Privacy Policy
This Policy describes how Capsid Systems, LLC, a Georgia limited liability company doing business as Regulatory Impact collects, uses, discloses, and retains information through RegulatoryImpact.com and related services.
1. Information collected
We collect account and profile data such as name, email, organization, role, country, credentials, preferences, verification status, and marketing choices; billing and transaction data such as billing contact, invoice, tax, subscription, and Stripe customer identifiers; and technical data such as IP address, browser/device information, authentication events, pages/features used, search queries, error logs, and security events.
We process prompts, queries, saved projects, notes, uploaded files, annotations, support messages, and generated outputs that you choose to submit. Do not submit PHI, patient-level data, confidential regulatory submissions, trade secrets, or export-controlled material. We do not intentionally store full card numbers.
2. Purposes and providers
- Authentication and account administration: email, credentials, sessions, and security logs.
- Hosting and storage: accounts, workspaces, projects, and content needed to provide the Service.
- Billing: Stripe processes payment details and transaction identifiers; we receive customer, subscription, invoice, and payment status data.
- Analytics and security: first-party usage events, IP/device signals, fraud prevention, diagnostics, performance data, and—where enabled—Google Analytics 4 measurement of page views, acquisition, and feature usage. We do not send search text, prompts, workspace content, design snapshots, email addresses, or session replay data to GA4.
- AI features: selected regulatory data-processing jobs may send the minimum necessary public or operational input to the configured provider. We do not send Customer Content to general-purpose model training and do not permit providers to do so.
- Email and support: contact details and the contents needed to respond to requests.
- Public sharing: content and metadata deliberately published or shared may be available to link recipients or the public until revoked, expired, or deleted.
We may use deidentified or aggregated information for security, measurement, and product improvement. We do not sell personal information or use it for targeted advertising under this Policy.
3. Cookies and choices
Strictly necessary cookies and local storage support authentication, security, preferences, and the Service. Analytics and advertising-measurement defaults are configured separately by region and deployment policy. Where required, these technologies are activated only after the applicable notice and consent choice; Google Consent Mode communicates the resulting analytics, advertising-storage, advertising-user-data, and personalization states. Advertising measurement may use first-party cookies and ad-click identifiers to associate an ad with a later subscription, but we keep personalized advertising and remarketing disabled. You may disable cookies in your browser, though some features may stop working. Contact us for access, correction, deletion, portability, or privacy-choice requests.
Analytics settings
Allow privacy-filtered GA4 measurement of public pages and product-funnel events. Restricted program links, search text, prompts, account identifiers, and workspace content are excluded.
Advertising measurement
Allow Google to store first-party advertising cookies and use ad-click data to measure which ads lead to subscriptions. This requires analytics measurement. Personalized advertising and remarketing remain disabled.
4. Sharing and retention
We share information with hosting, database, storage, payment, email, security, monitoring, analytics, and AI subprocessors only as needed for the disclosed purposes and under contractual restrictions. We may disclose information for legal process, safety, fraud prevention, corporate transactions, or with your direction.
We retain account and subscription records while the account is active and as needed for legal, accounting, fraud-prevention, dispute, and backup purposes. Workspace content is deleted according to account deletion and backup cycles, subject to enterprise terms. Public or link-shared content remains available until the publisher revokes, expires, unpublishes, or deletes it; copies made by recipients may remain.
5. Security and sensitive data
We use reasonable administrative, technical, and organizational safeguards, access controls, logging, and vendor controls. No system is completely secure. Notify support@regulatoryimpact.com of suspected incidents. The standard Service is not HIPAA-compliant, we do not provide a BAA, and we do not authorize PHI or directly identifiable patient data.
6. US scope, international processing, and children
The Service is initially offered for US business use. Information may be processed in the United States by our service providers. We do not intentionally offer the Service to children; eligibility is limited to people 18 or older, and we do not knowingly collect information from anyone under 18.
7. Changes and contact
We will post changes with a new version date and provide additional notice for material changes. If a material change expands Customer Content or AI processing, we will obtain renewed consent where appropriate.