Skip to main content
Back to Home

Privacy Policy

Version 1.2.1 · Effective 21 July 2026

1. Who is responsible for your data?

Usable Sp/f, Vestara Bryggja 15, 100 Tórshavn, Faroe Islands, is the data controller for account, billing, website, security, and support data processed through www.usable.dev and the Usable Service. Where an organisation using Usable determines why and how personal data in its workspace is processed, that organisation is normally the controller and Usable acts as its processor under the organisation’s instructions and applicable data-processing terms.

Privacy contact: privacy@usable.dev. Customer service: +298 556 600.

2. Data we collect

  • Account and contact data: name, email address, authentication identifiers, organisation, role, and preferences.
  • Workspace content: memory fragments, files, prompts, search queries, comments, metadata, access settings, and version history submitted by users.
  • AI-derived data: embeddings, similarity metadata, generated relationships, and requested AI outputs created from workspace content.
  • Billing data: plan, billing contact, payment status, invoices, transaction references, and limited payment-method information supplied by our payment provider. We do not store full card numbers.
  • Technical and usage data: IP address, device and browser information, timestamps, pages and features used, API activity, diagnostics, security logs, and usage quantities.
  • Integration data: information you authorise Usable to access from services and AI providers connected by you or a workspace administrator.
  • Communications: support requests, feedback, and other messages you send us.

3. Why we process data

  • Contract: provide accounts, workspaces, search, AI features, billing, support, and requested integrations.
  • Legitimate interests: secure, monitor, troubleshoot, and improve the Service; prevent abuse; and understand product use, balanced against your rights and reasonable expectations.
  • Legal obligations: process payments, keep financial records, respond to lawful requests, and meet accounting, tax, and regulatory duties.
  • Consent or another permitted basis: send optional marketing or activate optional technology where consent is required. You may withdraw consent or unsubscribe at any time.

4. AI processing

Customer Content may be transformed into embeddings or sent to the AI provider selected by Usable or configured by a workspace administrator to perform requested features. AI output is fully automated and is not subject to routine human review by Usable. It can be incomplete or inaccurate and must be reviewed by the user before it is relied on. We do not use AI output to make legal or similarly significant decisions about individuals, and we do not use Customer Content to train general-purpose models for other customers or third parties.

The AI features use data that a customer creates or uploads, data already available in the customer’s workspace, public sources deliberately supplied or selected by the user, and private or licensed sources made available through integrations authorised by the customer. Usable does not scrape public websites or use unauthorised collection of data for these features. An organisation may configure additional providers or bring its own credentials; its administrators are responsible for those choices and required notices.

5. Service providers and disclosures

We use service providers under contract for infrastructure and hosting, authentication, email delivery, event processing, monitoring, customer support, analytics, AI processing, and payment processing. Current examples include Keycloak for identity and authentication, Stripe for card payments and subscription billing, SendGrid and Amazon SES for service email, and Flowcore for event and pathway processing.

System-managed AI processing may use Microsoft Azure OpenAI, OpenRouter, Cerebras, or AWS Bedrock, depending on the feature and workspace configuration. Pro and Enterprise customers may instead connect supported providers with their own credentials, including OpenAI, Anthropic, and Google Gemini. Provider availability, model availability, context limits, rate limits, acceptable-use rules, and geographic processing options may vary. We require users to comply with the Service rules and any applicable provider restrictions.

Our current card-payment provider is Stripe; the active checkout identifies the payment provider and accepted payment methods before payment. Providers receive only the data reasonably needed to perform their services. A customer’s own integrations may send data to additional providers selected by that customer.

We may also disclose data where required by law, to protect rights and security, in connection with a corporate transaction, or when you instruct or consent to the disclosure. We do not sell customer workspace content.

6. Website analytics and marketing technology

Usable Web Analytics processes page URL, referrer, timestamp, and limited device or network data to produce aggregate website statistics without analytics cookies or browser local storage. We rely on our legitimate interest in understanding and improving the public site, subject to applicable law. The site stores language and theme preferences locally on your device. Essential authentication, security, session, and terms-acceptance cookies are used when you sign in.

7. International transfers

Data may be processed outside the Faroe Islands or EEA when a service provider or customer integration operates there. Where required, we use recognised safeguards such as adequacy decisions or standard contractual clauses and assess supplementary security measures.

8. Retention

  • Account and workspace data: while the account or workspace is active, followed by a limited backup and deletion period unless export, legal hold, or a separate agreement applies.
  • Security and diagnostic logs: only as long as reasonably needed for security, troubleshooting, and abuse prevention.
  • Billing and transaction records: for the period required by accounting, tax, payment-dispute, and anti-fraud obligations.
  • Support communications: while needed to resolve the request and document the outcome.

We delete or anonymise personal data when it is no longer needed, subject to backups and legal retention duties.

9. Security

We use organisational and technical measures designed to protect data, including access controls, encryption in transit, logging, backups, and restricted operational access. No online system can be guaranteed completely secure. Please report suspected security issues to privacy@usable.dev.

10. Your rights

Depending on applicable law and our role, you may request access, correction, deletion, restriction, objection, and portability, and withdraw consent where consent is the basis without affecting earlier lawful processing. You may also object to direct marketing at any time. If your data belongs to an organisation’s workspace, contact that organisation first because it normally controls the data; we assist it as processor where required.

Send requests to privacy@usable.dev. We may need to verify your identity. You may also complain to the Faroese Data Protection Authority, Datueftirlitið.

11. Children

The Service is not directed to children under 16. If you believe a child has supplied personal data without appropriate authorisation, contact us so we can investigate and delete it where required.

12. Automated decision-making

Usable does not use personal data to make solely automated decisions that produce legal or similarly significant effects about you. AI-generated suggestions and search results are advisory.

13. Changes to this policy

We may update this policy when our Service, providers, or legal obligations change. We will publish the updated policy with a new date and provide additional notice of material changes where appropriate.

14. Contact

Usable Sp/f
Vestara Bryggja 15
100 Tórshavn
Faroe Islands
Email: privacy@usable.dev
Customer service: +298 556 600