Performance Intelligence

Privacy Policy

Last updated: August 16, 2026

Who we are

Performance Intelligence is a performance management platform that companies use to run evaluations, collect feedback, and manage their organization. This policy explains what data we collect, why, and the choices you have. When your employer uses Performance Intelligence, your employer decides what performance data is collected inside their workspace and who in the company can see it. Performance Intelligenceprocesses that data on their behalf.

Data we collect

Account data. Your name, email address, and a securely hashed password. You may optionally add a phone number and profile details.

Sign-in with Google or Microsoft.If you use single sign-on, we store your email, your first and last name if the provider sent them, and the provider's permanent account identifier so we can recognize you next time. That is all. We never receive your Google or Microsoft password, we do not store provider tokens, and we get no access to your Google or Microsoft account beyond that sign-in profile.

Billing data.Paid plans are billed through Stripe. Your card number and billing address go to Stripe directly and never touch our servers; we store no card details. What we do store: your company's plan, subscription status, billed seat count, and invoice records (amounts, dates, and links to the Stripe-hosted invoice). To set up billing we share your company's name and the owner's email address with Stripe.

Workspace data. The content your company creates in Performance Intelligence: departments, positions, evaluations and their answers, scores, feedback notes, and suggestions. Your company controls this data.

AI assistant questions.The questions you type to the AI assistant are recorded so we can improve the assistant. The assistant's replies are not stored, and conversations disappear when you refresh the page. Questions are processed by Anthropic (our AI provider) to generate the answer. See our AI Disclosure for full details on how the assistant works.

Usage and diagnostics. AI token usage for metering, and error reports (via Sentry) that deliberately exclude request contents.

Cookies

Performance Intelligence uses essential cookies only. One is a session refresh token that keeps you signed in securely; it is httpOnly (not readable by scripts), scoped to authentication endpoints, and expires automatically. If you sign in with Google or Microsoft, a second short-lived cookie protects that sign-in handshake; it lasts at most ten minutes and is cleared when sign-in completes. We use no advertising or cross-site tracking cookies. Your theme preference is stored locally in your browser and never sent to us.

Service providers

We rely on a small set of infrastructure providers to run Performance Intelligence: Railway (application hosting and database), Anthropic (AI assistant processing), Stripe (payment processing for paid plans; card details go to Stripe directly and never to us), Resend (transactional email such as invitations, password resets, and billing notices), and Sentry (error monitoring, with request bodies stripped). Each receives only the data needed to perform its function.

Security

Passwords are hashed with bcrypt and never stored in plain text. If you sign in with Google or Microsoft, your password stays with that provider and Performance Intelligencenever sees it. Traffic is encrypted in transit (TLS). Sign-in sessions use short-lived access tokens with rotating refresh tokens, and changing or resetting your password signs out all other devices. Access to workspace data is enforced by a per-company permission system, including for the AI assistant, which can only read what you yourself are permitted to see.

Retention

Account and workspace data is retained while the account or workspace is active. Logged AI questions are retained to improve the product and are erased when you delete your account. Invoice records are kept after a workspace closes, for accounting. You can delete your account yourself at any time (see below).

Your rights

You can access and correct your profile data directly in the app, and exercise your data rights yourself under Profile → Your Data: download a copy of all personal data we store about you (JSON export), or permanently delete your account. Deletion erases your profile, login, notifications, and AI assistant history immediately; evaluations and feedback that form part of a company's appraisal records are retained by that company in anonymized form ("Deleted User"). If you are the only owner of a company, transfer ownership or delete the company first.

Performance data inside a company workspace is controlled by that company; direct requests about it to your employer, and we will support them. You can also contact us with any privacy request and we will respond within 30 days.

Contact

Privacy questions and requests: [email protected]

Changes

If this policy changes materially, we will update the date at the top and, for significant changes, notify account holders by email or in the app.