Privacy Policy
Effective date: 2026-09-27
This policy describes what Sourgent (the “Service”) collects, why, and how it is protected. Sourgent is a B2B sourcing and negotiation tool: it helps a buyer draft purchase requirements, find and evaluate suppliers, and negotiate and track quotes, using your own connected email and messaging accounts and, optionally, AI providers to help draft and analyse content.
Data we collect
- Account data: your email address and authentication credentials (managed by our authentication provider), display name, and preferred language.
- Workspace data: the workspace(s) you belong to and your role in each.
- Sourcing data you provide: purchase requirements, product specifications, your maximum/target price (kept confidential — see below), and the supplier shortlist for each project, including business contact details (company name, country, website, published email or phone) that you add or that the Service finds through supplier search.
- Communications: the content of email and WhatsApp messages exchanged with suppliers through the Service, kept as your negotiation history and audit trail.
- Files you upload: quotes, specifications, or other documents attached to a project.
- Operational data: a log of actions taken in your workspace (audit trail), delivery status of background jobs, and AI/search usage counts (token and call counts only — never the content of a prompt or a model’s response is stored in usage records).
- WhatsApp owner verification: if you verify your own WhatsApp number to approve requests by reply, we store that number once confirmed via a one-time code; the code itself is never stored in plain text.
Your confidential price is never exposed
Any maximum or target price you set is stored in a separate, access-restricted record. It is never included in messages sent to suppliers, never sent to an AI provider, never written to logs or the audit trail, and is only ever readable by workspace roles with explicit permission to view it.
Gmail / Google data use
If you connect Gmail, the Service requests only two permissions: read your mail (gmail.readonly) to detect supplier replies relevant to your sourcing projects, and send mail (gmail.send) to deliver messages you have approved. It does not request permission to delete mail, change mailbox settings, or otherwise manage your account. Your Google refresh token is encrypted at rest and used only server-side to call the Gmail API on your behalf.
WhatsApp / Meta data use
If your workspace connects a WhatsApp Business number, the Service uses Meta’s WhatsApp Cloud API to send you notifications about your sourcing projects and to let a verified workspace owner approve or reject a pending request by replying on WhatsApp. Every inbound message from Meta is cryptographically signature-verified before it is processed. WhatsApp access tokens are encrypted at rest.
AI and search providers
The Service uses a large-language-model provider (Anthropic Claude and/or OpenAI, depending on configuration) to help draft purchase briefs, evaluate supplier quotes, and draft outbound messages for your approval, and may use a web search provider (Brave Search and/or OpenAI’s web search) to find public business information about potential suppliers. Your confidential price is never included in any request to these providers, and content received from a supplier is treated as untrusted input, never as an instruction.
Storage and security
Data is stored in a PostgreSQL database with row-level security, so that only members of your own workspace can access your workspace’s data. Integration credentials (such as Gmail and WhatsApp tokens) are encrypted with envelope encryption; one-time verification codes are stored only as a cryptographic hash, never in plain text. Uploaded files are stored privately and are validated before being made available for download.
Retention and deletion
Your workspace’s audit trail — the record of actions taken in it — is append-only and immutable by design, including after a workspace is removed; this is a deliberate integrity control so that a record of what happened can never be silently altered or lost, and it cannot be deleted on request. Other workspace data (projects, supplier lists, messages, files) can be deleted on request, subject to that same audit-trail retention.
Your rights
You may request a copy of, correction to, or deletion of your personal account data by contacting us at the address below. We will respond as required by applicable data protection law, subject to the retention limitation described above.
Third parties we use
- Our database, authentication, and file storage provider
- Google (Gmail API), if you connect a mailbox
- Meta (WhatsApp Cloud API), if you connect a WhatsApp Business number
- Anthropic and/or OpenAI, for AI-assisted drafting and analysis
- Brave Search and/or OpenAI, for supplier discovery, if enabled
Each third party receives only the data necessary to provide the specific feature you use.
Contact
For privacy questions or requests, contact brahimcontact64@gmail.com.