Privacy Policy

Last Updated: October 2025

1. Introduction

Narwin (“we,” “our,” or “us”) provides AI-powered tools to assist organizations with RFP, grant writing, and workplace content search. We are committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your information.

By using Narwin, you agree to the terms of this Privacy Policy.

2. Data We Collect

We collect data to provide and improve our services. This includes:

Authentication Data

When you sign in via email or Google, we use Firebase Authentication to securely manage user accounts (Name, Email, UID).

User-Connected Sources

  • Google Drive: Files and documents you select.
  • Slack: Channel messages and metadata from authorized workspaces.
  • Notion: Page content and workspace structure.
  • Uploaded Files: PDFs, Word, Excel, Markdown, etc.

3. Purpose of Data Usage

Your data is used exclusively to:

  • Provide RFP and grant generation capabilities.
  • Deliver content search and document automation.
  • Power AI responses via OpenAI GPT-4.1 & Perplexity Sonar Pro.
  • Parse files using LLamaParse.
  • Index and retrieve documents using our internal vector database.

4. Data Sharing & Subprocessors

We rely on trusted subprocessors to provide our services:

  • Firebase & Supabase: Authentication and database storage.
  • Weaviate: Secure vector database for document indexing.
  • OpenAI & Perplexity AI: AI responses and knowledge retrieval.
  • LlamaParse: File parsing and document structuring.

5. Data Retention & Deletion

Uploaded and connected data are retained for active use only. If you deactivate your account, we delete all user-associated data within 7 calendar days, unless legally obligated to retain it longer.

6. Slack Permissions & Data Access

Important Notice: Narwin does not inherit Slack’s internal channel-level permissions. Once added to a channel, all content is indexed and accessible to authorized users within Narwin.

Recommendation: Do not add Narwin to channels containing sensitive HR or financial content.

7. Security Measures

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access Controls: Role-based and workspace-scoped restrictions.
  • Environment Isolation: Multi-tenant architecture for logical data isolation.

8. Your Rights

You have the right to Access, Correction, Deletion, and Restriction of your data. To exercise these rights, contact our privacy team.