Privacy Policy
Privacy Policy
Last updated: Oct 2025
1. Introduction
Narwin (“we,” “our,” or “us”) provides AI-powered tools to assist organizations with RFP, grant writing, and workplace content search. We are committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your information. This Privacy Policy outlines our practices in relation to data collection, processing, and user rights.
By using Narwin, you agree to the terms of this Privacy Policy.
2. Data We Collect
We collect data to provide and improve our services. This includes:
-
Authentication Data:
When you sign in via email or Google, we use Firebase Authentication to securely manage user accounts. This includes basic identifiers like your name, email, and UID.
-
User-Connected Sources:
Data you explicitly authorize us to access, including:
-
Google Drive: Files and documents you select.
-
Slack: Channel messages and metadata from workspaces where Narwin is added.
-
Notion: Page content and workspace structure.
-
Uploaded Files: PDFs, Word, Excel, Markdown, and other documents manually provided.
-
-
Metadata & Logs:
We collect logs and analytics data to monitor usage patterns and performance for service improvement and troubleshooting.
3. Purpose of Data Usage
Your data is used exclusively to:
-
Provide RFP and grant generation capabilities.
-
Deliver content search and document automation.
-
Power AI responses using OpenAI GPT-4.1 (via LangChain) and Perplexity Sonar Pro.
-
Parse files using LLamaParse.
-
Store structured data such as RFP responses in Supabase.
-
Index and retrieve documents using our internal vector database.
We do not sell, rent, or share your personal content with any third parties. Data may be used in aggregate and anonymized formats to improve our services.
4. Data Sharing and Subprocessors
We rely on the following subprocessors to provide our services:
-
Firebase (Google LLC) — Authentication and user account storage.
-
Supabase — RFP and grant project database.
-
Weaviate — Secure vector database for contextual document indexing.
-
OpenAI — AI responses via GPT-4.1, using LangChain.
-
Perplexity AI — External knowledge retrieval (Sonar Pro).
-
LlamaParse — File parsing and document structuring.
Each subprocessor is under a contractual obligation to maintain confidentiality and security of your data, aligned with global data protection standards.
5. Data Retention and Deletion
-
Uploaded data and connected-source data are retained for active use only.
-
If you deactivate your account, we will delete all user-associated data (including from Google Drive, Slack, Notion, and uploads) within 7 calendar days, unless legally obligated to retain it longer.
-
You may request early deletion at any time.
6. Slack Permissions and Data Access
Important Notice:
Narwin does not inherit Slack’s internal channel-level permissions. Once added to a Slack workspace or channel:
-
All accessible channel content is indexed.
-
All authorized users within Narwin may access that content.
Recommendation: Do not add Narwin to channels containing sensitive, regulated, or internal HR/financial content.
7. Security Measures
We employ industry-leading security practices, including:
-
Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
-
Access Controls: Role-based and workspace-scoped access restrictions.
-
Audit Logs: Detailed event logs maintained to monitor access and system use.
-
Environment Isolation: Multi-tenant architecture ensures workspace data is logically isolated.
8. Your Rights
You have the right to:
-
Access – Know what personal data we hold about you.
-
Correction – Request correction of inaccurate or incomplete data.
-
Deletion – Request deletion of your data before the automatic 7-day retention period.
-
Restriction – Limit or object to certain data uses where legally permitted.
To exercise your rights, contact us at fred[at]narwin.ai.
9. Children’s Privacy
Narwin is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we learn we have collected such data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through email or in-app notification. Continued use of the platform after updates constitutes your agreement to the revised terms.
11. Enterprise Customers – Contact Us
If you have questions or concerns about this Privacy Policy or your data or would like to obtain a security whitepaper, please contact:
Narwin, Inc.
Email: fred[at]narwin.ai
410 West Georgia Street, 5th Floor, Vancouver, BC Canada, V6B 1Z3