Privacy policy
Last updated 6 October 2026
Who we are
RegAffairs AI is a regulatory-research product operated at regaffairsai.com. This page describes how we handle personal data when you use the site, create an account, or email us. It is not legal advice.
What we collect
When you ask a question, we process the question text and the technical data needed to return an answer (IP address, user agent, timestamps).
If you create an account, we also store the email and identifiers supplied by the sign-in provider, your plan, and the conversations you keep.
If you use a partner's referral code or link, we also process your name, the referral and the subscription, upgrade or cancellation associated with it.
If you email hello@regaffairsai.com, we keep the correspondence long enough to answer it.
What we do not do
We do not use your questions, documents or uploads to train models. They stay yours.
We do not sell personal data. We do not run a marketing-pixel garden on this site.
Partner referrals
If you subscribe, upgrade or cancel using a partner's referral code or link, we email that partner your name and the subscription event to make the referral and revenue share transparent and allow reconciliation. We do not include your email address or other customer details. Partners are contractually required to use this information only for referral transparency and reconciliation, not to target you or market to you.
Our lawful basis is legitimate interests: our and our partners' interests in transparently administering referrals and reconciling revenue shares. You can object to this processing by emailing hello@regaffairsai.com. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need the data for legal claims.
Analytics
We use PostHog, hosted in the EU, as our product analytics processor. It receives the pages you visit, your clicks (including the text of what you click), heatmaps of where you click, move and scroll, session replays (recordings of how you use a page, including what it shows, such as your questions and their answers; text you type into a field is masked), product events such as sign-ups, sign-ins, questions asked (a question's length and which number question it is for your account), answers finished and upgrades, errors and page speed, and, when analytics may identify you and you are signed in, your user id from Clerk, our sign-in provider (not your email).
For each answer our server sends PostHog the model, timing, token counts, estimated cost, the conversation id, quick or deep mode, whether it came from cache, and whether it failed, with the error status. It never sends the question or answer text. This is sent for every answer, including in the EU, the EEA, the UK and Switzerland before you accept or after you decline; then it is anonymous, with the conversation id but without your user id, and sets nothing on your device.
In the EU, the EEA, the UK and Switzerland, this starts only after you accept; until then, or if you decline, PostHog only counts the pages you view and those product events, without analytics cookies or storage on your device, without your user id, and with no clicks, heatmaps or session replays. Elsewhere it is on by default, and analytics may identify you. You can change your choice at any time with the Cookie settings link in the footer of our website pages.
AI assistant connections
If you connect RegAffairs AI to an AI assistant (for example Claude or ChatGPT), we receive what the assistant sends to our tools: the tool inputs (such as a substance name, CAS number or the question text), the identifier of your RegAffairs AI account from the sign-in, and the name and version the assistant reports for itself. We also log the time, the tool used and how long it took.
We do not receive the rest of your chat with the assistant, only what it sends to RegAffairs AI tools.
Research questions asked through an assistant are kept in your RegAffairs AI history like questions asked on the site, and are kept and deleted on the same terms. We do not use them, or any tool input, to train models.
The assistant provider's own privacy policy covers what happens on their side, including your chat and anything our tools return to it.
Where data lives
Data is processed and stored in the EU by default. Regional options can be discussed for enterprise accounts.
How long we keep it
Conversation history stays until you delete it or close the account. Server logs are kept only as long as they are useful for security and debugging, then dropped.
We keep personal data used for partner referrals only as long as needed to reconcile revenue shares and resolve related disputes, or as required by law.
Your requests
You can delete conversations from the product. For account deletion, access, or a copy of your data, email hello@regaffairsai.com. We honour removal requests promptly.
Cookies
The Cookie Policy covers the cookies we use: session and sign-in cookies to run the product, and the PostHog analytics cookie described above. We do not use them to follow you around the web.
Changes
If this policy changes in a way that affects how we handle your data, we will update this page and the date below.