Privacy Policy
Last updated: September 10, 2026
BearingCore (“BearingCore,” “we,” “us”) provides CRM and AI software for industrial sales teams. This policy explains what information we collect through bearingcore.io and the BearingCore application, how we use it, and the choices you have.
1. Information we collect
Information you give us. When you create an account, request a demo, or contact sales, we collect the details you submit — typically your name, work email address, company, and anything you include in a message.
Account and sign-in information. Accounts are managed with Amazon Cognito. If you sign in with Google, we receive your name, email address, and profile picture from Google in order to create and match your account. We never receive your Google password.
Customer content. When your organization uses BearingCore, we store the business records you enter or import — leads and contacts, companies and facilities, equipment records, opportunities, site visits and visit notes, proposals, engineering reports, and utility incentive program data. This content belongs to your organization. We process it to provide the Service and do not sell it or use it to train third-party models.
Billing information. Payments are processed by Stripe. We do not store card numbers. We receive limited billing details from Stripe such as subscription status, the purchasing email, and the last four digits of the card.
Information collected automatically. We record log data such as IP address, browser and device type, pages viewed, and timestamps, along with security and audit events like sign-ins and record changes.
2. How we use information
- To provide, operate, secure, and improve the Service.
- To authenticate users and enforce organization permissions.
- To generate the documents and analyses you ask the AI modules to produce.
- To process subscriptions, purchases, and invoices.
- To respond to sales enquiries and support requests.
- To monitor usage, cost, and reliability, and to detect and prevent abuse.
- To meet legal obligations and enforce our terms.
3. AI features and how your data is handled
Paid modules — including the Proposal Builder, Engineering Reports, and Utility Incentive Programs — use a third-party large language model provided by Anthropic. When you run one of these features, the relevant record content is sent to Anthropic’s API to generate the requested output and returned to your organization.
Your content is not used to train Anthropic’s models. We record per-module usage and token counts for cost and reliability monitoring; those records are operational metrics, not copies of your content.
4. Cookies and analytics
The application uses essential cookies and browser storage for authentication and session management.
On our public marketing pages only, we use Google Analytics 4 to understand which pages are useful. This sets analytics cookies and processes a truncated IP address and a randomly generated identifier. Analytics are not loaded inside the signed-in application, so your CRM activity is not tracked by Google. You can block cookies in your browser or use Google’s opt-out add-on.
Also on our public marketing pages only, we use Apollo.io’s website visitor tracking. It matches a visitor’s IP address and network information against Apollo’s business database to identify the organization a visit likely came from, which pages that organization viewed, and when. It does not identify individual people, and it is not loaded inside the signed-in application. We use this to understand which utilities and contractors are interested in BearingCore and to prioritize our own outreach.
5. How information is shared
We do not sell personal information. We share it only in these situations:
- Service providers. Amazon Web Services (hosting, database, file storage, and transactional email) in the United States; Stripe (payments); Anthropic (AI features); Google (marketing-page analytics and optional sign-in); Apollo.io (marketing-page organization-level visitor identification).
- Legal and safety. Where required by law, or to protect our rights, our users, or the security of the Service.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.
6. Business communications and opt-out
We may contact business contacts by email about BearingCore, including outreach to professional addresses where permitted by applicable law. Every marketing email includes an unsubscribe link, and you can opt out at any time by using it or by emailing us. Opting out of marketing does not stop essential service messages about your account.
7. Data storage, security, and retention
Data is stored on Amazon Web Services in the United States, using a PostgreSQL database encrypted at rest, encrypted object storage for files, and AWS Secrets Manager for credentials. All traffic is served over HTTPS/TLS, and access is scoped to your organization.
We retain customer content while your organization’s account is active, and afterwards only as needed to meet legal obligations, resolve disputes, or keep billing records. On request we will delete an account’s personal data within 30 days, subject to those exceptions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your choices and rights
You can ask us to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing. Depending on where you live, you may have specific rights under laws such as the GDPR or the CCPA/CPRA, including the right not to receive discriminatory treatment for exercising them. We do not sell or share personal information for cross-context behavioural advertising.
If you use BearingCore through your employer’s account, that organization controls its data. We will refer requests about that content to them and support them in responding.
To make a request, email contact@bearingcore.io. We may need to verify your identity first.
9. International users
BearingCore is operated from the United States and our infrastructure is located there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
10. Children
BearingCore is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
We may update this policy as the product changes. We will revise the date above and, for material changes, provide additional notice.
12. Contact us
Questions about this policy or how we handle information can be sent to contact@bearingcore.io.