Privacy Policy
Last updated: September 2026 · Sugra Systems, Inc. · Delaware, USA
This Privacy Policy describes how Sugra Systems, Inc. ("Sugra", "we", "our") collects, uses, and protects personal information in connection with:
- the corporate website at sugra.systems,
- the Sugra API at sugra.ai, and
- the Sugra application at app.sugra.ai (including account management and OAuth flows).
This policy applies to visitors, prospective customers, account holders, and API Subscribers, collectively referred to as "you". Capitalized terms not defined here have the meanings given in the Sugra Terms of Service.
In addition, Section 14 describes how Sugra processes the personal data of third parties who are the subject of screening signals returned by Sugra Entity (for example individuals named on public sanctions or watchlists, politically-exposed persons, and individuals named in adverse media). Those individuals are not Sugra account holders, and Section 14 sets out their rights and the lawful basis for that processing.
1. Information We Collect
We collect information in the following categories:
1.1 Information you provide directly
- Website contact. When you contact us through the website or by email, we collect your name, email address, and the content of your message.
- Account registration. When you create an account at app.sugra.ai, we collect your email address, a password (stored as a bcrypt hash), and optional profile fields such as name, locale, and timezone.
- OAuth sign-in profile. If you sign in to app.sugra.ai or connect your account through GitHub, Google, or Microsoft, we receive your basic profile from that provider and store your name, email address, and profile photo URL on your account. The photo URL is refreshed each time you sign in through the provider. Where your account has no provider photo, pages that display your avatar may request a fallback image from the Gravatar service using a one-way SHA-256 hash of your email address; we never send your raw email address to Gravatar (see Section 6).
- Two-factor authentication. If you choose to enable two-factor authentication for your app.sugra.ai account, we store the shared secret used by your authenticator application and a set of single-use recovery codes you can use to regain access if you lose your authenticator. The shared secret is encrypted at rest using application-managed keys (Laravel's encrypted Eloquent attribute cast); the application decrypts it on each sign-in to verify the rotating code generated by your authenticator. Recovery codes, by contrast, are stored only as one-way bcrypt hashes and cannot be read back from our database in plaintext form, which is why we display them to you exactly once at the time you enable two-factor authentication. When you disable two-factor authentication, both the shared secret and the recovery code hashes are deleted from your account record.
- API Subscribers. When you register for API access, we collect account identifiers, generated API key material, and subscription tier information. API keys are stored as secure hashes; only the final characters are displayed to you after creation.
- Billing information. For paid subscriptions, we collect billing details necessary for payment, including a Stripe customer identifier, payment method type, and the last four digits of the payment card. We do not receive or store full payment card numbers; these are handled by Stripe, our payment processor.
1.2 Information collected automatically
- Technical information. IP address, browser type and version, device type, operating system, pages visited, referring URLs, and timestamps, collected through server access logs.
- API usage metadata. For API Subscribers, we record daily aggregate counts of API requests associated with each API key, including a daily aggregate broken down by endpoint template and product family. We do not record the content, parameters, or responses of API requests.
- Authentication and OAuth data. For the Service and for OAuth connections to third-party clients, we store access tokens, refresh tokens, authorization scopes, and token expiry information.
- Account security data. We keep your most recent sign-in timestamp and IP address on your account record, and derive from that IP an approximate location (country, city, network operator) using our own Sugra NetAtlas infrastructure - no third party receives your IP for this enrichment.
- Login history. For account security and fraud prevention, we record each successful sign-in to app.sugra.ai: the IP address, browser user-agent, sign-in method (password or OAuth provider), and timestamp. Login history is retained for twelve (12) months and is deleted with your account.
- Signup context. At registration we record, once, the IP address, browser user-agent, the referring URL, and any campaign parameters (utm_medium, utm_campaign) present on your first visit, to understand how users find the Service.
- Advertising click identifiers. If you reach us from an advertisement, the advertising platform appends an identifier for that click to the link (for example gclid, gbraid, or wbraid from Google, fbclid from Meta, twclid from X). We store the identifiers present on your first visit, once, together with the signup context above, and the plan you clicked before signing up. These identifiers let an advertising platform recognize its own click, and are used only for the advertising measurement described in Section 6.
- Cookies and similar technologies. Described in Section 4 below.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, secure, and improve the Service.
- Authenticate requests to the API and enforce rate limits and subscription quotas.
- Process billing, respond to subscription events, and deliver transactional emails (for example, account verification, password reset, subscription status changes, and usage-threshold notifications).
- Respond to your inquiries and provide customer support.
- Analyze aggregate usage patterns to improve reliability and performance.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Measure the effectiveness of our advertising, and attribute a signup or a subscription to the campaign that led to it. On sugra.systems the Google tags described in Section 4 do this only after you allow advertising in the cookie banner, wherever you are. On app.sugra.ai they do it by default (in the European Economic Area, the United Kingdom and Switzerland only after you allow it), unless you switch advertising off; the purchase reports we send ourselves under Section 6 are made only where you have allowed advertising measurement on your app.sugra.ai account.
- Comply with applicable legal obligations and respond to lawful requests.
We do not sell or rent your personal information for money, and we do not disclose it to data brokers. We do share a limited set of identifiers with the advertising platforms named in Section 6, each on the terms described there, and those platforms use what they receive for their own purposes as well as ours. Several United States state privacy laws classify that kind of sharing as a "sale" or as "sharing" for cross-context behavioral advertising even though no money changes hands; Section 15 explains what that means and how to opt out.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following lawful bases under the GDPR:
- Contractual necessity - to provide the Service to account holders and API Subscribers in accordance with the Terms of Service.
- Legitimate interests - for website security, fraud prevention, and service improvement, where such interests are not overridden by your rights and freedoms.
- Consent - for the Google Analytics and advertising tags described in Section 4, which on sugra.systems and its developer blog run only after you allow them wherever you are, and on app.sugra.ai, in the European Economic Area, the United Kingdom and Switzerland, where the advertising tag runs only after you allow it and Google Analytics does not run at all, there being no analytics choice to make on that site, for the purchase reports described in Section 6, for the first-party marketing cookies on app.sugra.ai described in Section 4, and for marketing communications, where required by applicable law. You may withdraw consent at any time, and withdrawal stops any further such sharing from that moment in the page you withdraw it in, except that an event already recorded may still be delivered as that page closes, as Section 4 describes; Section 15.2 says when it takes effect in a page of ours you already have open elsewhere in your browser.
- Legal obligation - where processing is required by law, regulation, or lawful order.
The lawful basis for processing the personal data of individuals who are the subject of screening signals (sanctions, watchlist, PEP, and adverse-media data processed by Sugra Entity) is described separately in Section 14.
4. Cookies
sugra.systems uses cookies in the following categories:
- Essential cookies - required for core website functionality, including session management for the contact form and retention of your cookie consent preference.
- Analytics cookies - Google Analytics 4, used to understand how our sites are used. On sugra.systems, including the developer blog at sugra.systems/blog, it runs only after you allow it in the cookie banner. On app.sugra.ai it runs by default, and that site offers no analytics switch of its own, except for visitors in the European Economic Area, the United Kingdom and Switzerland, described below.
- Marketing cookies - the Google advertising tag, used to measure which campaigns lead to a signup or a purchase. On sugra.systems it runs only after you allow it in the cookie banner, and it never runs on the developer blog. On app.sugra.ai it runs by default unless you switch advertising off as described below, except for visitors in the European Economic Area, the United Kingdom and Switzerland, described below. It may use the advertising click identifier on the link you followed and store an identifier for your browser, and it records the pages you view and how you interact with a page, such as starting or submitting a form, scrolling or following a link to another site. Where it finds contact details you type into a form, such as an email address, phone number or postal address, it may send them to Google in hashed form for advertising measurement.
You can switch either category off at any time. On sugra.systems the cookie banner offers Allow all, Reject all and Choose, where the boxes start unticked until you answer and you tick what you allow, and the Cookies link in the site footer reopens it. Until you answer, no Google tag is loaded on sugra.systems at all, wherever you are: Tag Manager is put on the page only once your answer allows something, and only with that answer already set. The developer blog at sugra.systems/blog, which has no banner of its own, follows the analytics choice made there in the same way. If you change your choice on a page whose tags are already running, a category you switch off stops storing anything and stops sending anything that identifies you from that moment, for as long as you stay on that page; an event already recorded may still be delivered to Google as the page closes. A category you switch on applies from that moment; where its tag has not started, it may begin then or only on the next page you open, because Tag Manager decides which tags run as a page loads. Your banner choice is kept in a cookie. Where your browser does not keep it - some browser settings and extensions do not - the banner asks again on the next page you open, and until it is answered there nothing runs; where a browser keeps an earlier choice but will not record a new one, the banner shows the choice it can still read, and that is the one that applies. On app.sugra.ai advertising is off for an account whose advertising measurement answer is no, which you can set at any time from your profile; there the page reloads when the answer changes, so the change takes effect at once. Google Analytics on app.sugra.ai has no switch of its own. On every one of our sites a browser that sends Global Privacy Control has advertising off. Your browser settings, an extension that blocks these scripts, or a message to privacy@sugra.systems work as well. Switching analytics or marketing off does not affect website functionality.
Visitors in the European Economic Area, the United Kingdom and Switzerland. On sugra.systems and its developer blog this makes no difference, because no Google tag is loaded for anyone who has not answered the banner, wherever they are. On app.sugra.ai, where the tags otherwise run by default, the advertising tag runs only after you answer yes to advertising measurement, and Google Analytics does not run at all, because app.sugra.ai offers no separate analytics choice. We recognise these visitors from the time zone your device reports and, as a backstop that keeps the tags from running, from Google's own estimate of where your connection comes from. A visitor from elsewhere whose device is set to a European time zone is treated the same way as a visitor in Europe; a visitor whose device and connection both point outside these places is treated like any other visitor.
These Google tags reach your browser through Google Tag Manager, a Google service that loads the tags we configure, and a tag is loaded only where its category is on. Switching that category off afterwards does not unload a tag that has already started: it stops that tag storing anything and sending anything that identifies you, from that moment, as the paragraph above describes. On sugra.systems, and on the developer blog, Tag Manager is not loaded at all until you answer the banner, and not while both categories are off. On app.sugra.ai it is never loaded on the password reset page, pages opened from a signed link we emailed you, the page where you authorize an application to use your account, your profile, billing, and the pages where you set up two-factor authentication or view your recovery codes, and administration pages. The page that asks for your two-factor code when you sign in is not on that list, and it does carry Tag Manager.
app.sugra.ai may set first-party marketing cookies (sugra_ft and sugra_pc) that record how a visit reached us, which plan was selected, and any advertising click identifier carried on the link you followed, solely so a signup can be attributed to its source. Those cookies are set only after you grant advertising measurement consent on app.sugra.ai. Until you grant consent, the same attribution facts may be held temporarily in the essential application session for the current visit so a paid click is not lost before you create an account; they are not written as long-lived cookies. Declining advertising measurement consent, or sending Global Privacy Control, clears those cookies and the session bridge. The API at sugra.ai sets no cookies.
The developer blog at sugra.systems/blog loads the same Tag Manager container but runs only Google Analytics there, never the advertising tag. It follows the analytics choice you make in the banner on the main site. The blog has no banner of its own, and until you have made that choice it loads no Google tag at all.
On app.sugra.ai the Google tags load before and after you sign in, because our advertisements link to that site and Google does not measure a campaign whose landing page carries no tag. When the page shown after a completed checkout loads, the advertising tag reports that a purchase took place, and Google counts it toward the advertisement you followed. That count is separate from the purchase reports we send ourselves under Section 6, which are made only where you have allowed advertising measurement on your account.
Advertising on app.sugra.ai follows the answer stored on your account, not a cookie, which is why a choice made on sugra.systems does not carry over to app.sugra.ai. The in-app question and your profile let you give or change that answer at any time, and the date it was given is stored with it. For the Google tags, advertising stays on until you answer no (for visitors in Europe, it stays off until you answer yes); for the purchase reports and the marketing cookies described above, no answer counts as a refusal.
5. Log Data
We retain server-side access logs for security, fraud prevention, debugging, and operational purposes. Access logs include typical fields such as source IP address, request method, path, status code, and user-agent. They do not include request bodies or query parameters that could expose credentials or personal content.
Access logs are retained for up to thirty (30) days, after which they are rotated and deleted by scheduled log rotation. Application logs produced by the API and app services are written to the system journal and retained subject to the retention policies of the underlying infrastructure.
6. Data Sharing
We share personal information with:
- Infrastructure providers. Microsoft Corporation provides cloud infrastructure (Microsoft Azure), primarily in the East US region, hosting our servers, databases, and shared cache. Personal information stored in our systems resides on Azure infrastructure.
- Payment processor. Stripe, Inc. processes payments, subscriptions, and related billing events. Stripe receives the information necessary to process payments, including your name, billing address, and payment method details. Stripe operates under its published Data Processing Addendum (stripe.com/legal/dpa). We do not receive or store full payment card numbers.
- Email provider. Resend, Inc. transmits transactional emails on our behalf. Resend processes recipient email addresses and the content of the transactional messages we send.
- Analytics provider. Google LLC operates Google Analytics 4 on sugra.systems, its developer blog, and app.sugra.ai. Google receives page-view telemetry, anonymized IP, browser and device characteristics, and a randomly generated client identifier. On sugra.systems and its blog it runs only after you allow it in the cookie banner, and when you switch analytics off it stops storing anything and stops sending anything that identifies you, from that moment, as set out in Section 4. On app.sugra.ai it runs by default and there is no such switch, except for visitors in the European Economic Area, the United Kingdom and Switzerland, for whom it does not run there at all. Typography on the main pages uses self-hosted DM typefaces served from sugra.systems. The Japanese locale is the exception: those pages load Noto Sans JP from Google Fonts (
fonts.googleapis.comandfonts.gstatic.com), and those requests share basic browser metadata (IP, user-agent) with Google as part of standard HTTP delivery, whatever you choose for analytics. The developer blog self-hosts its fonts and does not load Google Fonts. Google operates under its Ads Data Processing Terms, and IP anonymization is enabled by default for GA4. - Sign-in providers. If you use OAuth sign-in or account linking, GitHub, Inc., Google LLC, or Microsoft Corporation (Microsoft identity platform) process the sign-in handshake and provide us your basic profile (name, email address, profile photo URL). We do not transmit your account data to these providers beyond the handshake itself.
- Avatar service. Automattic Inc. operates Gravatar. Where your account has no provider profile photo, pages that display your avatar request a fallback image from gravatar.com addressed by a one-way SHA-256 hash of your email address. Automattic receives that hash and standard HTTP request metadata (IP address, user-agent) from the viewing browser as part of image delivery, and never your raw email address.
- Advertising platforms. Where you have allowed advertising measurement on your app.sugra.ai account, we report subscription purchases to the advertising platforms we use, so that a purchase can be matched to the advertisement that led to it: Meta Platforms Ireland Limited for people in the European Economic Area and Meta Platforms, Inc. elsewhere (Facebook and Instagram advertising); Google Ireland Limited or Google LLC depending on your region (Google Ads, a role separate from the analytics and sign-in roles above); and X Internet Unlimited Company for people in the European Economic Area, Switzerland, and the United Kingdom, and X Corp. elsewhere (X advertising). Each receives the click identifier that platform itself issued, a one-way SHA-256 hash of your email address, the amount and currency of the purchase, and an identifier we generate for the event so that one purchase is not counted twice. Google also counts signups and purchases through its own advertising tag on our sites, as described in Section 4: on sugra.systems only once you have allowed advertising in the cookie banner, wherever you are, and on app.sugra.ai unless advertising is switched off for you - and there, in the European Economic Area, the United Kingdom and Switzerland, only once you have allowed it. We do not send your raw email address, your name, your credentials, your API keys, or anything about your use of the API. Not every platform listed is active at any given time, and a platform receives nothing while its integration is switched off. If we add a platform to this list, this policy will say so before that platform receives anything.
- Legal authorities. Where required by law, regulation, or legal process, or where we in good faith consider disclosure necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
An advertising platform is not simply our processor. Unlike the providers listed above, an advertising platform may use part of what it receives for its own purposes rather than only on our instructions, and we would rather be plain about that than bury it. The role differs from platform to platform, and for the same platform from one kind of data to another, so we set the three out separately below instead of giving you a single label that would be wrong for at least one of them.
Under Meta's Business Tools Terms, Sugra and Meta are joint controllers for the collection and transmission of the purchase event, and Meta is an independent controller for what it does with that data afterwards, including improving its own advertising systems. Meta acts as a processor for the matching and measurement it performs on our behalf. The essence of the joint arrangement is this: Sugra decides which events are sent and remains answerable to you for that decision; Meta decides what it does with an event once received and is answerable for that; and whichever of us receives a request meant for the other will pass it on.
For X, our integration requires the setting that keeps conversion events under X's processor terms, so that X handles both the identifiers used to match you to an X account and the events themselves on our instructions, rather than being free to use them to improve its own advertising models. For Google, the split follows Google's own terms: Google acts as our processor for the services covered by its Ads Data Processing Terms, including the matching of a hashed email address, and as an independent controller for the parts of Google Ads that fall outside them. Each platform operates under its own published terms and its own international transfer mechanism, and you may exercise your rights directly against a platform as well as against us.
We do not share personal information with data brokers, and we do not provide it to anyone so that they can market their own unrelated products to you. Apart from the advertising measurement described above, and the providers listed above, we do not disclose personal information to advertisers or marketing networks.
7. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law. Specific retention periods include:
- Account data (users, authentication, API keys, OAuth clients): retained for the duration of the account. On account deletion, personal data is initially marked as deleted and then hard-deleted approximately ninety (90) days thereafter by a scheduled process, except where retention is required for billing records, legal obligations, or the defense of legal claims.
- API usage metadata (daily aggregate request counts): retained for up to fourteen (14) months, enabling annual Subscribers to review their usage history. Older records are removed by a scheduled purge.
- Login history: retained for twelve (12) months from each sign-in, then deleted by a scheduled process; deleted earlier if the account is deleted.
- OAuth access and refresh tokens: retained for the active lifetime of the token, plus approximately ninety (90) days after token expiry for security audit purposes, then purged. Tokens you explicitly revoke (for example, by disconnecting a connected application in Settings) are purged promptly on the next scheduled cleanup.
- Access logs: up to thirty (30) days, as described in Section 5.
- Contact form submissions and email correspondence: up to three (3) years.
- Billing records: retained as required by applicable tax, accounting, and payment regulations (typically at least seven years in the United States).
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to access - request a copy of your data.
- Right to rectification - request correction of inaccurate data.
- Right to erasure - request deletion of your data.
- Right to restriction - limit how we process your data.
- Right to data portability - receive your data in a machine-readable format.
- Right to object - object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent - where processing is based on consent.
- Right to lodge a complaint - with your national data protection authority.
Self-serve erasure. You may delete your account at any time from the Settings page at app.sugra.ai. Deletion triggers the retention schedule described in Section 7.
Other requests. To exercise any other right, including requests for access, rectification, or portability, contact us at privacy@sugra.systems. We will respond within thirty (30) days, extendable where the request is complex, in accordance with applicable law. A self-service data export is planned for a future release. We may request information reasonably necessary to verify your identity before acting on a request.
United States residents. If you live in a state with a comprehensive consumer privacy law, Section 15 sets out the additional rights you have and how to exercise them.
9. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit over public networks, encryption at rest where supported by the underlying storage, role-based access controls, network segmentation between public-facing and internal systems, private endpoints for shared datastores, logging of administrative events, and documented incident response procedures.
No method of transmission over the Internet or of electronic storage is perfectly secure. While we strive to protect your information, we cannot guarantee absolute security.
10. International Transfers
Sugra Systems, Inc. is incorporated in Delaware, USA, and its primary processing operations occur in the United States. If you are located outside the United States, your information may be transferred to, stored in, and processed in the United States or in other jurisdictions where our sub-processors operate.
Where required by applicable law, we rely on appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms recognized by other jurisdictions. Further detail is set forth in the Data Processing Agreement.
11. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from individuals under sixteen (16) years of age. If we learn that we have collected personal information from a child under this age without verifiable parental consent, we will delete it promptly.
Access to paid subscriptions and acceptance of the Terms of Service require the user to be at least eighteen (18) years of age or otherwise have legal capacity to contract under applicable law.
12. Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, personal information held by Sugra may be transferred as part of such transaction. We will notify you through the Service and, where practical, by email of any change in ownership or use of your personal information, as well as any choices you may have.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days' advance notice by email to active account holders and a prominent notice at sugra.systems, and will update the "Last updated" date above. Continued use of the Service after the effective date of a change constitutes acceptance.
14. Screening Data (Sugra Entity)
This section describes a specific processing activity that involves the personal data of individuals who are not Sugra account holders or Subscribers. Sugra Entity returns screening signals that compare a name, identifier, or entity against public sanctions, watchlist, politically-exposed-person ("PEP"), and adverse-media sources. To do so, Sugra processes personal data about the individuals who appear in those sources.
14.1 Personal data processed and its sources
- Sanctions and watchlist subjects. Names and name-parts, aliases, jurisdiction, listing program and dates, and any secondary public identifiers present on the official list (for example passport, national ID, tax ID, vessel or aircraft identifier), processed from official government and intergovernmental sources.
- Politically-exposed persons. Names and name-parts, public position or role, jurisdiction, and associated dates, processed from public records.
- Adverse-media subjects. Names and references to publicly-available news in which the individual is linked to defined financial-crime risk categories (for example fraud, corruption, sanctions evasion, terrorist financing).
Sugra processes only personal data already contained in public, sovereign, intergovernmental, or openly-licensed sources. Sugra does not use leaked or covertly-obtained data, does not add contact details or behavioural data, and does not perform people-search or build profiles of individuals beyond the screening purpose.
14.2 Lawful basis
For sanctions and watchlist screening, Sugra and its Customers process personal data primarily to comply with legal obligations relating to sanctions and the prevention of financial crime (GDPR Article 6(1)(c)), supported by legitimate interests (Article 6(1)(f)).
For PEP and adverse-media screening, Sugra relies on its legitimate interests and those of its Customers and the public interest in preventing financial crime, corruption, and sanctions evasion (Article 6(1)(f)), having carried out a legitimate-interest assessment that weighs those interests against the rights and freedoms of the individuals concerned. Because the sources are public and the safeguards in Section 14.4 apply, Sugra considers that those interests are not overridden by the individuals' interests in this context. Consent is not used as the basis for this processing, because the individuals concerned are not Sugra's customers.
14.3 Retention
Screening reference data is refreshed from its public sources on a recurring schedule, and superseded entries are replaced as the sources change, so Sugra mirrors the current public state rather than building a long-lived historical record of any individual. Point-in-time snapshots used for audit queries reflect the public state of the lists on a given date. Sugra does not retain screening reference data about an individual beyond what is necessary for the screening purpose and any applicable legal-retention requirement.
14.4 Rights of screened individuals and safeguards
Individuals who are the subject of screening data may exercise their rights of access, rectification, erasure, restriction, and objection by contacting privacy@sugra.systems. Because this processing relies on legitimate interests, individuals have a right to object under Article 21; Sugra will assess each objection and will stop processing unless it demonstrates compelling legitimate grounds or the processing is necessary for the establishment, exercise, or defence of legal claims or for compliance with a legal obligation. Where data Sugra holds mirrors an authoritative public source, Sugra will, where feasible, correct or suppress the entry on its side and direct the individual to the authoritative source for upstream correction.
No solely-automated decisions by Sugra. A screening signal is a technical signal, not a determination. Sugra does not make any decision producing legal effects, or similarly significant effects, about a screened individual within the meaning of Article 22 of the GDPR. Screening signals are intended to be reviewed and independently verified by a human before any decision is taken, and the Sugra Acceptable Use Policy requires Customers to apply that independent verification and prohibits using a screening signal as the sole basis for decisions about an individual.
15. United States State Privacy Rights
This section applies if you are a resident of a United States state with a comprehensive consumer privacy law, including California (the California Consumer Privacy Act as amended by the California Privacy Rights Act), Colorado, Connecticut, Texas, Virginia, and other states with equivalent laws. It supplements the rest of this policy and does not replace it.
15.1 Sale and sharing for advertising
The advertising measurement described in Sections 2, 4, and 6 discloses identifiers to advertising platforms that use them for cross-context behavioral advertising. Under California law that counts as a "sale" and as "sharing" of personal information, and under other state laws as "targeted advertising", whether or not we are paid anything for it. We would rather say so plainly than rely on the fact that no money changes hands: we treat this disclosure as a sale and as sharing under those laws.
The categories disclosed for this purpose are identifiers (an advertising click identifier issued by the platform, an identifier for your browser held in an advertising cookie, and a one-way SHA-256 hash of your email address and, where the advertising tag detects them in a form, of your phone number and postal address), commercial information (that a subscription purchase took place, its amount and currency, and an event identifier used for de-duplication), and internet or other electronic network activity information (the pages you view on our sites and how you interact with them, as recorded by the advertising tags described in Section 4). The recipients are the advertising platforms named in Section 6. No other category of personal information is disclosed for this purpose. We have not sold or shared the personal information of any consumer we know to be under sixteen (16) years of age.
15.2 How to opt out
The advertising measurement the Google tags perform follows your answer, and where it runs you can opt out of it at any time, in two places that do not speak for each other. On sugra.systems none of it happens until you allow marketing in the cookie banner, wherever you are. On app.sugra.ai it is on by default (in the European Economic Area, the United Kingdom and Switzerland only after you allow it, as Section 4 describes). On sugra.systems it is the marketing category in the cookie banner, which you can change at any time through the Cookies link in the site footer. On app.sugra.ai it is the advertising measurement answer on your account, which you can set to no at any time from your profile. Opting out stops any further such disclosure from the page you opt out in, from that moment, except that an event already recorded may still be delivered to Google as that page closes, as Section 4 describes. On app.sugra.ai a page you already have open in another tab stops disclosing anything that identifies you as soon as we record the answer, if your browser lets our pages share that answer with each other, and it switches the advertising tag off entirely when that page next reloads, which is the next thing you do in it; if that comes back with errors in a form you are filling in, the page keeps what you typed and the tag goes when the next one does not. On sugra.systems such a page applies the change the next time it loads. A page you have kept open since before an update to our site runs the version it was loaded with, so it applies your answer the next time it loads rather than at once; reloading it is enough. The purchase reports we send ourselves under Section 6 are made only where you have affirmatively allowed advertising measurement on your app.sugra.ai account, so if you have never allowed it, none are made. You may also write to privacy@sugra.systems and we will record the opt-out for you.
We also honor a browser opt-out preference signal such as Global Privacy Control. While your browser sends the signal, the Google advertising tag on each of our sites is off, whatever the banner or your account says; the page reads the signal itself when it loads, and on app.sugra.ai again on every page it moves to within the application. Where the signal appears while a page of ours is already open and the advertising tag has already run there, app.sugra.ai stops storing anything and stops sending anything that identifies you from the moment that page reads the signal, and the tag itself is gone when that page next loads; a page of sugra.systems you already have open was loaded before the signal and applies it the next time it loads, which reloading it is enough for. When you are signed in on app.sugra.ai and your browser sends the signal, we also treat it as a withdrawal of advertising measurement for your account: any prior permission is recorded as withdrawn, and no further purchase report is made. The signal does not permanently lock the setting. You can allow measurement again only by an explicit action in your profile or the in-app prompt, and only while the browser is no longer sending the signal; while the signal is still on, a new permission is refused. Turning the signal off does not by itself restore a prior permission - you must allow measurement again if you want it. You may still write to privacy@sugra.systems and we will record the opt-out for you.
15.3 Other rights
Subject to verification and to the exceptions in applicable law, you may request to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting or disclosing it, and the categories of third parties to whom it was disclosed; to correct inaccurate personal information; to delete personal information; and, where your state provides it, to obtain a portable copy. We will not discriminate against you for exercising any of these rights: the Service, its prices, and its features are the same whether or not you allow advertising measurement.
Requests go to privacy@sugra.systems, and account deletion is also self-serve from the Settings page at app.sugra.ai. We will acknowledge and respond within the period your state's law allows, and we may ask for information reasonably necessary to verify that the request is yours. An authorized agent may submit a request on your behalf with proof of authorization, and we may still ask you to verify your own identity. If we refuse a request, our response will say why, and you may appeal it by replying to that response or by writing to legal@sugra.systems; if the appeal is denied, you may contact your state attorney general.
We do not process personal information for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you, and we do not use or disclose sensitive personal information for purposes that require an option to limit that use.
16. Contact
For privacy-related questions, requests, or concerns:
- Email: privacy@sugra.systems
- Legal inquiries: legal@sugra.systems
- Support: support@sugra.systems
- Company: Sugra Systems, Inc., c/o LegalInc Corporate Services Inc., Middletown, Delaware, USA