Privacy
Last updated 4 September 2026
NORUM holds formulas and specifications. The personal data in it is a small number of fields about the people who sign in. This page says exactly what those are, who else sees them, and what we do not do.
The short version
- · We do not sell or share your personal information.
- · There is no advertising network and no cross-site tracking.
- · We do not use your data to train a model.
- · One workspace cannot read another. The database enforces that, not a query.
- · You can ask for a copy of your data, or for its deletion.
1. What we collect
About people: a name, an email address, the workspaces somebody belongs to and their role in each, and whether they have set up a second factor. If somebody uploads a profile photograph, that too.
About the company: what you enter — legal name, addresses, registrations, facilities, partners and contacts. Some of those contacts are people, and this page covers them as well.
About what happens: an audit record of who changed what and when. That one exists because a regulated record has to be attributable, and it cannot be switched off.
What we do not collect: card numbers, which go to the payment processor and never reach us; and any advertising or cross-site identifier, because there is no advertising network in the product.
2. Why we have it
To run the service you are paying for: to sign you in, to show your colleagues who did what, to send the few messages NORUM sends, to take payment, and to keep the audit trail a regulated record needs.
Where the law calls for a basis, ours is the contract with your company, and our legitimate interest in keeping the service secure and accountable.
3. What we send you
Almost nothing. An invitation, a receipt for a payment, a warning that a payment failed, and a message when something you recorded is about to expire. There is no newsletter and no marketing sequence.
4. Who else processes it
These companies process data on our behalf, under contract, for the purpose named and nothing else.
| Company | What it does | What it receives |
|---|---|---|
| Supabase | Database, sign-in and file storage | Everything in your workspace |
| Vercel | Runs the application | Requests in transit, and server logs |
| Stripe | Takes payment | Billing name, address, email and the card. We never see the card. |
| Resend | Sends the messages above | The address and the message |
| OpenAI | Reads documents you upload, drafts text | Only the content of a document you ask it to read |
All of them are in the United States, and your data is stored there. If we add one, this table changes before it does anything.
We do not send anything to an advertising network, an analytics company or a data broker, because we use none.
5. About the AI
When you ask NORUM to read a supplier document, its contents go to OpenAI to be read, and come back as fields you review before anything is saved. That is the only thing that leaves.
It is not used to train a model — ours or anybody else's — and one customer's data is never used to answer another's question.
6. Keeping workspaces apart
One workspace cannot read another. That is enforced by row-level security in PostgreSQL — by the database itself, on every query — rather than by a filter in application code that somebody could forget to write.
Documentation crosses between two companies only where somebody deliberately put it in a package and issued it, and it stops when they stop it.
7. How long we keep it
While your workspace is open, and for 30 days after it is closed, so an account closed by mistake can be brought back. After that it is deleted from the live database, and from backups as those age out — within 90 days.
We keep what the law makes us keep: invoices and payment records, for as long as tax rules require.
8. What you can ask for
A copy of the personal data we hold about you. A correction. Deletion. A restriction on what we do with it. And to object to a particular use.
Write to contact@norum.io and we will answer within 30 days. We will not charge you and we will not make it difficult.
Some of it you can do yourself: export your records, change your details, and remove a colleague's access, all from inside the product.
9. Children
NORUM is for companies. It is not for anybody under 16, and we do not knowingly collect anything about a child. If we learn we have, we delete it.
10. If something goes wrong
If personal data is exposed, we will tell the affected workspaces without undue delay and within 72 hours of establishing it, say what happened and what we are doing, and notify whoever the law requires. We would rather tell you early and imprecisely than late and neatly.
11. Changes
If we change something that matters — what we collect, who processes it, how long we keep it — we email the account address at least 30 days before, and the date at the top changes.
12. Reaching us
NORUM Data Systems, Springville, Utah, United States. contact@norum.io.
See also: Terms · Cookies · What NORUM will not claim