Privacy Policy
Effective: July 7, 2026
This Privacy Policy explains how Friese Regulatory LLC, operating the SubstantiatePro service (the “Service”), collects, uses, shares, and protects information about users of the Service. By accessing or using the Service, you agree to the practices described in this Policy. Please read it carefully.
1. Scope and Application
This Policy applies to information collected through the SubstantiatePro web application, its associated APIs, and any communications between users and our team in connection with the Service. It does not apply to third-party websites, services, or platforms that may be linked from or integrated with the Service; those have their own privacy practices.
This Policy applies to information about individual users of the Service. Information you upload about products, claims, ingredients, or studies is treated as Customer Content under our Terms of Service and is governed by that agreement.
The Service is offered to, and intended for, customers located in the United States, as further described in Section 11.
2. Information We Collect
We collect the following categories of information:
2.1 Account Information
When you register an account, we collect your name, business email address, business name and contact information, role or title, and credentials necessary to authenticate you. If you sign in through a third-party identity provider, we receive information that provider shares with us per your authorization.
2.2 Billing Information
We bill subscriptions by invoice. When you pay an invoice or set up automatic recurring payment, our third-party payment processor collects your payment details (credit card or bank/ACH account information) and billing address on our behalf. We do not store full payment card or bank account numbers on our systems. We retain transaction records, invoice information, and limited payment identifiers (such as the last four digits of your payment method) for accounting and customer support purposes.
2.3 Customer Content
Through use of the Service, you upload or provide content including but not limited to product labels, ingredient lists, claims, clinical study PDFs, brand information, regulatory documentation, and marketing materials (“Customer Content”). Customer Content may contain confidential business information. We treat Customer Content as your confidential information and process it only to provide the Service to you, as described in Section 3 and our Terms of Service. Customer Content is governed by the license and confidentiality terms set forth in our Terms of Service.
2.4 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, dossiers generated, claims assessed, queries made, dates and times of access, and the device and browser used. This information is used to operate, improve, and secure the Service.
2.5 Technical Data
We collect technical information such as IP address, browser type, operating system, device identifiers, and similar telemetry. This information helps us deliver the Service, diagnose problems, and prevent abuse.
2.6 Communications
When you contact us by email, support form, or other communication channel, we retain the content of those communications and any associated metadata.
3. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Service, including generating regulatory analyses, substantiation dossiers, and related outputs you request.
- Authenticate users, manage accounts, and provide customer support.
- Process subscriptions, billing, refunds, and related transactions.
- Communicate with you about the Service, including service announcements, security alerts, and responses to your inquiries.
- Monitor and analyze usage patterns, diagnose technical problems, and improve the performance and reliability of the Service.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service or applicable law.
- Comply with legal obligations, respond to lawful requests by public authorities, and protect the rights, property, or safety of our users, our company, or others.
- Send marketing communications about the Service, subject to your right to opt out.
We only collect and use personal information that is reasonably necessary for the purposes described above.
4. AI Model Training, Customer Content, and De-Identified Data
We do not use Customer Content to train any AI models — either our own or those of our third-party AI providers. Customer Content is processed solely to deliver the outputs you request and is not retained by our AI providers beyond the duration necessary to complete the requested operation, in accordance with their respective data processing terms. We do not sell, license, or otherwise share Customer Content with third parties for the purpose of training, fine-tuning, or developing AI models. Our third-party AI providers operate under terms that prohibit using customer-submitted content for model training. See Section 5 for a list of subprocessors.
Notwithstanding the foregoing, we may create, retain, and use de-identified and aggregated data derived from use of the Service, including after termination of your account, to operate, analyze, secure, and improve the Service, consistent with our Terms of Service. Such data is maintained in a form that does not identify you, your business, or any individual and that cannot reasonably be used to re-identify Customer Content. Because it is de-identified and aggregated, this data is not Customer Content and is not personal information, and the retention and deletion commitments in this Policy do not apply to it.
5. How We Share Information
We share information only as described in this Policy. Specifically:
5.1 Service Providers and Subprocessors
We engage third-party service providers to perform functions on our behalf. These providers receive only the information necessary to perform their function and are contractually obligated to protect that information. Current subprocessors include:
- Vercel Inc. (United States) — application hosting and infrastructure
- Supabase (United States) — data storage and authentication
- Anthropic, PBC (United States) — large language model inference for regulatory analysis
- Stripe, Inc. (United States) — subscription billing and payment processing
- Resend (United States) — transactional email delivery
We conduct due diligence on all subprocessors and maintain data processing agreements that require them to protect information at least as stringently as this Policy. We will update this list as our subprocessors change. You may request the current list at any time by contacting us at privacy@substantiatepro.com.
5.2 Legal Requirements
We may disclose information if required to do so by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.
5.3 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, information may be transferred as part of that transaction, subject to commercially reasonable obligations to maintain confidentiality and limit use of the information consistent with this Policy.
5.4 With Your Consent
We may share information with your consent or at your direction, including when you ask us to share information with a third party (such as a co-manufacturer, retailer, or consultant).
5.5 No Sale of Personal Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable law including the CCPA/CPRA.
6. Data Retention
We retain personal information for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account information: retained for the duration of your subscription and for ninety (90) days after account termination, after which it is deleted or anonymized.
- Customer Content: retained for the duration of your subscription. Following account termination, Customer Content is retained for thirty (30) days to allow you to export data, after which it is permanently deleted from active systems (subject to any legal or backup retention obligations). This deletion obligation does not apply to de-identified, aggregated data as described in Section 4, which we may retain and use as permitted by our Terms of Service.
- Billing records: retained for the period required by applicable tax, accounting, and financial regulations.
- Backup copies: retained for the period necessary to maintain operational continuity, not to exceed ninety (90) days, after which they are overwritten or deleted.
You may request earlier deletion at any time by contacting us, subject to our legal and contractual obligations.
7. Data Security
We maintain appropriate administrative, technical, and physical safeguards designed to protect the information we collect against unauthorized access, alteration, disclosure, or destruction, in accordance with industry standards. These measures include encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, regular security reviews, and vendor due diligence.
In the event of a security incident that compromises personal information or Customer Content, we will notify you as soon as commercially practicable and in compliance with applicable law, including the Delaware Data Breach Notification Act, the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), and any other applicable breach notification statutes. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your state of residence, you may have certain rights with respect to information we hold about you, which may include the rights to:
- Access the information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of information, subject to our legal and contractual obligations.
- Receive a portable copy of information you provided to us.
- Opt out of the sale or sharing of personal information (which we do not engage in) and the use of sensitive personal information for certain purposes.
- Opt out of marketing communications. Service-related communications cannot be opted out of while your account is active.
To exercise these rights, contact us at privacy@substantiatepro.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before processing certain requests, and you may use an authorized agent to submit a request where permitted by law.
9. U.S. State Privacy Rights
We serve customers located in the United States and comply with applicable U.S. state privacy laws.
California (CCPA/CPRA). If you are a California resident, you have the right to know what personal information we collect, to delete personal information, to correct inaccurate personal information, to opt out of the sale or sharing of personal information (which we do not engage in), to limit the use of sensitive personal information, and to non-discrimination for exercising these rights. For details on the categories of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it, please see Sections 2 and 5 of this Policy. We do not sell or share personal information, and we do not use sensitive personal information for purposes that would trigger additional rights to limit use.
Other U.S. states. Residents of other states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, and Texas) may have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling. We honor these rights to the extent they apply to you.
To exercise any of these rights, contact us at privacy@substantiatepro.com. If we deny a request, you may appeal by replying to our response where an appeal right is provided by applicable law.
10. Do Not Track and Global Privacy Control
Some browsers offer a “Do Not Track” (DNT) signal. Because there is no common industry standard for interpreting DNT signals, the Service does not currently respond to them. Where required by applicable law, we honor recognized opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
11. United States Users and Data Location
SubstantiatePro is operated from the United States, and our infrastructure and service providers are located in the United States. The Service is offered to, and intended for, customers located in the United States. We do not target or market the Service to individuals or businesses outside the United States, and we do not rely on cross-border data transfer mechanisms. If we begin offering the Service in other jurisdictions in the future, we will update this Policy to describe any applicable transfer safeguards before doing so.
12. Cookies and Tracking Technologies
The Service uses cookies and similar technologies that are strictly necessary to operate the application, including to maintain authenticated user sessions (keeping you logged in), remember preferences, and support performance and security. Session and authentication cookies are managed through our authentication provider. We do not use advertising or cross-site behavioral tracking cookies. You can manage cookie preferences through your browser settings, but some features of the Service may not function correctly if cookies are disabled.
13. Children’s Privacy
The Service is intended for use by businesses and by individuals 18 years of age or older, and is not directed to minors. We do not knowingly collect personal information from anyone under 18 years of age. If we learn that we have collected information from a person under 18, we will delete that information promptly. If you believe we have collected such information, please contact us at privacy@substantiatepro.com.
14. Governing Law
This Policy and any dispute arising out of or relating to it are governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles, consistent with our Terms of Service.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or through a prominent notice in the Service before the changes take effect. We encourage you to review this Policy periodically.
16. Contact Us
If you have questions, concerns, or requests regarding this Policy or our privacy practices, contact us at:
Friese Regulatory LLC
Attn: Privacy
8 The Green, Ste B, Dover, DE 19901
privacy@substantiatepro.com
© 2026 Friese Regulatory LLC. All rights reserved.