Privacy Policy

Effective: April 1, 2026

Binaurals, Inc. ("Binaurals," "Company," "we," "us," or "our") is an AI-powered negotiation technology company. We develop proprietary Negotiation Intelligence that operates on top of third-party large language model providers to deliver AI-assisted negotiation guidance through a conversational chat interface.

This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use our website, AI Negotiation Chat, and other products and services where Binaurals acts as a data controller (collectively, the "Services").

This Privacy Policy also describes your privacy rights. More information about your rights, and how to exercise them, is set out in the sections below.

For the purposes of the EU General Data Protection Regulation ("GDPR"), the Company is the Data Controller. For the purposes of the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Company is the Business.

1. Collection of Personal Data

We collect the following categories of personal data:

Personal Data You Provide to Us Directly

Identity and Contact Data. We collect your work email address when you sign up. We also derive a company domain from your email for account organization. Personal email domains (such as Gmail, Yahoo, Outlook, iCloud, and similar consumer providers) are not permitted. We do not collect your name, phone number, or home address at signup.

Payment Information. Billing name and address are collected by our third-party payment processor during checkout and are not stored in our systems. We receive only an opaque customer reference from our payment processor to manage your subscription.

Inputs and Outputs (Conversation Data). You interact with our AI Negotiation Chat by providing prompts, questions, documents, and other content in a variety of formats ("Inputs"). Our Services generate responses based on your Inputs ("Outputs"). Inputs and Outputs are collectively referred to as "Materials." If you include personal data in your Inputs — such as names, contact information, deal terms, or other identifying information — we will collect that information, and it may appear in your Outputs.

Because our Services operate on top of third-party large language model providers, your Inputs are transmitted to and processed by third-party AI infrastructure providers in order to generate Outputs. We configure our integrations with these providers to align with our privacy and security standards, and we maintain contractual agreements governing their handling of your data. However, these providers' own privacy policies also apply to the processing of your Inputs by their systems.

Feedback. We appreciate feedback, including ideas and suggestions ("Feedback"). If you provide feedback through any channel we may offer or by contacting us directly, we may use that feedback to improve our Services and our proprietary Negotiation Intelligence.

Communication Information. If you communicate with us, including through email or support channels, we collect your contact information and the contents of any messages you send.

Personal Data We Collect Automatically

When you use our Services, we automatically receive certain technical data, including:

Device and Connection Information. Your device or browser automatically sends us information including your device type, operating system, browser type, mobile network, IP address (including approximate location derived from your IP address), time zone, and unique device identifiers.

Usage Information. We collect information about your use of the Services, such as dates and times of access, features used, pages viewed, conversation frequency and duration, links clicked, and other interaction data.

Log and Troubleshooting Information. We collect log files and error information when our Services encounter issues, including the time of error, feature being used, and the state of the application.

Cookies. We set two essential cookies required for the Services to function securely: an authentication token (httpOnly) and a CSRF protection token. We do not set analytics, marketing, or tracking cookies. See Section 11 for details.

Personal Data We Collect or Receive to Improve Our Negotiation Intelligence

We may use data from the following sources to train, improve, and develop our proprietary Negotiation Intelligence:

  • Inputs and Outputs from our Services, unless you request otherwise by emailing security@binaurals.ai
  • Feedback that users explicitly provide about our Services
  • Materials flagged for safety, security, or policy review
  • Publicly available information relevant to negotiation practices and strategies
  • Data from commercial agreements with third-party data providers
  • Data that we generate internally through research and development

Work Email Sign-Up Only

Binaurals Negotiate supports account creation exclusively via a one-time passcode sent to a work email address. We do not support social login through Google, Facebook, LinkedIn, or any other third-party social media service. Personal email domains (such as Gmail, Yahoo, Outlook, iCloud, and similar consumer providers) are not permitted.

2. How We Use Your Personal Data

We use your personal data for the following purposes:

To Provide and Maintain Our Services. To operate our AI Negotiation Chat and other Services, process your Inputs, generate Outputs, and facilitate your use of the platform.

To Improve Our Services and Negotiation Intelligence. To train, develop, and improve our proprietary Negotiation Intelligence and the overall quality of our Services, including through analysis of Materials. You may request that your Materials not be used for improving our Negotiation Intelligence by emailing security@binaurals.ai, and we will honor such requests within a reasonable timeframe. Even if you have opted out, we will use Materials for improvement when: (1) you provide Feedback to us regarding any Materials, or (2) your Materials are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance our safety efforts.

To Create and Administer Your Account. To manage your registration, authenticate your identity, and maintain your account.

To Facilitate Payments. To process subscription fees and other payments for our Services through our third-party payment processor.

To Communicate With You. To contact you by email or other electronic communication regarding updates, security notices, support, and informational communications related to the Services.

To Provide Marketing Communications. To provide you with news, special offers, and general information about other goods, services, and events that may interest you, unless you have opted not to receive such information. You may unsubscribe at any time.

To Prevent Fraud and Enforce Our Policies. To prevent and investigate fraud, abuse, and violations of our Acceptable Use Policy, to detect harmful or illegal activity, to protect our rights and the rights of others, and to enforce our Terms of Service.

To Comply With Legal Obligations. To comply with applicable laws, legal processes, and regulatory requirements.

For Safety and Security. To investigate and resolve security incidents, debug and repair errors, and protect the safety of our users and the public.

For Research and Analysis. To analyze usage trends, measure the effectiveness of our Services, and conduct research to improve our offerings.

For Business Transfers. To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, in which personal data held by us is among the assets transferred.

For De-identified and Aggregated Data. We may aggregate or de-identify personal data so that it no longer identifies you and use this information for the purposes described above, including to analyze how our Services are used, improve features, and conduct research. We will maintain de-identified information in de-identified form and not attempt to re-identify it, unless required by law.

3. How We Disclose Personal Data

We may disclose your personal data to the following categories of third parties:

Third-Party AI Infrastructure Providers. Your Inputs are transmitted to third-party large language model providers to generate Outputs. These providers process your data in accordance with our contractual agreements and their own privacy policies.

Service Providers and Business Partners. We may disclose personal data to service providers and business partners who assist us with website hosting, data processing, payment processing, analytics, customer support, marketing, and other business operations.

Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.

Business Transfers. If Binaurals is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.

Legal and Safety Purposes. We may disclose your personal data if required to do so by law or in response to valid requests by public authorities. We may also disclose personal data in good faith belief that such action is necessary to: comply with a legal obligation; protect and defend the rights or property of the Company; prevent or investigate possible wrongdoing in connection with the Services; protect the personal safety of users or the public; or protect against legal liability.

With Your Consent. We may disclose your personal data for any other purpose with your consent.

We do not sell your personal data to third parties.

4. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy.

Conversation Data (Materials). We retain conversation data for the life of your account. You may request deletion of individual conversations at any time by emailing security@binaurals.ai. Deleted conversations will be removed from your conversation history and permanently deleted from our back-end systems within 30 days of your request.

Account Data. We retain your account information for as long as your account is active. Upon account closure, your data will be deleted within a reasonable period, subject to our legal obligations.

Usage Data. Usage data is generally retained for a shorter period, except when used to strengthen security, improve functionality, or where we are legally obligated to retain it longer.

We may retain certain information when we have a legal obligation or lawful basis to do so, including for compliance, dispute resolution, and enforcement of our agreements.

5. Your Rights and Choices

Depending on where you live and the laws that apply, you may have certain rights regarding your personal data. We strive to honor these rights and comply with all applicable privacy laws.

Model Training Opt-Out. You may request that your Materials not be used for improving our proprietary Negotiation Intelligence by emailing security@binaurals.ai. We will honor such requests within a reasonable timeframe. Please note that opting out does not affect Materials already used in training that has been completed, but we will stop using your newly stored Materials in future training.

Conversation Deletion. You may request deletion of individual conversations at any time by emailing security@binaurals.ai. Deleted conversations will be removed from your conversation history and permanently deleted from our back-end systems within 30 days of your request.

Right to Know. The right to know what personal data we process about you, including the categories collected, the sources, the business purposes, and the categories of third parties to whom we disclose it.

Access and Data Portability. The right to request a copy of the personal data we hold about you. In certain cases, you may have the right to receive your data in a portable format.

Deletion. The right to request that we delete personal data collected from you, subject to certain exceptions.

Correction. The right to request that we correct inaccurate personal data. Please note that we cannot guarantee the factual accuracy of AI-generated Outputs. If Outputs contain inaccurate personal data relating to you, you can submit a correction request and we will make a reasonable effort to address it, but due to the technical complexity of AI models, it may not always be possible.

Objection. The right to object to processing of your personal data in certain circumstances, including for direct marketing purposes.

Restriction. The right to restrict our processing of your personal data in certain circumstances.

Withdrawal of Consent. Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before the withdrawal.

Non-Discrimination. You have the right not to be discriminated against for exercising your privacy rights.

To exercise your rights, you or an authorized agent may submit a request by emailing us at security@binaurals.ai. After we receive your request, we may verify your identity before processing it.

6. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data under the following legal bases:

Consent. You have given your consent for processing personal data for one or more specific purposes.

Performance of a Contract. Processing is necessary for the performance of our Terms of Service or any other agreement with you.

Legal Obligations. Processing is necessary for compliance with a legal obligation to which the Company is subject.

Legitimate Interests. Processing is necessary for the purposes of legitimate interests pursued by the Company, such as improving our Services, preventing fraud, and ensuring security, where those interests are not overridden by your rights and freedoms.

Vital Interests. Processing is necessary to protect your vital interests or those of another person.

You have the right to complain to a Data Protection Authority about our collection and use of your personal data. If you are in the EEA, please contact your local data protection authority.

7. Data Transfers

Your information, including personal data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located, including in the United States. Your data may also be processed by third-party AI infrastructure providers in their respective data processing locations.

Your consent to this Privacy Policy, followed by your submission of information, represents your agreement to these transfers.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. Where information is transferred outside the EEA or the UK, we ensure it benefits from an adequate level of data protection through appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission.

8. Security of Your Personal Data

The security of your personal data is important to us. We implement commercially reasonable technical, administrative, and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction.

However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. You should take special care in deciding what information you provide through the Services, particularly in the context of sensitive negotiation discussions.

9. Children's Privacy

Our Services are not directed at anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and you become aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from anyone under 18 without verification of parental consent, we take steps to remove that information from our systems.

10. CCPA/CPRA Privacy Notice (California Privacy Rights)

This section applies solely to California residents and supplements the information in this Privacy Policy.

Categories of Personal Information Collected. We have collected the following categories of personal information within the last twelve (12) months:

Category A: Identifiers. Examples include work email address, account identifier, and IP address. Collected: Yes.

Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Limited payment-related information (billing name and address) is collected by our third-party payment processor during checkout and is not stored in our systems. Collected: Via third-party payment processor only.

Category F: Internet or other similar network activity. Examples include interaction with our Services and usage data. Collected: Yes.

Category L: Sensitive personal information. Examples include account login information. Collected: Yes.

We have not collected Categories C, D, E, G, H, I, J, or K within the last twelve months.

Sources of Personal Information. We obtain personal information directly from you, indirectly from observing your activity, automatically through cookies and similar technologies, and from our service providers.

Use and Disclosure of Personal Information. We use and disclose personal information for the business and commercial purposes described in Section 2 of this Privacy Policy.

Sale and Sharing of Personal Information. We do not sell personal information as the term "sell" is commonly understood. We do allow service providers, including our third-party AI infrastructure providers, to process your personal information for the business purposes described in this Privacy Policy, which may be deemed a "sale" or "sharing" under the CCPA/CPRA.

Your CCPA/CPRA Rights. As a California resident, you have the following rights:

  • The right to know and access your personal information.
  • The right to delete your personal information, subject to certain exceptions.
  • The right to correct inaccurate personal information.
  • The right to opt out of the sale or sharing of your personal information.
  • The right to limit the use and disclosure of sensitive personal information.
  • The right not to be discriminated against for exercising your rights.

To exercise your rights, contact us at: security@binaurals.ai or by mail at Binaurals, Inc., 2261 Market Street #10815, San Francisco, CA 94114.

We will respond to verifiable requests within 45 days, which may be extended by an additional 45 days when reasonably necessary and with prior notice.

Sale of Personal Information of Minors Under 16. We do not knowingly collect personal information from minors under 16 through our Services. We do not sell the personal information of consumers we actually know are less than 16 years of age.

"Do Not Track" Signals. Our Services do not currently respond to Do Not Track signals. However, some third-party websites may track your browsing activities. You can set your preferences in your web browser to inform websites that you do not want to be tracked.

California's Shine the Light Law. Under California Civil Code Section 1798, California residents with an established business relationship with us can request information once a year about sharing their personal data with third parties for the third parties' direct marketing purposes. Contact us using the information below.

11. Tracking Technologies and Cookies

We use only strictly necessary cookies required for the Services to function securely.

Strictly Necessary / Session Cookies. We set two essential cookies: an authentication token (httpOnly) and a CSRF protection token. These cookies are required for the Services to function securely. We do not set analytics, marketing, or tracking cookies.

You can instruct your browser to refuse cookies, but doing so will prevent you from signing in or using the Services.

12. Links to Other Websites

Our Services may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and, where appropriate, by sending you an email or providing a prominent notice within our Services prior to the change becoming effective. We will update the "Effective" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy, you can contact us: