Legal

Privacy

How we handle your data, in full. Last updated August 24, 2026. Questions? Reach us at support@tryren.com.

Privacy Notice

Last updated August 24, 2026

This Privacy Notice for Good Authority, Inc. (doing business as Ren) (“we,” “us,” or “our”), describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:

  • Visit our website at https://tryren.com or any website of ours that links to this Privacy Notice
  • Use the Ren platform, including via our web application or our integrations with Slack, Microsoft Teams, Google Calendar, and Zoom
  • Download and use our mobile application (Ren), or any other application of ours that links to this Privacy Notice
  • Engage with us in other related ways, including any marketing or events

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support@tryren.com.

Summary of Key Points

What personal information do we process?
When you visit, use, or navigate our Services — including when you connect Ren to Slack, Microsoft Teams, Google Calendar, or Zoom — we may process personal information depending on how you interact with us and the Services. Learn more in Section 1.
Do we process any sensitive personal information?
Some information may be considered “special” or “sensitive” in certain jurisdictions. We may process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law. Learn more in Section 1.
Do we collect any information from third parties?
We do not collect information from third parties except through integrations you or your organization explicitly authorize (e.g., Slack, Microsoft Teams, Google Calendar, Zoom).
How do we process your information?
We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. Learn more in Section 2.
In what situations and with which parties do we share personal information?
We may share information with the AI, infrastructure, and other service providers (“sub-processors”) described in Section 4, each bound by a written agreement.
How do we keep your information safe?
We maintain organizational and technical safeguards including encryption, tenant-level data isolation, and continuously monitored security controls, described in Section 10.
What are your rights?
Depending on where you are located, applicable privacy law may give you certain rights regarding your personal information. Learn more in Section 12.

1. What Information Do We Collect?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:

  • names
  • phone numbers
  • email addresses
  • job titles
  • usernames
  • passwords
  • billing addresses
  • debit/credit card numbers

Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

  • Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice at stripe.com/privacy.
  • Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Google or Microsoft account. If you choose to register in this way, we will collect certain profile information about you from the social media provider, as described in Section 7 below.

Information from Ren's Integrations

In Short: If you connect Ren to Slack, Microsoft Teams, Google Calendar, or Zoom, we process the information you or your organization authorize us to access through those integrations.

  • Slack and Microsoft Teams. When your organization connects Ren to Slack or Microsoft Teams, we process message content submitted to Ren through the integration, workspace and channel identifiers, and user identifiers, as needed to support coaching conversations and deliver features like the Morning Brief. See “How We Process Chat Integration Data” below for how this content is screened and handled before it reaches any AI Service Provider.
  • Google Calendar. When you authorize calendar access, we process calendar metadata (such as meeting titles, participants, and times) to support meeting preparation and coaching context.
  • Zoom. When you explicitly authorize it, we process Zoom meeting transcripts to support coaching insights related to that specific meeting.

We only ingest data from these integrations that you or your organization have explicitly authorized, and only the scopes necessary to provide the relevant feature. You can disconnect any integration at any time in your account or workspace settings.

How We Process Chat Integration Data

Messages received from Slack and Microsoft Teams are received through platform-verified webhooks and temporarily buffered in an internal message queue (Apache Kafka) for a maximum of 72 hours while they are validated and processed. Before any message is used to generate coaching content or sent to an AI Service Provider, it passes through an automated screening step (“Guardrails AI”) that detects and masks personally identifiable information, passwords, and other leaked secrets. Raw chat message content is not persisted to our primary database — only the sanitized, coaching-relevant output (e.g., a growth plan note or coaching moment) is stored.

Information automatically collected

In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

Like many businesses, we also collect information through cookies and similar technologies. The information we collect includes:

  • Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files, including IP address, device information, browser type and settings, and activity within the Services.
  • Device Data. Information about the computer, phone, tablet, or other device you use to access the Services, including IP address, device and application identification numbers, browser type, hardware model, and operating system.
  • Location Data. Information about your device's location, which can be either precise or imprecise, depending on the type and settings of the device you use. You can opt out of allowing us to collect this information by refusing access or disabling your Location setting on your device.
  • Google API. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. How Do We Process Your Information?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts.
  • To deliver and facilitate delivery of coaching content, guided conversations, growth plans, and related Services.
  • To respond to user inquiries and offer support.
  • To send administrative information to you, including changes to our terms and policies.
  • To fulfill and manage your orders, payments, returns, and exchanges.
  • To enable user-to-user communications, such as manager/report coaching interactions.
  • To request feedback and to contact you about your use of our Services.
  • To determine the effectiveness of our marketing and promotional campaigns.
  • To save or protect an individual's vital interest, such as to prevent harm.

3. What Legal Bases Do We Rely On To Process Your Information?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.

If you are located in the EU or UK, this section applies to you. The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases:

  • Consent — where you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.
  • Performance of a Contract — where processing is necessary to fulfill our contractual obligations to you, including providing our Services.
  • Legitimate Interests — where processing is reasonably necessary to achieve our legitimate business interests, such as supporting marketing activities or understanding how our users use our Services to improve user experience.
  • Legal Obligations — where processing is necessary for compliance with our legal obligations.
  • Vital Interests — where processing is necessary to protect your vital interests or those of a third party.

If you are located in Canada, we may process your information with your express or implied consent, which you may withdraw at any time, or in certain exceptional cases as permitted by applicable Canadian law (for example, investigations and fraud prevention, business transactions, or compliance with a subpoena, warrant, or court order).

4. When And With Whom Do We Share Your Personal Information?

In Short: We may share information in specific situations described in this section and with the sub-processors listed below.

We may need to share your personal information in the following situations:

  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

Sub-processors. We share personal information with the service providers below (each engaged under a written data processing agreement) to provide, secure, and improve the Services:

Sub-processorPurposeData ProcessedRegion
AWSCloud infrastructure and hostingAll primary application data; physical/environmental security delegated to AWSUnited States
AnthropicPrimary AI Service Provider for coaching inferencePrompts and retrieved context sent for inference; zero-retention enterprise terms applied; no training on customer dataUnited States
OpenAIBackup AI Service Provider; embedding generationPrompts/context (backup inference); text for embedding generation; zero-retention enterprise terms applied; no training on customer dataUnited States
PineconeVector database for AI-powered retrievalEmbedded vector representations of coaching content, stored in a dedicated, tenant-scoped namespace per customer workspaceUnited States
LangSmithAI observability and quality evaluationTraces and evaluation runs; personal information minimized before sendingUnited States
Guardrails AIAutomated PII detection and message sanitizationInbound Slack/Microsoft Teams messages screened before further processing; not used as a data storeUnited States
VapiVoice AI interface for voice-based coaching sessionsVoice input and related session data during AI-guided coaching conversationsUnited States
Auth0Application authenticationLogin credentials and session data for the Ren applicationUnited States
OktaEnterprise single sign-on (available on request)SAML assertions and identity attributes for customers using this integrationUnited States
StripePayment processingPayment instrument data for billingUnited States

A current, living list of sub-processors is maintained at tryren.com/trust/sub-processors.

Tenant Isolation Across Sub-processors

Each customer organization's data is logically isolated within our systems. Operational data in our primary database is scoped by a unique tenant identifier enforced on every data access path. Where we use vector storage (Pinecone) to support AI-powered retrieval, each customer workspace's embeddings are stored in a dedicated, tenant-scoped namespace — meaning one customer's coaching data cannot be retrieved through another customer's queries. This namespace-level separation is applied consistently across every workspace we support.

5. Do We Use Cookies And Other Tracking Technologies?

In Short: We may use cookies and other tracking technologies to collect and store your information.

We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.

We also permit third parties and service providers to use online tracking technologies on our Services for analytics, including to help us understand feature usage and improve the product. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.

Google Analytics. We may share your information with Google Analytics to track and analyze the use of the Services. To opt out of being tracked by Google Analytics across the Services, visit tools.google.com/dlpage/gaoptout.

6. Do We Offer Artificial Intelligence-Based Products?

In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer AI-powered coaching features (“AI Products”), including guided conversation threads, AI coaching guidance, Morning Brief and Calendar Brief summaries, and structured growth-plan assistance. The terms in this Privacy Notice govern your use of the AI Products within our Services.

Use of AI Technologies

We provide the AI Products through third-party AI Service Providers, including Anthropic (our primary provider) and OpenAI (used as a backup provider and for embedding generation). Your input, output, and relevant personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products. Both providers are engaged under enterprise terms with zero-retention and no-training addenda applied: customer data is not used to train their models.

Ren also offers voice-based coaching sessions through Vapi, our voice AI interface provider, for organizations using that feature. Voice input is processed to support the same coaching pipeline described in this Privacy Notice.

Content ingested from chat integrations (Slack, Microsoft Teams) is screened and sanitized before it reaches any AI Service Provider, as described in Section 1 (“How We Process Chat Integration Data”).

AI Observability

We use LangSmith to trace and evaluate the performance of our AI Products for quality and debugging purposes. Personal information is minimized before being sent to LangSmith.

How We Process Your Data Using AI

All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with our AI Service Providers and other sub-processors described in Section 4. This ensures your personal information is protected throughout the process.

7. How Do We Handle Your Social Logins?

In Short: If you choose to register or log in to our Services using a third-party account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using a third-party account, such as Google or Microsoft, through our authentication provider, Auth0. Where you choose to do this, we will receive certain profile information about you from that provider, which often includes your name, email address, and profile picture, as well as other information you choose to make public on that platform. For customers with enterprise single sign-on requirements, we also support Okta SAML 2.0 SSO on request.

We will use the information we receive only for the purposes described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. We do not control, and are not responsible for, other uses of your personal information by your third-party identity provider. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information.

8. Is Your Information Transferred Internationally?

In Short: We may transfer, store, and process your information in countries other than your own.

Our primary data stores (including our production database and file storage) are hosted on Amazon Web Services in the United States. Our AI Service Providers and other sub-processors listed in Section 4 also currently operate in the United States. Regardless of your location, your information may be transferred to, stored by, and processed by us and our sub-processors in the United States.

If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, these countries may not necessarily have data protection laws as comprehensive as those in your country. We will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law, including by using the European Commission's Standard Contractual Clauses for relevant cross-border transfers. Our Standard Contractual Clauses can be provided upon request.

9. How Long Do We Keep Your Information?

In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice, and, for organizational customers, for the duration of the applicable services agreement.

  • Customer service data. If your organization has a services agreement with us (such as a Master Subscription Agreement), your organization's service data — including account, growth plan, coaching, and related content — is retained for the duration of your active contract with us. In accordance with our internal Data Management Policy, service data is securely deleted within up to 180 days following contract termination, unless a different retention period is agreed in writing or a longer period is required by law.
  • AI Service Provider processing data. Separately from our own retention above, our AI Service Providers (Anthropic and OpenAI) each retain API input and output data for a 30-day window, solely for their own safety and monitoring purposes, in accordance with their standard enterprise terms. This provider-side retention window is independent of, and shorter than, Good Authority's own retention of your service data described above.
  • Chat integration content. Slack and Microsoft Teams messages are buffered for a maximum of 72 hours during processing and are not retained in raw form beyond that window; only sanitized, coaching-relevant output is stored for the duration described above.
  • Individual account data. For individual users without an organizational services agreement, we will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your information is stored in backup archives), we will securely store it and isolate it from further processing until deletion is possible.

10. How Do We Keep Your Information Safe?

In Short: We aim to protect your personal information through a system of organizational and technical security measures, examined as part of our SOC 2 Type II audit.

We have implemented technical and organizational security measures designed to protect the security of any personal information we process, including:

  • Encryption at rest: AES-256 encryption for our database (AWS RDS), file storage (AWS S3), and compute volumes, using AWS-managed keys via AWS KMS.
  • Encryption in transit: TLS 1.2+ for all external and internal service-to-service traffic.
  • Tenant isolation: every record in our primary database is scoped by a unique tenant identifier, and AI-related vector data is stored in a dedicated, tenant-scoped Pinecone namespace per customer workspace, so that customer data is logically separated at every layer.
  • Chat data screening: inbound Slack/Microsoft Teams messages are buffered in Apache Kafka for a maximum of 72 hours and screened by an automated PII-detection step (Guardrails AI) before any content is used in coaching output or sent to an AI Service Provider.
  • Network security: private subnets for data stores, restricted security groups, and a Web Application Firewall at the public edge; internal backend services are not directly reachable from the public internet.
  • Access control: role-based access control and least-privileged access to production systems, with quarterly access reviews.
  • Independent audit: our controls are examined annually as part of a SOC 2 Type II audit, and we undergo annual third-party penetration testing.
  • Continuous monitoring: security and compliance controls (including encryption and MFA enforcement) are continuously monitored through our automated compliance platform (Vanta), rather than assessed only at a point in time.

However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk.

11. Do We Collect Information From Minors?

In Short: We do not knowingly collect data from or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction.

We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 (or the equivalent minimum age in your jurisdiction) or that you are the parent or guardian of such a minor and consent to that minor's use of the Services. If we learn that personal information from a user under the applicable age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data. If you become aware of any such data, please contact us at j@tryren.com.

12. What Are Your Privacy Rights?

In Short: Depending on your state of residence in the US or in some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information.

In some regions, you have certain rights under applicable data protection laws, which may include the right to: (i) request access to and obtain a copy of your personal information; (ii) request rectification or erasure; (iii) restrict the processing of your personal information; (iv) data portability, if applicable; and (v) not be subject to automated decision-making. If a decision that produces legal or similarly significant effects is made solely by automated means, we will inform you, explain the main factors, and offer a simple way to request human review. You can make such a request by contacting us using the details in Section 16.

If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your Member State or UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

  • Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw it at any time by contacting us using the details in Section 16. This will not affect the lawfulness of processing before its withdrawal.
  • Opting out of marketing communications. You can unsubscribe at any time by clicking the unsubscribe link in our emails, replying “STOP” to our SMS messages, or contacting us. We may still send you non-marketing, service-related messages necessary for the administration and use of your account.
  • Account information. You can review, change, or request deletion of your account information at any time by contacting us or updating your account settings. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases, though we may retain some information as required to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, or comply with legal requirements.

13. Controls For Do-Not-Track Features

Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. Because there currently is no industry or legal standard for recognizing or honoring DNT signals, California law requires us to disclose that we do not respond to them at this time.

14. Do United States Residents Have Specific Privacy Rights?

In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you, correct inaccuracies, obtain a copy of, or delete your personal information.

Categories of Personal Information We Collect

The table below shows the categories of personal information we have collected in the past twelve (12) months. This table is illustrative and does not reflect the personal information we collect from any specific individual; see Section 1 for a full description.

CategoryExamplesCollected
A. IdentifiersReal name, alias, postal address, phone number, unique online identifier, IP address, email address, account nameNO
B. Customer recordsName, contact information, employment, employment history, and financial informationYES
C. Protected classificationsGender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic dataNO
D. Commercial informationTransaction information, purchase history, and payment informationNO
E. Biometric informationFingerprints and voiceprintsNO
F. Internet/network activityBrowsing history, search history, online behavior, and interactions with our and other websites and applicationsYES
G. Geolocation dataDevice locationNO
H. Audio/visual informationImages, audio, video, or call recordingsNO
I. Professional informationBusiness contact details, job title, and work historyNO
J. Education informationStudent records and directory informationNO
K. InferencesInferences drawn from collected information to create a profile of preferences or characteristicsNO
L. Sensitive personal informationDebit or credit card numbers and account login informationYES

We use and retain the collected personal information as needed to provide the Services or for: Category B — the duration described in Section 9; Category F — as long as necessary for the purposes described in this notice; Category L — as long as necessary for billing and account purposes.

We may disclose your personal information to our sub-processors listed in Section 4 pursuant to a written contract with each. We have not disclosed, sold, or shared personal information to third parties for a business or commercial purpose in the preceding twelve (12) months, and we will not sell or share personal information belonging to website visitors, users, or other consumers.

Your Rights

You have rights under certain US state data protection laws, though these rights are not absolute and we may decline a request as permitted by law. These rights include the right to know whether we are processing your personal data, to access it, to correct inaccuracies, to request deletion, to obtain a copy of data you previously shared with us, to non-discrimination for exercising your rights, and to opt out of targeted advertising, sale, or certain profiling. Depending on your state, you may have additional rights described in the original notice on file, including rights to obtain lists of categories or specific third parties to which we have disclosed or sold personal data.

How to Exercise Your Rights

To exercise these rights, you can contact us by submitting a data subject access request or by emailing hello@tryren.com. Under certain state laws, you may designate an authorized agent to make a request on your behalf; we may deny a request from an agent that does not provide valid proof of authorization.

Request Verification and Appeals

Upon receiving your request, we will need to verify your identity, and may request additional information for that purpose. If we decline to take action on your request, you may appeal by emailing support@tryren.com; we will respond in writing with our reasoning, and if your appeal is denied, you may submit a complaint to your state attorney general.

California “Shine The Light” Law

California Civil Code Section 1798.83 permits California residents to request, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year. To make such a request, please contact us using the details in Section 16.

15. Do We Make Updates To This Notice?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated “Last updated” date at the top of this Privacy Notice. If we make material changes, we may notify you by prominently posting a notice of the changes or by directly notifying you. We encourage you to review this Privacy Notice periodically.

16. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may contact our Data Protection Officer by email at j@tryren.com, or by post at:

Good Authority, Inc.
Data Protection Officer
1536 N Coast Hwy 101 Ste 102, Encinitas, CA 92024
United States

17. How Can You Review, Update, Or Delete The Data We Collect From You?

Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please submit a data subject access request to support@tryren.com.

Ren logo

Start free

Free for up to 4 people. No credit card. Create your account, then connect Slack in a couple of clicks.

or use your email

Your conversations with Ren are always private.