Privacy Policy
Effective Date: May 12, 2026
Last Updated: May 12, 2026
1. Who We Are
Conviction AI LLC ("Conviction," "we," "our," or "us") operates the Conviction platform, the websites at withconviction.ai and app.withconviction.ai, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, and share personal information when you visit our websites, use the Service, or otherwise interact with us.
Our mailing address is Conviction AI LLC, 8401 Mayland Dr, Ste A, Richmond, Henrico County, VA 23294, United States. You can reach us about any privacy-related question at alex@withconviction.ai.
2. Scope
This Policy applies to:
- Visitors to our marketing websites at withconviction.ai (the "Marketing Site").
- Organizations that subscribe to the Service ("Customers") and their authorized end users ("End Users").
- Individuals who contact us, complete forms, or otherwise communicate with us.
Customers use the Service to provide certain data and content to the platform ("Customer Data"). With respect to Customer Data, the Customer is the "controller" and Conviction is the "processor" — meaning the Customer determines what data is processed and Conviction processes Customer Data on the Customer's behalf under our subscription agreement. For all other personal information described in this Policy (e.g., billing, account, and marketing data), Conviction is the controller.
If you are an End User of a Customer organization, your use of the Service is also governed by your organization's policies. Direct requests about Customer Data (e.g., to access, correct, or delete it) to your organization's administrator.
3. Information We Collect
We collect the following categories of personal information:
- Account and identity information — name, work email, organization, role, password (stored as a salted hash), profile photo, and any authentication factors you enable.
- Customer Data — content you, your organization, or your End Users create or upload while using the Service, including chat assistant messages, saved workflows, formulas, marketing release drafts, exposure/tag rules, and uploaded files.
- Third-party integration data — when you connect a third-party service (e.g., LinkedIn, Meta/Facebook, or market-data providers), we store the tokens and metadata needed to perform the connection (account label, external account name and identifier, access and refresh tokens, token expiry, and connection status). Today these integrations are used for social accounts that Conviction operates for its own outbound communications; we may expand integration capabilities to Customers in the future.
- Billing data — billing contact, billing address, last four digits of the payment card, and transaction history. Card numbers and full payment details are collected and processed directly by our payment processor, Stripe, and are not stored on our servers.
- Usage and device data — IP address, browser type and version, device type, operating system, language, time zone, referring page, pages viewed, links clicked, session timestamps, and error logs.
- Communications — the contents of messages you send us via email, contact forms, or support requests.
- Marketing data — information you provide if you sign up for marketing communications.
We do not knowingly collect special categories of personal data, biometric data, or precise geolocation data. We do not knowingly collect personal information from children; the Service is not directed to individuals under 18.
4. Sources of Personal Information
We collect information:
- Directly from you (e.g., registration, support, forms).
- From your organization (e.g., when an administrator invites you to the Service).
- Automatically through cookies, analytics, and server logs.
- From third-party services you or your organization connect, such as OAuth providers and market-data providers.
5. How We Use Your Information
We use personal information to:
- Provide, operate, secure, and improve the Service.
- Authenticate users and protect against fraud, abuse, and unauthorized access.
- Process subscriptions, invoices, and tax obligations through Stripe.
- Send service-related communications, including notifications, alerts, support, and material policy or security updates.
- Respond to inquiries and provide customer support.
- Analyze usage and product performance.
- Operate Conviction's own marketing channels (including social posts from Conviction-managed accounts).
- Comply with applicable laws and enforce our agreements.
We do not sell your personal information in exchange for monetary consideration. To the extent that our use of analytics or session-replay tools could be considered "sharing" under California law, you may opt out at any time by emailing alex@withconviction.ai or by enabling the Global Privacy Control (GPC) signal in your browser.
6. Artificial Intelligence and Machine-Learning Processing
The Service uses artificial intelligence and machine-learning systems, including large language models, to generate research outputs, summaries, suggestions, and chat-assistant responses. We currently use:
- OpenAI(GPT and related models) under OpenAI's API terms.
- Google Gemini under Google's API terms.
When you submit a prompt or content to a feature that uses these systems, the relevant inputs and outputs are transmitted to and processed by the AI provider so the feature can return a response. Each provider has its own privacy and data-retention policies, which we encourage you to review.
We do not use Customer Data to train foundation models, and we configure our integrations with these providers to disable provider-side training on our API traffic where the provider supports such controls. We may use aggregated, de-identified, or anonymized data derived from use of the Service to improve our own product features.
AI outputs may be inaccurate, incomplete, or biased. Outputs are not investment advice and should be independently verified before being used to make any decision.
7. Cookies and Similar Tracking Technologies
We and our service providers use cookies, pixels, local storage, and similar technologies to operate the Service and understand how it is used.
- Strictly necessary — session cookies, CSRF tokens, and local storage used to authenticate you, remember your preferences, and maintain security.
- Vercel Analytics and Web Analytics — first-party or cookieless metrics (depending on configuration) for page views and performance.
- Google Analytics 4 — page views, sessions, and event analytics. Sets cookies prefixed with
_ga. - Microsoft Clarity — heatmaps and session-replay recordings of how visitors interact with the Marketing Site. Clarity captures interactions such as clicks, scrolls, and keystrokes. Input fields are masked by default. See Microsoft's Clarity privacy documentation for additional detail.
You can control cookies through your browser settings. Disabling strictly-necessary cookies may impair functionality of the Service. Most browsers also support "Do Not Track" or Global Privacy Control signals; we treat the GPC signal as a valid opt-out of "sharing" under California law.
8. How We Share and Disclose Information
We share personal information only in the following circumstances:
- Service providers and sub-processors — third parties that provide infrastructure or services on our behalf and are contractually obligated to safeguard personal information. Current sub-processors include:
- Vercel — hosting, content delivery, analytics, and observability.
- Stripe — payment processing.
- OpenAI — AI model inference.
- Google — AI model inference (Gemini) and analytics (Google Analytics 4).
- Microsoft — product analytics and session replay (Clarity).
- LinkedIn (Microsoft) and Meta — only when connected via OAuth to operate Conviction-managed social accounts.
- Financial Modeling Prep and similar market-data providers — to ingest market data into the platform.
- Within your organization — End User content within the Service is accessible to your organization's administrators and other authorized users as permitted by your organization.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our assets, subject to standard confidentiality protections.
- Legal and safety — to comply with applicable law, lawful requests from public authorities, valid court orders or subpoenas, or to protect our rights, property, and the safety of users or the public.
- With your consent — for any other purpose disclosed to you at the time we request your consent.
We may add or change sub-processors from time to time. Customers can request the current list by emailing alex@withconviction.ai.
9. Your Privacy Rights (U.S. State Laws)
Depending on where you live, you may have the following rights with respect to personal information that Conviction holds as a controller. The Service is currently offered to U.S. residents only.
- Right to know / access — request confirmation of whether we process personal information about you and a copy of that information.
- Right to correct — request correction of inaccurate personal information.
- Right to delete — request deletion of personal information.
- Right to portability — receive a copy of certain information in a portable format.
- Right to opt out of "sale" or "sharing" — we do not sell personal information for monetary consideration; you may opt out of any activity that could be considered "sharing" at any time.
- Right to limit use of sensitive personal information — we do not knowingly use sensitive personal information for purposes beyond what is permitted under California law without notice.
- Right to non-discrimination — we will not discriminate against you for exercising your rights.
- Right to appeal — if we deny a request, residents of states that provide an appeal right (e.g., Virginia, Colorado, Connecticut) may appeal by replying to our response with the word "Appeal."
To exercise any of these rights, email alex@withconviction.ai with your request and the email associated with your account so we can verify your identity. We will respond within the time required by applicable law (generally up to 45 days). We may need additional information to verify your identity before fulfilling a request.
If you are an End User of a Customer organization, requests relating to Customer Data should be directed to your organization's administrator; we will support our Customers in responding to such requests under our subscription agreement.
You may use an authorized agent to submit a request on your behalf, subject to our verification of the agent's authority.
10. Data Retention
We retain personal information for as long as needed to provide the Service and for the legitimate business purposes described in this Policy, unless a longer retention period is required or permitted by law. Typical categories:
- Active account data — for as long as the account is active.
- Closed account data — generally deleted or de-identified within 90 days of account closure, except as noted below.
- Customer Data — retained per the subscription agreement; on termination, deleted or returned within approximately 30 days unless otherwise required by law.
- Server and security logs — typically retained for up to 12 months.
- Billing and tax records — retained for at least 7 years for tax and audit purposes.
- Backups — may persist in encrypted form for a limited additional period and will be overwritten in the ordinary course.
11. Data Security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, role-based access controls, audit logging, and vendor due diligence. No system is perfectly secure, however, and we cannot guarantee the absolute security of any information.
If you discover a potential security issue, please contact us promptly at alex@withconviction.ai.
12. International Users
The Service is operated in the United States and is intended for users in the United States. If you access the Service from outside the United States, you understand that your personal information will be transferred to, processed, and stored in the United States, where data-protection laws may differ from those in your country.
13. Children's Privacy
The Service is intended for business users and is not directed to children under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us at alex@withconviction.ai and we will delete it.
14. Third-Party Links and Services
The Service may contain links to or integrations with third-party websites, services, or content. We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies.
15. Publicly Visible Content
Certain parts of the Service may be publicly available, including marketing hub pages, release pages, and related SEO content that we publish on the Marketing Site. This content is intended to be public and may be indexed by search engines. Do not place confidential information in fields you intend to be public.
16. Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date above reflects the most recent revision. If we make material changes, we will provide notice (for example, by email to Customer administrators or by an in-product notification) before the changes take effect.
17. Contact Us
If you have questions or requests regarding this Policy, contact us at:
Conviction AI LLC8401 Mayland Dr, Ste A
Richmond, Henrico County, VA 23294
United States
alex@withconviction.ai