix and punctuation (for example "Vera Compliance, Inc." or "Vera Compliance LLC"), state of formation, file number, and good standing. A public search on 2026-09-11 did not find this entity. If no entity has been formed yet, this notice cannot name one: stop and ask counsel. ("we", "us", "our").

Postal address: 8 The Green VERIFY: suite number, plus written confirmation from the provider that general mail addressed to the entity (not only service of process) is scanned or forwarded to a named person, Dover, DE 19901, United States.

Privacy contact: hello@getapplicable.ai VERIFY: send a test from an outside account, confirm it arrives, reply, confirm the reply does not land in spam, and record the date, the time and the name of the person who reads this inbox.

This notice covers personal information we handle through:

  • our website at https://getapplicable.ai;
  • our app at https://app.getapplicable.ai;
  • emails the app sends.

It explains what we collect, why, who else handles it, how long we keep it, and what you can ask us to do.

2. The short version

  • Demo access: we keep your email address and username. We also keep a security record of sign-ups and sign-ins, including your IP address and browser details. If you ask us to delete your information, we delete your email address, username and demo account. The security record stays, without your email address or username.
  • Demo users can only read our regulatory library. Nothing a demo user does is sent to an AI model provider.
  • Customer institutions: to work out which rules apply to a bank or credit union, the app sends parts of that institution's information to an AI model provider (section 3.4).
  • We do not sell personal information, and we do not use advertising or analytics trackers (section 10).

3. What we collect and why

3.1 Demo access (sign-up on https://getapplicable.ai)

What we collectWhy
The email address you enter. We remove surrounding spaces and store it in lower case.To send you one-time sign-in links, identify your demo account, and handle your requests.
The username you choose, stored in lower case. Usernames must be unique, and some names are not allowed (for example, names that imitate our staff or product).To identify your demo account.
Which page of our website you signed up from.To understand which pages lead to sign-ups.
Which version of this notice and of the Demo Terms of Use you accepted, with the date and time, your IP address and your browser's user agent. VERIFY: engineering confirms the acceptance record described in docs/legal/acceptance-requirements.md is live before this notice publishes. On 2026-09-14 it is not built, and the app refuses every notice version (KNOWN_NOTICE_VERSIONS is empty).To show what you agreed to and when.
Sign-in links. We store a one-way hash of each link, never the link itself. We also store the address it was issued for, when it was created, when it expires and when it was used. A link works once and expires after 15 minutes.To let you sign in without a password, and to stop a link being used twice or by the wrong person.
Your demo account. It is created the first time you use a sign-in link. It holds your email address and the account type. It has no password.To give you demo access.
A security record of each sign-up or repeat sign-up, each sign-in link issued or failed to send, each link used or refused, account verification, and each demo sign-in. Each entry holds the date and time, your IP address, your browser's user agent and internal reference numbers. It does not contain your email address or username.To detect and investigate abuse, and to keep the service secure.
A session cookie while you are signed in (section 11).To keep you signed in.

Short-lived counters. To limit repeated attempts, the running server also counts requests by IP address and by email address in its memory. These counters are not written to our database.

Who sends your sign-in link. Normally the app emails it from notifications@getapplicable.ai through Google Workspace. Occasionally a member of our team issues a link and sends it to you from their own mailbox.

Who can see sign-ups. Our platform administrators can see the list of demo sign-ups: email address, username, sign-up page, dates, and how many links were issued.

What a demo account can do. Read the regulatory library, nothing else. A demo account cannot enter information about an institution, and nothing it does is sent to an AI model provider.

Email. We use your email address to send sign-in links and to answer your requests. We do not currently send marketing email to demo users. VERIFY: founder confirms. If there is any plan to email demo users about sales, product news or surveys, this notice and the sign-up form must say so before sign-ups are collected, and CAN-SPAM rules apply to those emails.

3.2 App users (staff of our customer institutions)

App accounts are created by an administrator, not by self sign-up. For each app user we store:

  • email address, name (if given) and account timestamps;
  • a password, stored only as a one-way (bcrypt) hash, and whether a temporary password must be changed at next sign-in;
  • which customer organisations you belong to and your role (admin, member or view only);
  • a session cookie while you are signed in (section 11);
  • a record of who did what. Many actions are recorded with your email address, for example:
    • who answered a question and who reviewed an emailed answer;
    • who changed which regulatory sources apply;
    • who granted or removed someone's access;
    • who sent or cancelled an "Ask someone" email.

      Several of these records are permanent history, kept even after your account or your organisation's account is deleted (section 8).

We do not record IP addresses when you sign in with a password. Actions you take in "Ask someone" are recorded with your IP address and browser user agent (section 3.3).

Why: to provide the service to your organisation under its agreement with us, secure it, keep a trail of who did what (that trail is part of what the product provides), and support you.

Our role. We handle this information on behalf of your organisation. Your organisation's agreement with us governs how, and we may refer your requests to it. VERIFY: no customer agreement exists yet (pre-revenue). See the memo: until one is signed, no bank or credit-union staff other than the founder should hold an app account.

A small number of our staff can access customer organisations' information to operate and support the service. VERIFY: this matches how platform-admin access is actually granted on the publication date (founder decision A of 2026-09-10 is policy; implementation was not complete as of 2026-09-14), and matches the customer agreement.

3.3 People asked a question by email ("Ask someone")

A signed-in app user can email one question to someone, usually a colleague. That person answers on a web page without an account. The email is sent in one of two ways:

  • the app sends it, from notifications@getapplicable.ai through Google Workspace, with replies directed to the person who asked; or
  • the app user sends it from their own mailbox. Their email provider carries the message, not us, but we still store the details below.

We store:

  • the recipient's email address;
  • the sender's note, and who sent it (account and email address);
  • when it was sent and when the link expires (14 days by default);
  • whether it was cancelled;
  • when the answer page was first opened (this can be an email security scanner rather than a person);
  • when it was answered, and the answer.

The answer is added to the organisation's information, with a note that it came through an emailed link from the recipient's address. VERIFY: engineering confirms the exact attribution wording stored on the profile fact (the decision log of 2026-09-13 records that it contains the recipient's email address).

A history log records each event: link created, resent or cancelled; answer recorded, refused, accepted, rejected or undone. Each entry holds the recipient's email address, the person acting, the question text and answer, and the IP address and browser user agent of the request. For an answer, that is the recipient's IP address and user agent. For a send or cancel, it is the app user's.

What the recipient sees: the question and its explanation, the sender's email address and note, the institution's name, and when the link expires. VERIFY: once release/2026-09-13b is live, the email also shows the sender's display name and organisation and up to three regulatory citations with short excerpts. Update this sentence to match what is live on the publication date.

Why: so the organisation can get an answer it needs and keep a record of where the answer came from. Answers can be used in AI evaluation (section 3.4). We do not add recipients to any mailing list.

3.4 Information about customer institutions, and AI model providers

Customer organisations enter or confirm information about their institution: profile facts, legal entities, where it operates, answers to questions, applicability decisions and notes. This is mostly about the institution, not about individuals. It can still include staff names and email addresses (for example, who answered something) and anything a person types into a free-text field.

Please do not enter personal information about a bank's or credit union's customers or members. The service is designed for information about institutions.

Company research. The app can read an institution's own public website, its SEC filings and its FDIC BankFind record, and propose facts for a person to review.

AI model providers. To work out which rules may apply and to draft mappings to controls, the app sends parts of an institution's information to an AI model provider, together with regulation text. That includes relevant profile facts and answers, jurisdictions, entity details and a summary of the institution. Our default provider is Anthropic; OpenAI is used where we have configured it.

  • VERIFY: which providers and which features are switched on in the hosted production service on the publication date. Check the Railway variables MODEL_PROVIDER, ANTHROPIC_API_KEY, OPENAI_API_KEY, APPLICABILITY_MODEL_PROVIDER, EXTRACTION_MODEL_PROVIDER and APPLICABILITY_OPENAI_ALLOW_TENANT_DATA. Name only providers actually in use.
  • VERIFY: whether any user's or recipient's email address can reach a model prompt. A code check on 2026-09-14 found that the applicability evaluator's fact list leaves out the fact's source/attribution field. Emailed answers and free text flowing into clarifications, controls generation, the questionnaire and other features were not traced field by field. Engineering to confirm per feature.
  • VERIFY: whether customer information is processed anywhere other than the hosted service, for example on a development machine (the decision log records AI evaluation run locally with the OpenAI Batch transport enabled). If so, stop before the first customer, or disclose it here and in the customer agreement.

Retention at OpenAI. When the app uses OpenAI's batch processing, it deletes the files it uploads after each run. As a backstop, it sets them to expire automatically after 48 hours (inputs) and 72 hours (outputs).

Retention at the providers generally. Each provider may keep information for a period under its own terms, for example for abuse monitoring. VERIFY against the signed commercial terms and data processing agreements: (a) Anthropic API retention; (b) whether OpenAI Batch and Files data can be kept up to 30 days and are not eligible for zero data retention (decision log 2026-09-10); (c) that neither provider trains its models on our API data. Say only what the signed terms say.

We do not send demo users' information to AI model providers.

3.5 Emails you send us

If you email hello@getapplicable.ai or support@getapplicable.ai, we receive your email address and your message. They are stored in our Google Workspace mailboxes.

3.6 Visiting our website or app

No trackers. Our website and app do not use analytics, advertising or social-media tracking tools, or third-party scripts. Our website's fonts are served from our own site. VERIFY: re-check the deployed https://getapplicable.ai and https://app.getapplicable.ai pages on the publication date, not only the code branches reviewed on 2026-09-14.

Our hosting provider. When your browser connects, our hosting provider receives your IP address and request details, as any web server does. VERIFY: whether Railway's own edge or HTTP logs record visitor IP addresses, and how long Railway keeps them.

Our request logs. The app's request logs record the request method, the page address (with query strings removed and one-time link codes masked), the response status and an internal request number. They do not record your IP address or browser user agent. VERIFY: engineering confirms no other application log line contains an email address or IP address (only the sign-up code was spot-checked).

4. Legal bases

We are a US business, and our service is aimed at US banks and credit unions. We do not rely on your consent to handle your information. The sign-up checkboxes record that you agree to the Demo Terms of Use and that you have read this notice.

Where a law requires us to state a legal basis:

  • performing our agreement with you or your organisation: providing demo access or the app;
  • our legitimate interests: keeping the security record, preventing abuse, and keeping the "Ask someone" record for the organisation that sent the question;
  • complying with the law.

VERIFY / COUNSEL: whether to state legal bases at all, limit sign-up to the US, or add EU/UK-specific rights and international transfer language. The product is not aimed at the EU or UK, but the sign-up form is open to anyone.

5. Who we share information with

We do not sell personal information. We do not share it for cross-context behavioural advertising. VERIFY / COUNSEL: that "sell" and "share" are used here as California law defines them.

These service providers handle personal information for us:

ProviderWhat they do for usInformation involved
Railway VERIFY: contracting entity's legal nameHosts our website, app and databaseEverything in section 3 that the app stores, plus hosting logs
Google (Google Workspace)Sends the app's emails from notifications@getapplicable.ai; hosts our email inboxesEmail addresses and email contents, including sign-in links and "Ask someone" questions; messages you send us
AnthropicAI model processingCustomer institution information (section 3.4)
OpenAI VERIFY: in use in production on the publication date; remove this row if notAI model processingCustomer institution information (section 3.4)

GitHub hosts our source code. It is not given personal information from the service. VERIFY: the repository holds no user, recipient or customer personal information.

We may also disclose information:

  • to your organisation, if you are an app user or an "Ask someone" recipient: its administrators can see the activity described in sections 3.2 and 3.3;
  • to our professional advisers, under confidentiality;
  • when the law requires it, or to protect people, the service or our rights;
  • to a buyer or successor if our business is sold or reorganised COUNSEL: confirm this is wanted and adequately worded;
  • when you ask us to.

6. Where information is stored

Our app and database are hosted in the United States. VERIFY: the region of the production app and database. Engineering memory records a Railway Postgres volume in region "iad" (US East); confirm this is the current production database. Our email and AI providers may process information in the United States or other countries. VERIFY: each provider's processing locations under its DPA.

7. How we protect information

No method of storing or sending information is completely secure, and we cannot guarantee security. Measures we use today:

  • Our website and app are served over HTTPS.
  • Passwords are stored only as one-way hashes.
  • Sign-in links and "Ask someone" links are stored only as one-way hashes. Each works once and expires.
  • Session cookies cannot be read by page scripts (HttpOnly) and are sent only over HTTPS on our hosted service.
  • Only our platform administrators can see the demo sign-up list.
  • Sign-ups, sign-ins, access grants and "Ask someone" events are recorded in history logs.

If a security incident affects your personal information, we will notify you where the law requires.

8. How long we keep information

We have not yet set automatic deletion periods for most categories. The table says what actually happens today. When we set periods, we will publish a new version of this notice.

InformationHow long
Demo sign-up (email address, username, sign-up page, notice version) and demo accountUntil you ask us to delete it, or we delete it. COUNSEL: set a period, for example deleting sign-ups never verified within 30 days and demo accounts unused for 12 months. The period may appear here only after engineering builds the deletion job.
Sign-in link recordsUntil the sign-up they belong to is deleted. A link stops working once used, or 15 minutes after it was issued.
SessionEnds when you sign out, or 14 days after your last activity. VERIFY: expired session rows are pruned from the database (connect-pg-simple default).
Security record, acceptance record, and the record of a deletion requestKept indefinitely. The app cannot edit or delete these records. COUNSEL: set a period (for example 24 months). This needs engineering work, because the tables refuse deletion by design.
App user accountUntil the account is deleted. VERIFY: the code has no route that deletes a standard user account (checked 2026-09-14). Engineering confirms how deletion is done; a logged manual database action by a named person is acceptable for now.
History logs holding app users' and recipients' email addresses (access grants, platform-admin grants, scope changes, impact links, "Ask someone" events)Kept indefinitely, including after the account or organisation is deleted.
"Ask someone" linksUntil the organisation's profile is deleted. Answers become part of the organisation's information.
Customer institution informationFor the term of the customer agreement. It is deleted when the profile or organisation is deleted, except the history logs above. VERIFY: deletion is complete, including AI batch jobs in progress (the decision log recorded a fix on fix/batch-job-delete-cascade; confirm it is merged and live).
Files sent for OpenAI batch processingDeleted after each run, with automatic expiry after 48 hours (inputs) or 72 hours (outputs) as a backstop. The provider's own retention is in section 3.4.
Emails the app sendsVERIFY: whether Google Workspace keeps copies in the Sent folder of notifications@getapplicable.ai (normal for Gmail SMTP). If it does, set a deletion rule or disclose the period here.
Emails you send usUntil we delete them. COUNSEL: set a period.
BackupsVERIFY: whether Railway keeps database backups or snapshots, and how long a deleted record survives in them. Disclose it here.

9. Your choices and rights

Whatever state you live in, you can ask us to:

  • tell you what personal information we hold about you, and give you a copy;
  • correct it;
  • delete it.

We will not treat you differently for making a request.

Deleting demo access. We delete your email address, username, demo account, sign-in link records and active sessions. We keep:

  • the security record and acceptance record (dates, times, IP addresses, browser user agents and internal reference numbers, without your email address or username);
  • a record of the deletion (an internal reference number, the date you originally signed up, which of our staff handled it, and a request reference).

We keep these to investigate abuse and to show that we handled your request. COUNSEL: confirm that keeping IP address and user agent after a deletion request is permitted under any law that applies (flagged in the code as an open legal question).

App users. Your organisation controls your account. We may refer your request to your organisation. History logs described in section 8 are kept.

"Ask someone" recipients. Ask the organisation that emailed you, or ask us and we will pass your request on.

How to ask. Email hello@getapplicable.ai from the address your request is about. We may ask you to confirm the request from that address before we act. Someone you authorise can ask for you; we may ask for proof of that authority. We aim to respond within 30 days. COUNSEL: response window; some state laws allow 45 days. If we decline your request, reply to our response and ask us to reconsider. VERIFY / COUNSEL: whether a formal appeal process is required.

Do Not Track and Global Privacy Control. We do not track you across other websites, and we do not sell or share personal information for advertising. Our website and app therefore do nothing different when your browser sends a Do Not Track or Global Privacy Control signal.

10. Cookies and similar technologies

  • https://app.getapplicable.ai sets one cookie, connect.sid, when you sign in. It keeps you signed in and the app does not work without it. It cannot be read by page scripts, it is sent only over HTTPS on our hosted service, and it expires 14 days after your last activity. Signing out ends the session it points to.
  • Theme. The app saves your light/dark theme choice in your browser's local storage (theme). It is not sent to us.
  • https://getapplicable.ai (our website) sets no cookies.
  • We use no advertising or analytics cookies.

VERIFY: engineering lists every cookie and every localStorage or sessionStorage key the app and website set. This review found connect.sid and theme; keys written through variables were not traced, and the deployed site should be checked in a browser.

11. Children

applicable.ai is for professionals. It is not directed at children, and the Demo Terms of Use require users to be at least 18. We do not knowingly collect personal information from children under 13. If we learn we have, we will delete it.

12. Changes to this notice

Each version of this notice has a version identifier and an effective date, shown at the top.

  • A change means a new version. When we change the notice, we publish a new version with a new identifier and effective date.
  • Earlier versions stay available at https://getapplicable.ai/privacy/[version]. VERIFY: engineering hosts the archive before publication.
  • Demo users re-acknowledge. They are asked to acknowledge a new version before they can continue using demo access.
  • Advance notice for new uses. If a change would use information you already gave us in a materially different way, we will tell you before the change applies. COUNSEL: confirm this commitment is wanted.

13. Contact

Vera Compliance VERIFY: exact legal name 8 The Green VERIFY: suite, Dover, DE 19901, United States hello@getapplicable.ai

applicable.ai
Product AI Agents Regulatory Coverage Regulatory Sources FAQ Trust Contact Terms Privacy
© 2026 applicable.ai. All rights reserved.  ·  AI-first regtech. Regulatory scenarios shown are illustrative. applicable.ai provides compliance intelligence and workflow support, not legal advice; outputs require review by qualified professionals.