NOAH

Privacy Policy

Last updated: 2026-07-08

1. Who we are

NOAH is a cloud business management system (contacts, deals, tasks and communication). This policy explains what we collect, why, and how we protect it — in accordance with the Israeli Protection of Privacy Law, 1981.

2. What we collect

Account data: name, email and a hashed password (or your Google identity if you sign in with Google).

Your business data: contacts, companies, deals, tasks, activities and messages you enter. This data belongs to you — we process it solely to provide the service.

Usage data: audit logs, AI feature usage metrics, and technical data such as IP address and browser user-agent — collected for security on sensitive operations, and to measure ad-campaign effectiveness when a trial account is created (see section 4).

Cookies: essential cookies only — session management and theme preference. No advertising cookies; the ad-conversion measurement described in section 4 happens entirely server-side, with no cookie placed in your browser.

3. AI processing

AI features (the CHIEF agent, deal scoring, email drafting) use Anthropic's Claude. When you use an AI feature, the data relevant to your request is sent for processing and is not used to train models. Actions the agent proposes require your explicit confirmation.

For organizations that have enabled CHIEF's WhatsApp reply-drafts module (an optional feature, off by default) — when a customer of that organization sends a WhatsApp message, the message content is likewise sent to Anthropic to prepare a suggested reply draft for the organization's team member; this applies even when the sender has never used NOAH themselves and has never seen this policy. Here too, the draft is only a suggestion, and is sent to the customer only after a person approves it.

4. Sub-processors

We rely on established infrastructure providers: Supabase (database), Vercel (application hosting), Anthropic (AI processing), Resend (transactional email), Google (sign-in and Gmail sync — only with your authorization), Meta / Facebook (ad-campaign conversion measurement when a trial account is created — we send a one-way hash of your email address, name, and user id, plus your IP address and browser user-agent in plaintext, to match the signup to the ad campaign that led to it; no client-side cookies are used), and Sentry (error monitoring; session replays are masked). All are bound by data processing agreements.

5. Security

Each organization's data is isolated at the query level; every operation is validated against your permissions. Traffic is encrypted (TLS), sensitive tokens are encrypted at rest (AES-256-GCM), and a full audit log covers sensitive operations. Two-factor authentication is available and can be enforced org-wide.

6. Your rights

Export: the organization owner can export all organization data at any time (Settings → Privacy).

Deletion: you can permanently erase all organization data. Deleted data cannot be recovered. Note: data already sent to an external sub-processor before your deletion request (for example, for ad-conversion measurement as described in section 4) cannot be retroactively recalled or "unsent" from that sub-processor — our deletion applies to the data held in our own systems.

Access and correction: account details can be updated in profile settings.

7. Retention

Account and business data are kept while the account is active. If a trial ends without upgrading, your data is kept waiting for you. Account deletion permanently removes the data.

8. Contact

For privacy questions, reach us via the in-app contact form or on the home page.