Privacy Policy
Tier1/AI, operated by INS Digital Intelligence LLC
Effective: July 24, 2026
Last updated: July 24, 2026
1. WHO WE ARE
Tier1/AI ("Tier1/AI," "we," "us," "our") is a capital markets communications operating system, operated by INS Digital Intelligence LLC, a New York limited liability company with its principal place of business at 170 Ontario St, Honeoye Falls, NY 14472. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our platform, marketing site, and related services (collectively, the "Service").
2. WHO THIS POLICY APPLIES TO
This policy applies to:
- CEOs and communications professionals who operate accounts on the Service ("Clients")
- Team members invited by Clients ("Authorized Users")
- Visitors to www.tier1ai.io
- Investors and prospects whose information Clients upload or process through the Service ("Investor Contacts")
You must be at least 18 years old to use the Service. The Service is not directed to children under 13 and we do not knowingly collect information from children under 13.
3. INFORMATION WE COLLECT
3.1 Information you provide directly:
- Account information: name, business email, company, ticker symbol, password, billing details
- Content you create or upload: investor lists, CRM notes, uploaded documents (10-Ks, presentations, drafts), campaign copy, email templates, tasks
- Communications: replies, feedback, support requests
3.2 Information from connected accounts:
When you connect a Google or Microsoft account, we access data covered by the OAuth scopes you approve. See Section 6 for detailed treatment.
3.3 Information collected automatically:
- Usage data: pages visited, features used, agents run, actions taken
- Device and log data: IP address, browser, operating system, timestamps
- Cookies and similar technologies (see Section 10)
3.4 Information from third parties:
- Public market data: quotes, filings, mentions, ownership records
- Visitor identification services (GetUntitled, RAEK) may resolve website visitor identity from IP, referrer, and UTM data
4. HOW WE USE INFORMATION
We use information to:
- Operate, maintain, and improve the Service
- Deliver the features you request (briefings, strategy generation, outbound campaigns, engagement tracking)
- Communicate with you about the Service, billing, and support
- Protect the Service and detect fraud or abuse
- Comply with legal obligations
- Develop aggregated, de-identified intelligence to improve the platform (see Section 8)
5. LEGAL BASES (for users in jurisdictions requiring them)
We process personal data based on:
- Performance of a contract (delivering the Service you subscribed to)
- Legitimate interests (improving the Service, security, fraud prevention)
- Consent (marketing communications, optional integrations)
- Legal obligation (tax, accounting, court orders)
6. GOOGLE USER DATA AND LIMITED USE
When you connect a Google account, Tier1/AI requests permission to access Gmail and Google Calendar data via Google OAuth.
Scopes we may request:
gmail.modify- read, send, draft, and manage messagescalendar.readonly- read calendar eventsuserinfo.email- retrieve the email address of the signed-in user
Use of Google user data by Tier1/AI is subject to and complies with the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
(a) We only use Google user data to provide user-facing features of the Service - sending investor emails, tracking engagement, drafting replies, surfacing calendar context, and identifying the signed-in user's email.
(b) We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models.
(c) We do not transfer Google user data to third parties except (i) as necessary to provide or improve user-facing features of the Service, (ii) to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with notice to Clients.
(d) We do not allow humans to read Google user data unless (i) we have your affirmative consent for specific messages, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is necessary to comply with applicable law, or (iv) the data has been aggregated and de-identified and is used for internal operations in accordance with applicable privacy requirements.
(e) We do not sell Google user data.
You can revoke Tier1/AI's access to your Google account at any time at https://myaccount.google.com/permissions.
7. MICROSOFT USER DATA
When you connect a Microsoft work or school account (Microsoft Entra ID), Tier1/AI requests permission to access Outlook and Microsoft Graph data via Microsoft OAuth.
Scopes we may request:
- Mail.Read, Mail.Send, Mail.ReadWrite - read, send, and manage messages
- Calendars.Read - read calendar events
- User.Read - retrieve basic profile information
We handle Microsoft user data on the same terms as Google user data in Section 6: only for user-facing features, never for training generalized AI models, no sale, no unnecessary human access, and no transfer to third parties beyond the exceptions listed in Section 6(c).
You can revoke Tier1/AI's access to your Microsoft account at any time in your Microsoft account settings.
8. HOW TIER1/AI USES DATA TO IMPROVE THE PLATFORM
Tier1/AI develops proprietary intelligence to improve the Service. This uses aggregated, de-identified data only.
We use the following categories for platform intelligence:
- Aggregated campaign metrics (send counts, open rates, click rates, reply rates)
- Engagement patterns (timing, audience segment, channel performance)
- Agent usage patterns
- Strategy outcomes and effectiveness
- Industry benchmarks
- Content characteristics measured against outcomes (whether an attachment was present, attachment category such as "investor presentation" or "video link," subject line features, message length, day and time of send)
We do not use the following for platform intelligence or model training:
- Gmail message body content, subject lines, or metadata
- Microsoft message body content, subject lines, or metadata
- Personally identifiable investor information (names, personal email addresses, personal notes)
- The contents of documents you upload (10-Ks, presentations, drafts, other client materials)
Data used for platform intelligence is de-identified before use. No individual Client, Investor Contact, company, or message is identifiable in the resulting models or benchmarks.
9. SERVICE PROVIDERS AND SUBPROCESSORS
We share information with the following service providers who process data on our behalf under written agreements:
Infrastructure and delivery:
- Supabase - database, authentication, edge functions, file storage
- Vercel - application and marketing site hosting
- Mailgun - transactional and outbound email delivery
- Stripe - payment processing (when enabled)
AI and voice:
- Anthropic - Claude API for briefings, strategy, drafting, and analysis
- OpenAI - embeddings for the knowledge base
- ElevenLabs - text-to-speech for audio briefings
Market and identity data:
- Finnhub - stock quotes and company profiles
- Yahoo Finance - historical stock chart data
- GetUntitled - website visitor identification
- RAEK - website visitor identification (redundancy)
Identity and authentication:
- Google - OAuth sign-in and Gmail integration
- Microsoft - OAuth sign-in and Outlook integration
Analytics and monitoring:
- Google Analytics - website usage analytics
- Sentry - application error monitoring
Each provider processes data only for the purposes we specify and under contractual confidentiality and security obligations. Third-party AI providers (Anthropic, OpenAI, ElevenLabs) do not train their foundation models on data flowing through their paid API tiers.
We may add or replace subprocessors as the Service evolves. We will provide at least 30 days' notice to Clients before adding a new subprocessor that materially changes how personal data is processed.
10. COOKIES AND TRACKING
We use cookies and similar technologies to keep you signed in, remember preferences, measure usage, and secure the Service. See our Cookies Policy at https://www.tier1ai.io/cookies for details on the specific cookies used and how to control them.
11. DATA RETENTION
We retain information for as long as needed to provide the Service and for the periods described below.
11.1 Client content (investor lists, CRM notes, uploaded documents, briefings, drafts, campaign copy):
- Retained while the account is active
- After account closure, retained for 90 days to allow reactivation and data export
- Permanently deleted after the 90-day closure window
11.2 Billing lifecycle:
- Invoice unpaid at day 15: account is placed in read-only mode. The Client can log in and access data. Outbound campaigns, briefings, scheduled sends, and background jobs are halted.
- Days 15 to 90: automated payment reminders continue.
- Payment received before day 90: account fully resumes with no data loss.
- Payment not received by day 90: account closes and Section 11.1 deletion timeline begins.
11.3 Billing records:
Retained for 7 years to comply with tax and accounting requirements.
11.4 Security and audit logs:
Retained for 12 months for security investigations and dispute resolution.
11.5 Aggregated, de-identified data:
Aggregated and de-identified data described in Section 8 may be retained indefinitely because it does not identify individuals.
12. YOUR RIGHTS
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your information (subject to retention requirements above)
- Export your information in a portable format
- Object to or restrict certain processing
- Withdraw consent
- Opt out of the sale or sharing of personal information (Tier1/AI does not sell personal information)
To exercise these rights, contact privacy@tier1ai.io. We respond within 30 days. We will not discriminate against you for exercising your rights.
California residents have specific rights under the CCPA/CPRA. New York residents have rights under applicable New York privacy laws. EU/UK residents have rights under the GDPR and UK GDPR.
13. SECURITY
We implement administrative, technical, and physical safeguards designed to protect information, including encryption in transit, encryption at rest for stored credentials, access controls, and monitoring. No system is perfectly secure. If we become aware of a security incident affecting your information we will notify you as required by applicable law.
Report security concerns to privacy@tier1ai.io.
14. INTERNATIONAL TRANSFERS
Tier1/AI is operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. Where required, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
15. CHILDREN
The Service is not intended for anyone under 18. We do not knowingly collect information from children under 13. If you believe a child has provided us with information, contact privacy@tier1ai.io and we will delete it.
16. CHANGES TO THIS POLICY
We may update this policy from time to time. If we make material changes we will notify Clients by email and update the "Last updated" date at the top of this page. Continued use of the Service after changes take effect constitutes acceptance.
17. CONTACT US
Privacy inquiries and data requests: privacy@tier1ai.io
User support: support@tier1ai.io
General and business contact: services@tier1ai.io
Mailing address:
INS Digital Intelligence LLC
170 Ontario St
Honeoye Falls, NY 14472
United States
18. GOVERNING LAW
This Privacy Policy is governed by the laws of the State of New York, without regard to conflict-of-law principles.