Privacy Policy
Last updated: July 2026 · Sugra Systems, Inc. · Delaware, USA
This Privacy Policy describes how Sugra Systems, Inc. ("Sugra", "we", "our") collects, uses, and protects personal information in connection with:
- the corporate website at sugra.systems,
- the Sugra API at sugra.ai, and
- the Sugra application at app.sugra.ai (including account management and OAuth flows).
This policy applies to visitors, prospective customers, account holders, and API Subscribers, collectively referred to as "you". Capitalized terms not defined here have the meanings given in the Sugra Terms of Service.
In addition, Section 14 describes how Sugra processes the personal data of third parties who are the subject of screening signals returned by Sugra Entity (for example individuals named on public sanctions or watchlists, politically-exposed persons, and individuals named in adverse media). Those individuals are not Sugra account holders, and Section 14 sets out their rights and the lawful basis for that processing.
1. Information We Collect
We collect information in the following categories:
1.1 Information you provide directly
- Website contact. When you contact us through the website or by email, we collect your name, email address, and the content of your message.
- Account registration. When you create an account at app.sugra.ai, we collect your email address, a password (stored as a bcrypt hash), and optional profile fields such as name, locale, and timezone.
- OAuth sign-in profile. If you sign in to app.sugra.ai or connect your account through GitHub, Google, or Microsoft, we receive your basic profile from that provider and store your name, email address, and profile photo URL on your account. The photo URL is refreshed each time you sign in through the provider. Where your account has no provider photo, pages that display your avatar may request a fallback image from the Gravatar service using a one-way SHA-256 hash of your email address; we never send your raw email address to Gravatar (see Section 6).
- Two-factor authentication. If you choose to enable two-factor authentication for your app.sugra.ai account, we store the shared secret used by your authenticator application and a set of single-use recovery codes you can use to regain access if you lose your authenticator. The shared secret is encrypted at rest using application-managed keys (Laravel's encrypted Eloquent attribute cast); the application decrypts it on each sign-in to verify the rotating code generated by your authenticator. Recovery codes, by contrast, are stored only as one-way bcrypt hashes and cannot be read back from our database in plaintext form, which is why we display them to you exactly once at the time you enable two-factor authentication. When you disable two-factor authentication, both the shared secret and the recovery code hashes are deleted from your account record.
- API Subscribers. When you register for API access, we collect account identifiers, generated API key material, and subscription tier information. API keys are stored as secure hashes; only the final characters are displayed to you after creation.
- Billing information. For paid subscriptions, we collect billing details necessary for payment, including a Stripe customer identifier, payment method type, and the last four digits of the payment card. We do not receive or store full payment card numbers; these are handled by Stripe, our payment processor.
1.2 Information collected automatically
- Technical information. IP address, browser type and version, device type, operating system, pages visited, referring URLs, and timestamps, collected through server access logs.
- API usage metadata. For API Subscribers, we record daily aggregate counts of API requests associated with each API key, including a daily aggregate broken down by endpoint template and product family. We do not record the content, parameters, or responses of API requests.
- Authentication and OAuth data. For the Service and for OAuth connections to third-party clients, we store access tokens, refresh tokens, authorization scopes, and token expiry information.
- Account security data. We keep your most recent sign-in timestamp and IP address on your account record, and derive from that IP an approximate location (country, city, network operator) using our own Sugra NetAtlas infrastructure - no third party receives your IP for this enrichment.
- Login history. For account security and fraud prevention, we record each successful sign-in to app.sugra.ai: the IP address, browser user-agent, sign-in method (password or OAuth provider), and timestamp. Login history is retained for twelve (12) months and is deleted with your account.
- Signup context. At registration we record, once, the IP address, browser user-agent, the referring URL, and any campaign parameters (utm_medium, utm_campaign) present on your first visit, to understand how users find the Service.
- Advertising click identifiers. If you reach us from an advertisement, the advertising platform appends an identifier for that click to the link (for example gclid, gbraid, or wbraid from Google, fbclid from Meta, twclid from X). We store the identifiers present on your first visit, once, together with the signup context above, and the plan you clicked before signing up. These identifiers let an advertising platform recognize its own click, and are used only for the advertising measurement described in Section 6.
- Cookies and similar technologies. Described in Section 4 below.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, secure, and improve the Service.
- Authenticate requests to the API and enforce rate limits and subscription quotas.
- Process billing, respond to subscription events, and deliver transactional emails (for example, account verification, password reset, subscription status changes, and usage-threshold notifications).
- Respond to your inquiries and provide customer support.
- Analyze aggregate usage patterns to improve reliability and performance.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Measure the effectiveness of our advertising, and attribute a subscription to the campaign that led to it, where you have allowed advertising measurement.
- Comply with applicable legal obligations and respond to lawful requests.
We do not sell or rent your personal information for money, and we do not disclose it to data brokers. Where you have allowed advertising measurement, we do share a limited set of identifiers with the advertising platforms named in Section 6, and those platforms use what they receive for their own purposes as well as ours. Several United States state privacy laws classify that kind of sharing as a "sale" or as "sharing" for cross-context behavioral advertising even though no money changes hands; Section 15 explains what that means and how to opt out. If you have not allowed advertising measurement, nothing is shared with those platforms.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following lawful bases under the GDPR:
- Contractual necessity - to provide the Service to account holders and API Subscribers in accordance with the Terms of Service.
- Legitimate interests - for website security, fraud prevention, analytics, and service improvement, where such interests are not overridden by your rights and freedoms.
- Consent - for non-essential cookies, for advertising measurement and the sharing described in Section 6, and for marketing communications, where required by applicable law. You may withdraw consent at any time, and withdrawal stops any further sharing from that moment.
- Legal obligation - where processing is required by law, regulation, or lawful order.
The lawful basis for processing the personal data of individuals who are the subject of screening signals (sanctions, watchlist, PEP, and adverse-media data processed by Sugra Entity) is described separately in Section 14.
4. Cookies
sugra.systems uses cookies in the following categories:
- Essential cookies - required for core website functionality, including session management for the contact form and retention of your cookie consent preference.
- Analytics cookies - Google Analytics 4, used to understand aggregate website usage. The analytics tag is loaded only after you allow analytics cookies through the consent banner. If you decline, the tag is never loaded.
- Marketing cookies - used to measure which campaigns lead to a purchase. Nothing in this category is set unless you allow it, and declining is the default. This choice applies to sugra.systems, and a choice made on one of our domains cannot be read on another.
You may manage your preferences at any time through the Cookies link in the site footer, which reopens the consent banner, as well as through your browser settings or by contacting us at privacy@sugra.systems. Declining analytics or marketing cookies does not affect website functionality.
app.sugra.ai may set first-party marketing cookies (sugra_ft and sugra_pc) that record how a visit reached us, which plan was selected, and any advertising click identifier carried on the link you followed, solely so a signup can be attributed to its source. Those cookies are set only after you grant advertising measurement consent on app.sugra.ai. Until you grant consent, the same attribution facts may be held temporarily in the essential application session for the current visit so a paid click is not lost before you create an account; they are not written as long-lived cookies. Declining advertising measurement consent, or sending Global Privacy Control, clears those cookies and the session bridge. The API at sugra.ai sets no cookies.
Advertising consent on app.sugra.ai is not kept in a cookie. It is a question we put to you once you are signed in, and your answer is stored on your account together with the date it was given, which is why a choice made on sugra.systems does not carry over to app.sugra.ai and has to be made again there. The answer starts as no answer, which we treat as a refusal, and you can change it at any time from your profile.
5. Log Data
We retain server-side access logs for security, fraud prevention, debugging, and operational purposes. Access logs include typical fields such as source IP address, request method, path, status code, and user-agent. They do not include request bodies or query parameters that could expose credentials or personal content.
Access logs are retained for up to thirty (30) days, after which they are rotated and deleted by scheduled log rotation. Application logs produced by the API and app services are written to the system journal and retained subject to the retention policies of the underlying infrastructure.
6. Data Sharing
We share personal information with:
- Infrastructure providers. Microsoft Corporation provides cloud infrastructure (Microsoft Azure), primarily in the East US region, hosting our servers, databases, and shared cache. Personal information stored in our systems resides on Azure infrastructure.
- Payment processor. Stripe, Inc. processes payments, subscriptions, and related billing events. Stripe receives the information necessary to process payments, including your name, billing address, and payment method details. Stripe operates under its published Data Processing Addendum (stripe.com/legal/dpa). We do not receive or store full payment card numbers.
- Email provider. Resend, Inc. transmits transactional emails on our behalf. Resend processes recipient email addresses and the content of the transactional messages we send.
- Analytics provider. Google LLC operates Google Analytics 4 on sugra.systems. Google receives aggregate page-view telemetry, anonymized IP, browser and device characteristics, and a randomly generated client identifier. The Google Analytics tag is loaded only after you accept non-essential cookies through the consent banner; if you reject, no analytics telemetry is sent to Google. Note that sugra.systems also embeds Google Fonts hosted on `fonts.googleapis.com` and `fonts.gstatic.com` for typography; those font requests share basic browser metadata (IP, user-agent) with Google as part of standard HTTP delivery and are independent of analytics consent. Google operates under its Ads Data Processing Terms, and IP anonymization is enabled by default for GA4.
- Sign-in providers. If you use OAuth sign-in or account linking, GitHub, Inc., Google LLC, or Microsoft Corporation (Microsoft identity platform) process the sign-in handshake and provide us your basic profile (name, email address, profile photo URL). We do not transmit your account data to these providers beyond the handshake itself.
- Avatar service. Automattic Inc. operates Gravatar. Where your account has no provider profile photo, pages that display your avatar request a fallback image from gravatar.com addressed by a one-way SHA-256 hash of your email address. Automattic receives that hash and standard HTTP request metadata (IP address, user-agent) from the viewing browser as part of image delivery, and never your raw email address.
- Advertising platforms. Where you have allowed advertising measurement, we report subscription purchases to the advertising platforms we use, so that a purchase can be matched to the advertisement that led to it: Meta Platforms Ireland Limited for people in the European Economic Area and Meta Platforms, Inc. elsewhere (Facebook and Instagram advertising); Google Ireland Limited or Google LLC depending on your region (Google Ads, a role separate from the analytics and sign-in roles above); and X Internet Unlimited Company for people in the European Economic Area, Switzerland, and the United Kingdom, and X Corp. elsewhere (X advertising). Each receives the click identifier that platform itself issued, a one-way SHA-256 hash of your email address, the amount and currency of the purchase, and an identifier we generate for the event so that one purchase is not counted twice. We do not send your raw email address, your name, your credentials, your API keys, or anything about your use of the API. Not every platform listed is active at any given time, and a platform receives nothing while its integration is switched off. If we add a platform to this list, this policy will say so before that platform receives anything.
- Legal authorities. Where required by law, regulation, or legal process, or where we in good faith consider disclosure necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
An advertising platform is not simply our processor. Unlike the providers listed above, an advertising platform may use part of what it receives for its own purposes rather than only on our instructions, and we would rather be plain about that than bury it. The role differs from platform to platform, and for the same platform from one kind of data to another, so we set the three out separately below instead of giving you a single label that would be wrong for at least one of them.
Under Meta's Business Tools Terms, Sugra and Meta are joint controllers for the collection and transmission of the purchase event, and Meta is an independent controller for what it does with that data afterwards, including improving its own advertising systems. Meta acts as a processor for the matching and measurement it performs on our behalf. The essence of the joint arrangement is this: Sugra decides which events are sent and remains answerable to you for that decision; Meta decides what it does with an event once received and is answerable for that; and whichever of us receives a request meant for the other will pass it on.
For X, our integration requires the setting that keeps conversion events under X's processor terms, so that X handles both the identifiers used to match you to an X account and the events themselves on our instructions, rather than being free to use them to improve its own advertising models. For Google, the split follows Google's own terms: Google acts as our processor for the services covered by its Ads Data Processing Terms, including the matching of a hashed email address, and as an independent controller for the parts of Google Ads that fall outside them. Each platform operates under its own published terms and its own international transfer mechanism, and you may exercise your rights directly against a platform as well as against us.
We do not share personal information with data brokers, and we do not provide it to anyone so that they can market their own unrelated products to you. Apart from the advertising measurement described above, and the providers listed above, we do not disclose personal information to advertisers or marketing networks.
7. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law. Specific retention periods include:
- Account data (users, authentication, API keys, OAuth clients): retained for the duration of the account. On account deletion, personal data is initially marked as deleted and then hard-deleted approximately ninety (90) days thereafter by a scheduled process, except where retention is required for billing records, legal obligations, or the defense of legal claims.
- API usage metadata (daily aggregate request counts): retained for up to fourteen (14) months, enabling annual Subscribers to review their usage history. Older records are removed by a scheduled purge.
- Login history: retained for twelve (12) months from each sign-in, then deleted by a scheduled process; deleted earlier if the account is deleted.
- OAuth access and refresh tokens: retained for the active lifetime of the token, plus approximately ninety (90) days after token expiry for security audit purposes, then purged. Tokens you explicitly revoke (for example, by disconnecting a connected application in Settings) are purged promptly on the next scheduled cleanup.
- Access logs: up to thirty (30) days, as described in Section 5.
- Contact form submissions and email correspondence: up to three (3) years.
- Billing records: retained as required by applicable tax, accounting, and payment regulations (typically at least seven years in the United States).
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to access - request a copy of your data.
- Right to rectification - request correction of inaccurate data.
- Right to erasure - request deletion of your data.
- Right to restriction - limit how we process your data.
- Right to data portability - receive your data in a machine-readable format.
- Right to object - object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent - where processing is based on consent.
- Right to lodge a complaint - with your national data protection authority.
Self-serve erasure. You may delete your account at any time from the Settings page at app.sugra.ai. Deletion triggers the retention schedule described in Section 7.
Other requests. To exercise any other right, including requests for access, rectification, or portability, contact us at privacy@sugra.systems. We will respond within thirty (30) days, extendable where the request is complex, in accordance with applicable law. A self-service data export is planned for a future release. We may request information reasonably necessary to verify your identity before acting on a request.
United States residents. If you live in a state with a comprehensive consumer privacy law, Section 15 sets out the additional rights you have and how to exercise them.
9. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit over public networks, encryption at rest where supported by the underlying storage, role-based access controls, network segmentation between public-facing and internal systems, private endpoints for shared datastores, logging of administrative events, and documented incident response procedures.
No method of transmission over the Internet or of electronic storage is perfectly secure. While we strive to protect your information, we cannot guarantee absolute security.
10. International Transfers
Sugra Systems, Inc. is incorporated in Delaware, USA, and its primary processing operations occur in the United States. If you are located outside the United States, your information may be transferred to, stored in, and processed in the United States or in other jurisdictions where our sub-processors operate.
Where required by applicable law, we rely on appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms recognized by other jurisdictions. Further detail is set forth in the Data Processing Agreement.
11. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from individuals under sixteen (16) years of age. If we learn that we have collected personal information from a child under this age without verifiable parental consent, we will delete it promptly.
Access to paid subscriptions and acceptance of the Terms of Service require the user to be at least eighteen (18) years of age or otherwise have legal capacity to contract under applicable law.
12. Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, personal information held by Sugra may be transferred as part of such transaction. We will notify you through the Service and, where practical, by email of any change in ownership or use of your personal information, as well as any choices you may have.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days' advance notice by email to active account holders and a prominent notice at sugra.systems, and will update the "Last updated" date above. Continued use of the Service after the effective date of a change constitutes acceptance.
14. Screening Data (Sugra Entity)
This section describes a specific processing activity that involves the personal data of individuals who are not Sugra account holders or Subscribers. Sugra Entity returns screening signals that compare a name, identifier, or entity against public sanctions, watchlist, politically-exposed-person ("PEP"), and adverse-media sources. To do so, Sugra processes personal data about the individuals who appear in those sources.
14.1 Personal data processed and its sources
- Sanctions and watchlist subjects. Names and name-parts, aliases, jurisdiction, listing program and dates, and any secondary public identifiers present on the official list (for example passport, national ID, tax ID, vessel or aircraft identifier), processed from official government and intergovernmental sources.
- Politically-exposed persons. Names and name-parts, public position or role, jurisdiction, and associated dates, processed from public records.
- Adverse-media subjects. Names and references to publicly-available news in which the individual is linked to defined financial-crime risk categories (for example fraud, corruption, sanctions evasion, terrorist financing).
Sugra processes only personal data already contained in public, sovereign, intergovernmental, or openly-licensed sources. Sugra does not use leaked or covertly-obtained data, does not add contact details or behavioural data, and does not perform people-search or build profiles of individuals beyond the screening purpose.
14.2 Lawful basis
For sanctions and watchlist screening, Sugra and its Customers process personal data primarily to comply with legal obligations relating to sanctions and the prevention of financial crime (GDPR Article 6(1)(c)), supported by legitimate interests (Article 6(1)(f)).
For PEP and adverse-media screening, Sugra relies on its legitimate interests and those of its Customers and the public interest in preventing financial crime, corruption, and sanctions evasion (Article 6(1)(f)), having carried out a legitimate-interest assessment that weighs those interests against the rights and freedoms of the individuals concerned. Because the sources are public and the safeguards in Section 14.4 apply, Sugra considers that those interests are not overridden by the individuals' interests in this context. Consent is not used as the basis for this processing, because the individuals concerned are not Sugra's customers.
14.3 Retention
Screening reference data is refreshed from its public sources on a recurring schedule, and superseded entries are replaced as the sources change, so Sugra mirrors the current public state rather than building a long-lived historical record of any individual. Point-in-time snapshots used for audit queries reflect the public state of the lists on a given date. Sugra does not retain screening reference data about an individual beyond what is necessary for the screening purpose and any applicable legal-retention requirement.
14.4 Rights of screened individuals and safeguards
Individuals who are the subject of screening data may exercise their rights of access, rectification, erasure, restriction, and objection by contacting privacy@sugra.systems. Because this processing relies on legitimate interests, individuals have a right to object under Article 21; Sugra will assess each objection and will stop processing unless it demonstrates compelling legitimate grounds or the processing is necessary for the establishment, exercise, or defence of legal claims or for compliance with a legal obligation. Where data Sugra holds mirrors an authoritative public source, Sugra will, where feasible, correct or suppress the entry on its side and direct the individual to the authoritative source for upstream correction.
No solely-automated decisions by Sugra. A screening signal is a technical signal, not a determination. Sugra does not make any decision producing legal effects, or similarly significant effects, about a screened individual within the meaning of Article 22 of the GDPR. Screening signals are intended to be reviewed and independently verified by a human before any decision is taken, and the Sugra Acceptable Use Policy requires Customers to apply that independent verification and prohibits using a screening signal as the sole basis for decisions about an individual.
15. United States State Privacy Rights
This section applies if you are a resident of a United States state with a comprehensive consumer privacy law, including California (the California Consumer Privacy Act as amended by the California Privacy Rights Act), Colorado, Connecticut, Texas, Virginia, and other states with equivalent laws. It supplements the rest of this policy and does not replace it.
15.1 Sale and sharing for advertising
The advertising measurement described in Sections 2, 4, and 6 discloses identifiers to advertising platforms that use them for cross-context behavioral advertising. Under California law that counts as a "sale" and as "sharing" of personal information, and under other state laws as "targeted advertising", whether or not we are paid anything for it. We would rather say so plainly than rely on the fact that no money changes hands: we treat this disclosure as a sale and as sharing under those laws.
The categories disclosed for this purpose are identifiers (an advertising click identifier issued by the platform, and a one-way SHA-256 hash of your email address) and commercial information (the amount and currency of a subscription purchase, and an event identifier used for de-duplication). The recipients are the advertising platforms named in Section 6. No other category of personal information is disclosed for this purpose. We have not sold or shared the personal information of any consumer we know to be under sixteen (16) years of age.
15.2 How to opt out
Advertising measurement is off until you turn it on. Nothing is disclosed to an advertising platform unless you have affirmatively allowed it on app.sugra.ai, and you can withdraw that permission at any time from your profile on app.sugra.ai, which stops any further disclosure. You therefore do not need to submit an opt-out request in order to be excluded; if you have never given permission, you are already excluded. You may also write to privacy@sugra.systems and we will record the opt-out for you.
We also honor a browser opt-out preference signal such as Global Privacy Control. When you are signed in on app.sugra.ai and your browser sends the signal, we treat it as a withdrawal of advertising measurement for your account: any prior permission is recorded as withdrawn, and no further disclosure is made. The signal does not permanently lock the setting. You can allow measurement again only by an explicit action in your profile or the in-app prompt, and only while the browser is no longer sending the signal; while the signal is still on, a new permission is refused. Turning the signal off does not by itself restore a prior permission - you must allow measurement again if you want it. You may still write to privacy@sugra.systems and we will record the opt-out for you. For anyone who never gave permission, there is nothing being shared to begin with.
15.3 Other rights
Subject to verification and to the exceptions in applicable law, you may request to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting or disclosing it, and the categories of third parties to whom it was disclosed; to correct inaccurate personal information; to delete personal information; and, where your state provides it, to obtain a portable copy. We will not discriminate against you for exercising any of these rights: the Service, its prices, and its features are the same whether or not you allow advertising measurement.
Requests go to privacy@sugra.systems, and account deletion is also self-serve from the Settings page at app.sugra.ai. We will acknowledge and respond within the period your state's law allows, and we may ask for information reasonably necessary to verify that the request is yours. An authorized agent may submit a request on your behalf with proof of authorization, and we may still ask you to verify your own identity. If we refuse a request, our response will say why, and you may appeal it by replying to that response or by writing to legal@sugra.systems; if the appeal is denied, you may contact your state attorney general.
We do not process personal information for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you, and we do not use or disclose sensitive personal information for purposes that require an option to limit that use.
16. Contact
For privacy-related questions, requests, or concerns:
- Email: privacy@sugra.systems
- Legal inquiries: legal@sugra.systems
- Support: support@sugra.systems
- Company: Sugra Systems, Inc., c/o LegalInc Corporate Services Inc., Middletown, Delaware, USA