1. The short version
We collect what we need to get your company through a SOC 2 examination and nothing else. We do not sell your data, show you ads, or train AI models on it. When you connect a tool such as Google, we only read settings and records that count as SOC 2 evidence, and we never change anything in your account.
2. Who we are
Polara Labs Inc. ("Polara Labs", "we", "us") runs the platform at polaralabs.com. For any privacy question or request, email help@polaralabs.com.
3. What we collect
- Account details: your name, work email, company name and the teammates you invite.
- Assessment answers: what you tell us about your company, systems and controls.
- Evidence and documents: files you upload, policies we draft with you, and audit records.
- Payment details: handled by Stripe. We never see or store your full card number.
- Data from tools you connect: described in sections 4 and 5.
- Operational logs: sign-in times, errors and security events. No page content.
4. Data we access from Google
Connecting Google is optional. If you connect Google Workspace or Google Cloud, you choose the account and approve each permission on Google's own screen. We request read-only access only:
- Your Google account identity (
openid,email): the email address and account ID of the person who connects, so we know which Google account the connection belongs to. - Workspace users and groups (
admin.directory.user.readonly,admin.directory.group.readonly): who has an account, whether 2-Step Verification is on, admin roles, and group membership. Used to show access control and MFA for SOC 2. - Workspace audit reports (
admin.reports.audit.readonly): login and admin activity events. Used to show that access is logged and monitored. - Google Cloud settings (
cloud-platform.read-only,cloud-identity.groups.readonly,logging.read): IAM members and service accounts, key management, storage bucket settings, compute instances, organization policies and audit logging configuration. Used to show encryption, access control and logging for SOC 2.
We do not access Gmail, Drive, Calendar, Docs or any file or message content, and we cannot change anything in your Google account.
How we use it. Google data is used only to show SOC 2 evidence inside your Polara Labs workspace, where you, your invited teammates and your assigned independent auditor can see it. It is not used for advertising, not sold, not used to train or improve AI models, and not sent to our AI provider. People at Polara Labs do not read it unless you ask us to for support, it is needed for security, or the law requires it.
Limited Use. Polara Labs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Stopping access. Click Disconnect on the Integrations page, or remove Polara Labs at myaccount.google.com/permissions. Disconnecting revokes our access at Google and deletes the stored token right away.
5. Other tools you connect
AWS: you create a read-only role in your AWS account using Amazon's SecurityAudit and ViewOnlyAccess policies. We read account settings such as IAM users, password policy, logging, encryption and backups. We cannot read the contents of your databases or files. Delete the role at any time to end access. GitHub: our GitHub App reads organization members, two-factor settings, teams, branch protection, repository settings and each repository's CODEOWNERS file. It does not read or copy any other source code. Uninstall the app to end access.
6. How we use your data
To run the service: score your readiness, find gaps, draft policies, collect evidence, assemble your report package and hand it to your auditor. To bill you, keep the platform secure, and email you about your account. Your assessment answers and the policies you work on are sent to our AI provider (Anthropic Claude through AWS Bedrock) to draft your documents. AWS does not use that data to train models.
7. Who we share it with
We share data only with the services that run Polara Labs, and only what each one needs:
- Amazon Web Services: file storage, email delivery and AI drafting.
- Supabase: our database.
- Netlify: website and server hosting.
- Stripe: payments.
- Sentry: error reports, with secrets and personal content removed.
- Your assigned independent auditor: your report package and evidence.
We do not sell or rent personal data, and we share it with authorities only when the law requires it.
8. How we protect it
Data is encrypted in transit and at rest. Access tokens for connected tools are encrypted in our database with a separate key, and evidence files sit in private storage that opens only through short-lived signed links. Staff access is limited to what is needed to support you.
9. How long we keep it and how to delete it
We keep your data while your account is open. Email us to export it (within 30 days) or delete it (within 60 days), subject to records we must keep by law. Evidence already delivered to your auditor may be kept by the auditor under their own professional rules.
10. Your rights
You can ask to see, correct, export or delete your personal data, or object to how we use it. Email us and we will answer within 30 days. Polara Labs is for businesses and is not meant for anyone under 16.
11. Changes
If we change this policy in a way that matters, we will email active customers at least 14 days before it takes effect and update the date at the top.