1. Overview
This Privacy Policy explains how Anager collects, uses, shares, stores, and protects personal data when you use our websites, mobile applications, enterprise workspaces, connected systems, AI co-workers, workflows, APIs, and related services.
Anager is operated from Delhi, India and is designed for Indian and global customers. We aim to follow privacy-by-design principles and comply with applicable privacy laws, including India's Digital Personal Data Protection Act, 2023, and where applicable global privacy frameworks such as GDPR, UK GDPR, CCPA/CPRA, and similar laws.
2. Our role for consumer and enterprise data
- For individual account, billing, security, website, product telemetry, and support data, Anager generally acts as an independent data controller.
- For enterprise Customer Content processed inside a workspace, Anager generally acts as a processor or service provider for the organization that controls that workspace.
- The workspace owner or administrator is responsible for determining what business data is connected to Anager, who may access it, and what notices or consents are required for users, employees, vendors, customers, and other data principals.
- A signed data processing agreement, enterprise order, or customer agreement may provide additional data protection terms.
3. Data we collect
- Account data: name, email, authentication provider, workspace membership, role, organization, profile image, and login details.
- Workspace data: prompts, messages, AI outputs, work cards, approvals, tasks, comments, workflows, agent configurations, business profiles, memory packs, documents, contracts, invoices, relationships, and related metadata.
- Connected system data: data you authorize Anager to access from email, calendar, Drive, CRM, finance, communications, document stores, internal tools, and other integrations.
- Device and usage data: browser, app version, device type, operating system, IP-derived region, diagnostics, logs, feature usage, latency, errors, and security telemetry.
- Billing and commercial data: plan, subscription, invoice, tax, payment status, address, GST or other tax identifiers, and transaction metadata. Payment processors may collect full payment method data directly.
- Support and feedback data: support messages, ratings, corrections, survey responses, product feedback, and security reports.
- Website and analytics data: privacy-safe analytics events, page routes, consent choices, referral data, and cookie or local storage preferences.
4. How we use data
- Provide, secure, maintain, and improve Anager.
- Authenticate users, manage accounts, support workspaces, and enforce permissions.
- Sync connected systems and build workspace intelligence, business profiles, agent knowledge packs, relationships, documents, contracts, invoices, and work context.
- Generate AI outputs, workflows, reports, dashboards, research, summaries, classifications, recommendations, and approval requests.
- Operate learning loops that improve workspace-specific workflows, memory, agent behavior, and successful patterns under workspace policy.
- Monitor service health, detect abuse, prevent fraud, investigate security incidents, debug failures, and enforce policies.
- Process billing, subscriptions, tax, notices, support, and customer communications.
- Comply with law, legal process, government requests, contractual obligations, audit requirements, and dispute resolution.
5. AI providers, model routing, and training
Anager may route AI tasks to model providers such as OpenAI, Anthropic, Google/Gemini, and other providers, depending on workspace policy, task type, cost, reliability, quality, safety, and availability.
We do not sell Customer Content. For enterprise workspaces, Anager does not use Customer Content to train a general foundation model owned by Anager. Workspace-specific learning may improve that workspace's workflows, memory, agent knowledge packs, and operating behavior.
Where model providers process Customer Content, we use available commercial/API controls and contractual or technical settings intended to prevent provider training on business content, subject to the terms and capabilities of each provider.
6. Legal basis and consent
Depending on your location and the context, we process personal data on one or more lawful bases: contract performance, consent, legitimate interests, compliance with legal obligations, protection from fraud or abuse, vital interests where applicable, and instructions from an enterprise customer acting as controller.
Where consent is required, you may withdraw consent through product settings, workspace controls, browser settings, mobile OS settings, or by contacting us. Withdrawal may limit some features.
7. How we share data
- With workspace owners, administrators, members, assignees, approvers, and authorized collaborators according to workspace permissions.
- With vendors and subprocessors who provide hosting, databases, authentication, storage, analytics, payments, communications, support, monitoring, AI models, security, and infrastructure.
- With connected systems and third-party services when you authorize Anager to read from or write to those services.
- With app stores, payment processors, tax systems, or banks where needed for billing and subscription administration.
- With professional advisers, auditors, insurers, legal counsel, regulators, courts, law enforcement, or government authorities when required or reasonably necessary.
- In connection with a merger, financing, acquisition, restructuring, sale of assets, or business transition, subject to appropriate confidentiality and legal safeguards.
- With your direction, consent, or as otherwise described at the time of sharing.
8. Enterprise admin visibility
If you use Anager through an organization workspace, your organization may be able to access, export, monitor, delete, retain, or restrict workspace data, connected system data, AI outputs, work cards, approvals, audit logs, user activity, and account information according to its policies and your role.
Your organization is responsible for telling you how it monitors and controls its workspace and connected systems.
9. Security safeguards
- We use technical, organizational, and operational controls designed to protect data, including access controls, authentication, encryption in transit, role-based permissions, audit logs, monitoring, backup practices, and least-privilege operating practices.
- No online service is completely secure. You are responsible for strong credentials, device security, workspace permissions, integration scopes, and prompt reporting of suspected compromise.
- Security reports may be sent to hello@anager.ai with enough detail for investigation.
10. Cookies, local storage, and analytics
Anager uses essential cookies and local storage for login, security, workspace routing, preferences, and product operation.
For Google Analytics and similar measurement, Anager uses consent gating where implemented. We do not intentionally send prompts, emails, document titles, company names, person names, workspace content, or raw Customer Content to analytics tools.
You can control cookies and analytics through browser settings, product consent controls, or device settings. Disabling some storage may affect product functionality.
11. Retention and deletion
We retain data for as long as needed to provide the services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, support backups, maintain audit trails, and follow enterprise retention settings.
Enterprise customers may configure retention, deletion, export, and legal hold policies where supported. Deletion from active systems may not immediately remove data from backups, logs, legal archives, or records we must retain.
12. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for personal data. You may also have rights to complain to a data protection authority.
For enterprise workspace data, we may direct your request to the organization that controls the workspace or process the request according to that organization's instructions.
- India: Data principals may request access, correction, completion, updating, deletion, grievance redressal, and withdrawal of consent where applicable under the DPDP Act.
- EEA/UK: You may have GDPR rights including access, rectification, erasure, portability, restriction, objection, and complaint rights.
- California and similar US states: You may have rights to know, access, delete, correct, opt out of sale or sharing, limit sensitive personal information, and non-discrimination. Anager does not sell personal information.
- To exercise rights, contact hello@anager.ai. We may need to verify your identity and workspace authority before acting.
13. International transfers
Anager may process and store data in India and other countries where we, our infrastructure providers, subprocessors, model providers, or support teams operate. These countries may have different privacy laws than your location.
Where required, we use contractual, technical, organizational, and transfer safeguards designed to protect personal data during international processing.
14. Children's privacy
Anager is not intended for children. You must be at least 18 years old, or the age required in your location to use the services. We do not knowingly collect personal data from children for direct consumer use.
15. Changes to this Policy
We may update this Privacy Policy to reflect product, legal, operational, security, or data processing changes. If changes materially affect privacy rights, we will provide notice through the website, product, email, or other reasonable means.
16. Contact and grievance redressal
For privacy requests, data protection questions, grievance redressal, or security concerns, contact hello@anager.ai. Anager operates from Delhi, India. If you are an enterprise user, you may also contact your workspace administrator because your organization may control the relevant workspace data.