Privacy Policy

Last updated September 24, 2026.

DataStreet Technologies, Inc. (“DataStreet,” “we” or “us”) provides DataStreet’s websites and research platform. This Policy explains what personal information we collect, why we use it, when we disclose it, and your choices. It covers visitors, account holders, people who contact us, and personal information included in research or customer content.

For account administration, billing and our own website operations, DataStreet determines the purposes of processing. When processing workspace content on behalf of a business customer, that customer controls its content and authorized uses, subject to law and our agreement. Your organization may manage your account and information shared within its workspace. A signed data-processing agreement controls where it conflicts with this Policy.

Information We Collect

Information you provide. This includes your name, email, organization, company website, preferences, company information, notes, feedback, submitted content, and contact or support messages. Provide only information you are authorized to share. Do not submit passwords, API keys, payment-card details, health records or other highly sensitive personal information in workspace content or support messages.

Account, payment and integration information. Google’s authentication service protects and manages passwords for email sign-in. DataStreet securely passes credentials to Google for authentication and does not store your password. If you choose Google or Microsoft sign-in, we receive identity information needed to create or access your account, such as your name, email and provider identifier. Microsoft sign-in requests only basic identity information, not access to your email messages, files or calendar. Stripe processes payment details; DataStreet does not collect or store full payment-card numbers. We receive subscription, transaction and billing-status information. Available integrations provide the account identifiers, permissions and content you authorize for that connection, not unrestricted access to your other accounts or conversations.

Usage and device information. Our service and hosting providers process IP addresses, browser and device information, request timestamps, pages or features accessed, errors and security logs. Cookies and similar storage support sign-in, security and preferences.

Public and third-party information. Research may include public business and professional information from company websites, publications, professional profiles, reviews and other public sources or data providers. This can include names, roles, professional statements and source links. Authorized workspace users may also provide information about other people.

How It Is Used

We use information to provide and personalize the service, manage accounts and subscriptions, deliver research and requested features, respond to inquiries, maintain and improve quality, protect against misuse and security threats, and comply with legal obligations. We also send account, billing, security and service notices. Where permitted, we may send product news or offers; you can opt out of marketing without losing essential account notices.

When We Share Information

Service providers. We share information as needed with providers supporting hosting, storage, authentication, AI-assisted processing, payments, communications, security and support. They are subject to contractual or legal protections appropriate to the information and their role. Private workspace context is not submitted to public-source data collection providers.

Your organization and your choices. Information may be visible to authorized users in your organization or recipients you select through sharing, exports or connected services. Review the audience before sharing confidential or personal information. Copies downloaded or delivered to another service are subject to the recipient’s handling and cannot necessarily be recalled by DataStreet.

Legal, safety and business purposes. We may disclose information to comply with law, legal process or lawful government requests; protect rights, safety and security; investigate misuse; or establish, exercise or defend legal claims. We limit legally compelled disclosures as required and give notice where lawful and practical. We may share information with professional advisers under appropriate confidentiality duties or in connection with a financing, merger, acquisition, reorganization or business sale, subject to appropriate protections and legally required notice or consent.

We do not make private workspace content public or use it in advertising without permission. We may use aggregated or de-identified information that no longer reasonably identifies a person to understand performance and improve the service. We maintain such information in that form except where law permits otherwise.

Cookies and Similar Technologies

We and our website and platform providers use cookies and similar technologies for authentication, session security, preferences and reliable operation. You can control cookies through your browser and clear locally stored data, but blocking essential cookies can prevent sign-in or other features from working. Connected third-party services apply their own policies. Where law requires consent for nonessential technologies, we will request it before using them.

Retention and Deletion

We retain personal information for as long as reasonably needed to provide the service, maintain your research history, fulfill the purposes described here, and meet legal, accounting, dispute-resolution and security obligations. Retention depends on the information, account relationship, your requests and applicable requirements; it is not unlimited merely because you created an account.

Where connected-channel context processing is enabled, stored message excerpts stop being used after 30 days and extracted context after 180 days. Disconnecting a context channel stops future collection and use of its learned context. Application expiry and deletion from backups or infrastructure can occur on different schedules. These limits do not automatically delete reports already shared or downloaded. Earlier early-access request records remain subject to the 90-day deletion schedule disclosed when collected, unless you separately created an account or another lawful retention requirement applies.

Request account-data deletion using the contact details below. We may retain limited records where required or permitted for legal, billing, fraud-prevention and security purposes and explain applicable limitations in responding. Canceling a subscription, disconnecting an integration and deleting account data are separate actions.

Security

We use reasonable administrative, technical and organizational safeguards designed to protect personal information. No service, storage system or transmission is completely secure, and we cannot guarantee absolute security. Protect your credentials, limit access appropriately, and promptly contact us about suspected unauthorized use. This does not limit duties imposed by law or a signed agreement.

Your Choices and Privacy Rights

Use available account controls or contact us to request access, correction, export or deletion. You can disconnect optional integrations and opt out of marketing through an unsubscribe link or by contacting us. Essential service and billing communications continue while needed.

Depending on your location and applicable law, you may have rights to know about or access your information; correct, delete or obtain a portable copy; restrict or object to processing; withdraw consent; or opt out of certain uses or disclosures. Where applicable, you may use an authorized agent, appeal a denied request, or complain to a data-protection authority. We will not unlawfully discriminate against you for exercising privacy rights. Rights are subject to lawful exceptions and are not all available in every jurisdiction.

We may reasonably verify identity and authority before acting and will respond within the period required by law. For information processed on behalf of your organization, we may refer the request to its administrator or assist it in responding. Withdrawing consent does not affect processing already lawfully performed and may affect features that depend on that consent.

International Processing and Legal Bases

DataStreet is based in the United States. Information may be processed in the United States or other countries where our providers operate, whose laws may differ from those where you live. Where applicable law requires safeguards for international transfers, we use the required safeguards. Using the service is not a waiver of statutory rights.

Where a legal basis is required, we process information as necessary to perform a contract, meet legal obligations, pursue legitimate interests such as operating and securing a business service where not overridden by your rights, or with consent when required. The basis depends on the information and purpose. Contact us for details about a particular use or transfer.

Children and Third-Party Sites

The service is intended for business users aged 18 or older, not children. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information so we can investigate and take appropriate action, including deletion where required. Outside links are not endorsements, and this Policy does not govern independent third-party practices. Review their policies before providing information.

Policy Changes and Contact

We may update this Policy as the service or legal obligations change. The date above identifies the latest update. We will provide notice of material changes and obtain consent where required before applying changes to your information. An update does not itself authorize uses inconsistent with the commitments under which information was collected.

For privacy questions, requests or appeals, contact DataStreet Technologies, Inc. at marc@datastreet.ai.

Terms of Service

Back to Website →