1. Who we are
Nrth OS is made by Nrth AI AS, Bergen, Norway. Org. no. [org.nr]. We are the controller for the personal data we collect through this website and for account data in Nrth OS. For the content customers put into or connect to Nrth OS, we are the processor. See section 3.
Nrth OS is a workspace where businesses set up AI assistants for different parts of the business, connect them to their documents and let them run tasks now or on a schedule.
This policy covers this website, trynrth.com, and Nrth OS. It explains what personal data we process, why, where it is processed, who we share it with, how long we keep it and what rights you have. It is also available in Norwegian.
Nrth OS is under development, in the pilot phase. Where this policy describes the product, it describes how Nrth OS is being built to work. Most of it, including memory and the Google Drive and Microsoft 365 connections, is not built yet.
Questions about privacy: privacy@trynrth.com. Security issues: security@trynrth.com. More about us is on the company page.
2. The website
When you visit
The website does not use cookies and does not track you across other websites.
Analytics: [Plausible without cookies / no analytics]
The website is hosted by Vercel. Like any web host, Vercel's servers receive the technical information your browser sends with each request, such as your IP address, the page you ask for and your browser type. We use it only to deliver the website and to protect it against attacks and abuse. Our legal basis is our legitimate interest in running a website that works and is secure (GDPR article 6(1)(f)). Logs are deleted after [retention period for Vercel server logs]. Pages may be delivered from a Vercel location near you, which can be outside the EU.
Fonts are served from our own website, not from Google Fonts or other services. Apart from any analytics named above, the website loads no scripts from other companies.
The pilot form
When you apply for the pilot program through the form on the pilot page, the form asks for:
- Company (required)
- Your name (required)
- Work email (required)
- Role (optional)
- Company size (optional)
- Which area you want to start with (required)
- Where your documents are (optional)
- Where your company is based (required)
- What you want the assistant to do, in your own words (optional)
- Your consent to be contacted about the pilot program (required)
Giving us this information is voluntary. We need the required fields to review your application, and the form cannot be sent without them.
The form also records which language you used and when you sent it. It has a hidden field and a time check that help us filter out spam. Apart from the technical information described above, we collect nothing else through the form. Please do not write sensitive personal data in the free-text field.
Why we collect it. To review your application, reply to you and contact you about the pilot program. We read and assess every application ourselves.
Legal basis. Your consent (GDPR article 6(1)(a)). You can withdraw it at any time by writing to privacy@trynrth.com. We then delete your application. Withdrawing does not affect what we did before.
How it is stored. The form is handled by a server function at Vercel in Frankfurt (EU). It sends your application to our inbox as an email through Resend, our email service, and sends you a confirmation email. During the pilot phase, applications are kept only as email, in our inbox at [email provider for our inbox]. They are not stored in a database.
How long we keep it. We delete your application [12] months after we receive it. If your company enters into a pilot agreement with us before then, we keep your contact details as part of the customer relationship, see section 3.
If you email us
If you write to one of our addresses, we use your message and email address to answer and follow up. Our legal basis is our legitimate interest in answering you (GDPR article 6(1)(f)). [Retention period for email correspondence.]
3. The product: our roles
In Nrth OS, Nrth AI AS has one of two roles, depending on the data.
Account data: we are the controller
Nrth AI AS is the controller for account data. This is the data we need to run a company's account and bill for the service:
- The company: name, home region, tier and subscription
- Users: name, email address and which company they belong to
- Sign-in and security: how and when users sign in, and a log of important actions in the account
- Billing: invoice and payment details, and the credits bought and used
We use account data to give users access, to run and secure the service, to give support, to show usage and to bill for it. Where you have entered into the agreement with us yourself, for example as a sole proprietor, our legal basis is that agreement (GDPR article 6(1)(b)). For other users, it is our legitimate interest in providing the service the company has agreed with us to the users the company gives access to (article 6(1)(f)). For billing records, it is our duty to keep accounts under Norwegian accounting law (article 6(1)(c)).
Payments are handled by our payment provider. Card numbers are not stored in Nrth OS.
We keep account data while the company has an account with us, and delete it [retention period for account data after an account is closed] after the account is closed. Billing records are kept for as long as Norwegian accounting law requires.
Customer content: we are the processor
Nrth AI AS is the processor for the content a customer puts into or connects to Nrth OS. Content includes:
- Files and connected sources, and the knowledge index made from them
- Assistants and their instructions
- Tasks, the files given to them, and their results
- Feedback on results
- Skills the company builds
- Memory
The customer is the controller. It decides what is put in and what it is used for. We process customer content only to provide Nrth OS to the customer, and only on the customer's instructions.
A data processing agreement (DPA) is entered into with each customer. It covers, among other things, security, subprocessors, deletion and how we help the customer when someone uses their rights. We will publish our DPA before launch.
Content is deleted when the customer deletes it, and no later than [time until content is deleted after an account is closed] after the account is closed. Deleted data is removed from backups within [backup retention period].
If you use Nrth OS through your employer, your employer decides what is put into it. Questions about that content should go to your employer first. We help our customers answer them.
4. Where data is processed
Home region
When a company signs up, it chooses a home region: the EU (Frankfurt) or the US. The choice cannot be changed afterwards. The company's files, knowledge index, memory and results are stored in that region, and its tasks run there. Which models may process a task's data, and where, is set by each assistant's data policy, described below.
Account data for all customers is kept in the EU, including for companies with the US as home region. It is kept apart from customer content, which is stored in the home region.
A data policy for each assistant
Each assistant has a data policy. It decides which models may process that assistant's data when a task runs. A company with the EU as home region can choose between:
- In the EU. The default. The models process the data in the EU. Some of the providers are owned by US companies. They are subject to US law whatever the region, and we label them.
- European providers only. The models that process the data run in the EU and come from EU-owned providers only.
- Our own model. Tasks are sent from Nrth OS to a model endpoint the company chooses: its own server, or a provider it chooses. The company decides where that endpoint runs and what happens to the data there.
The data policy applies to the models. Storage, hosting, web search and email go through the same subprocessors whatever the data policy, see section 8. Some of them are US-owned.
“Our own model” does not mean Nrth OS runs on your side. Tasks still run in Nrth OS, in the home region. Only what Nrth OS sends to the model goes to your endpoint. In this version, Nrth OS does not run on your own hardware. Running fully on your own hardware is planned for a later version, Nrth Node.
A company with the US as home region gets the same kind of choice, with processing in the US as the default.
Every model, labelled
The model catalog shows, for each model, who the provider is, where the model processes data, where the provider is based and so which country's law it is subject to, and whether the provider keeps data. You can see an example on our data page. The final catalog is set after testing and published before launch.
Other parts of a task
When a task searches the web, the search query is sent to a web search provider chosen for your home region. When a result is sent by email, it goes through an email service in your home region. To make knowledge searchable, Nrth OS uses a model that follows the assistant's data policy.
Nrth OS is being built so that every task runs in its own isolated environment, deleted when the task is done. Keys to your own model and to connected accounts are kept in an encrypted vault, never in the task itself. More of these rules are described under how it's built.
5. No training on customer data
No model is trained on customer data. That covers files, knowledge, tasks, results, feedback and memory, and data from Google and Microsoft 365.
Instead, Nrth OS gets better in three ways the customer can see, control and undo. None of them is training:
- Knowledge. The sources the customer connects: uploaded files, Google Drive folders, SharePoint libraries and OneDrive folders. They are split into passages and indexed in the home region, so a task can find what is relevant. Remove a source, and its index is deleted.
- Memory. What users have told Nrth OS and the feedback they have given. See the next section.
- Skills. Tasks that work, saved as reusable skills after the customer approves them.
More about this is on our data page.
To build the index, text is turned into numbers (embeddings) by a model that follows the assistant's data policy. This uses the model. It does not change or train it.
Some model providers may keep requests for a period after processing them. The model catalog shows what each provider keeps. If an assistant uses the company's own model, the company decides what that endpoint keeps and what the data is used for there.
6. Memory
Memory is what Nrth OS remembers between tasks, from what users tell it and from their feedback on results. That includes the company description given at sign-up and the instructions users give. It has two layers:
- Company memory, shared by all the company's assistants: what the company does, the terms it uses, fixed rules, language and tone.
- Assistant memory, for one assistant only: its subject area, the sources it should use, preferred formats and ongoing work.
Memory holds only what users have actually said in instructions and feedback. Nrth OS does not add its own conclusions. Memory is stored in the home region.
The customer can read every line of memory in plain text, change any line, and delete all of it in one step.
What is never written to memory
Some things are never written to memory, whatever a user says:
- ID numbers
- Payment card and account numbers
- Health information
- Information about children
- Special categories of personal data under GDPR article 9
Nrth OS is being built with these rules in the code, with tests that check them. The list applies to memory. Files and sources are stored and indexed as they are, and they can contain such information. The customer, as controller, then decides whether to use them, and the DPA applies. See also what it never keeps.
7. Google and Microsoft 365 user data
Google Drive and Microsoft 365 are connections in Nrth OS. They let an assistant use your company's documents as knowledge. This section explains what data Nrth OS can access, and how that data is used, stored, shared and deleted. In short, Nrth OS uses the data only to recognize the account you connect and to let assistants work with the files you choose yourself.
Nrth OS asks for these Google permissions (scopes), and no others:
- openid, email and profile. These give Nrth OS the email address, name and profile picture of the Google account, and an ID that identifies the account. Nrth OS uses them to recognize the account you connect and to show you which Google account it is.
- drive.file. This gives Nrth OS access only to the files and folders you choose yourself in the Google Picker, the window from Google where you pick files, and to the files in a folder you choose. Nrth OS cannot see anything else in your Google Drive. It uses this access to read these files.
Nrth OS does not ask for access to Gmail, Google Calendar, Google Contacts or any other Google service.
Microsoft 365
Nrth OS connects to Microsoft 365 through Microsoft Graph. It asks for these delegated permissions, and no others:
- User.Read. The name, email address and basic profile of the person who connects. Nrth OS uses them to recognize the account you connect and to show you which Microsoft account it is.
- Files.Read. Read access to the OneDrive files of the person who connects.
- Sites.Read.All. Read access to the SharePoint sites the person who connects has access to.
- offline_access. Lets Nrth OS keep your sources up to date on a schedule, without you having to sign in again each time.
Delegated means Nrth OS acts on behalf of the person who connects, and can never see more than that person can. The file permissions only allow reading, so Nrth OS cannot change or delete anything in Microsoft 365.
These permissions are wider than what Nrth OS uses. Nrth OS only reads and indexes the SharePoint libraries and OneDrive folders you connect as sources, and a task can only open files from those sources. Nrth OS does not ask for access to email, calendars or contacts. Depending on your organization's settings, an administrator may need to approve Nrth OS before you can connect it.
How the data is used
This applies to data from both Google and Microsoft 365.
The name, email address and account ID are used to recognize the account you connect and to show you which account it is.
The files and folders you choose become knowledge for the assistant you connect them to. Nrth OS checks the sources for changes once a day, and when you ask it to update now.
To index a file, Nrth OS reads it, splits the text into passages and sends them to a model allowed by the assistant's data policy. That model turns them into numbers (embeddings) for the search index.
When the assistant runs a task, the most relevant passages are taken from the index, and the assistant can also open files from the connected sources through Nrth OS. The passages and the files it opens are sent to a model allowed by the assistant's data policy, so it can do the task. The task itself never holds the access tokens.
The result can contain content from the files. It is stored in the home region, shown in Nrth OS and sent by email to the recipients set up for the task. If you turn a task into a skill, Nrth OS uses the task's files and result to build it.
Nrth OS uses this data only to provide these features. It is not used for anything else.
How the data is stored
The index made from your files is stored in your company's home region. It holds the text of the files split into passages, which together cover the full text, a set of numbers for each passage that makes it searchable, and what is needed to keep the index up to date, such as file names, a fingerprint of each file's content and when the source was last synced.
Results of tasks that used these files are stored in your company's workspace, in the home region.
The name, email address and account ID from Google or Microsoft[, and the profile picture if it is kept,] are stored [with the account data in the EU / with the source in the home region].
The access Google and Microsoft give Nrth OS to your files (tokens) is kept in an encrypted vault. It is used only by the part of Nrth OS that fetches your files, never inside a task.
How the data is shared
Data from Google and Microsoft 365 is never sold, never used for advertising and never used to assess creditworthiness. It is not used to develop, improve or train AI models, by us or by the model providers we use.
We share it only:
- with the subprocessors we need to run Nrth OS, such as providers of hosting and storage, and the model providers the assistant's data policy allows
- on your instructions, with your company's own model endpoint, if the assistant uses “Our own model”. Your company then decides what happens to the data there
- on your instructions, with the people a result is sent to by email
- with others, where the law requires it
People at Nrth AI AS do not read this data, except in three cases: you ask us to, for example in a support case; it is needed to investigate abuse or a security incident; or the law requires it.
How the data is deleted
When you remove a source from an assistant, its index is deleted. If you delete a file in the source, or move it out of the folder or library you chose, it is removed from the index at the next sync.
Results that tasks made using these files are not deleted with the source. They stay in your company's workspace, in the home region, until [they are deleted / the account is closed]. When a company's account is closed, the index and other content are deleted within the period given in section 3.
You can remove Nrth OS's access at any time. For Google, go to your Google Account. For Microsoft 365, your administrator can remove it in Microsoft Entra, and depending on your organization's settings you can also remove it yourself in your Microsoft account settings. Nrth OS then stops syncing and can no longer read your files. This does not delete what has already been indexed. To delete it, remove the source in Nrth OS or write to privacy@trynrth.com.
Google API Services User Data Policy
Nrth OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same rules to data from Microsoft 365.
8. Subprocessors
We use other companies to run Nrth OS. They cover hosting, computing and databases, AI models, web search, email, monitoring of quality and cost per task, and payments. For customer content, where we are the processor, these companies are our subprocessors. For this website and for account data, where we are the controller, they are our processors. Which model providers an assistant uses depends on its data policy and is shown in the model catalog.
The list will show each company, what it does and where it processes data.
[List of subprocessors published before launch.]
For this website we use Vercel for hosting, Resend for sending email and [email provider for our inbox] to receive and keep pilot applications, as described in section 2.
An example of the model catalog is on our data page. The final catalog, with every model provider, is published before launch. The DPA will set out how we tell customers before we start using a new subprocessor.
9. Transfers outside the EU and EEA
Nrth AI AS is based in Norway, which is part of the EEA. Some of the companies we use are based outside the EU and EEA, process data there, or may access data from there even when it is stored in the EU.
When personal data is transferred to a country outside the EU and EEA that the European Commission has not found to protect personal data adequately, we use the Commission's standard contractual clauses (SCCs). When the recipient is a US company certified under the EU–US Data Privacy Framework, the transfer can instead rely on the Commission's adequacy decision for that framework. Write to privacy@trynrth.com for a copy of the safeguards that apply.
Four cases are worth knowing about:
- US home region. The content of companies that choose the US is stored in the US, and the models process it in the US, unless an assistant uses “Our own model”. Their account data is kept in the EU.
- US-owned providers in the EU. When a US-owned provider processes data in the EU, that is not in itself a transfer out of the EU. But said plainly: the provider is subject to US law, which can require it to hand over data, whatever region the data is processed in. That is why the model catalog shows where each provider is based, and why you can choose “European providers only” for the models. Storage, hosting, web search and email go through the subprocessors in section 8, whatever the data policy.
- The website. Vercel (hosting), Resend (email) and [email provider for our inbox]: [where they process data and which safeguard applies].
- “Our own model”. Nrth OS sends tasks to the endpoint the company has chosen, which can be anywhere. If it is outside the EU and EEA, the company, as controller, must have a legal basis for that transfer.
10. Your rights
You have the right to:
- see the personal data we hold about you
- have wrong data corrected
- have your data deleted
- get a copy of your data in a common, machine-readable format, to take it to another service (data portability)
- object to processing, and ask us to limit processing
- withdraw your consent at any time, where we rely on consent
Some of these rights apply only in certain situations.
Right to object. Where our legal basis is our legitimate interest, as for server logs, emails you send us and account data (sections 2 and 3), you can object to the processing on grounds relating to your own situation. We then stop, unless we have compelling reasons that outweigh your interests, or need the data for a legal claim.
To use your rights, write to privacy@trynrth.com. We answer within one month. We may ask you to confirm who you are first.
If your request is about content in Nrth OS, your company is the controller and answers it. We help your company do that. Much of it can also be done directly in Nrth OS, such as reading, changing and deleting memory, removing sources and deleting files.
No automated decisions. We do not make decisions about you based only on automated processing, including profiling, that have legal or similarly significant effects for you.
Complaints. If you think we process personal data in breach of the rules, you can complain to the Norwegian Data Protection Authority, Datatilsynet, or to the data protection authority where you live or work in the EU or EEA. We would appreciate hearing from you first, but you do not have to.
If you are in the US
You can make the same requests wherever you live: access, correction, deletion and a copy of your data. Depending on your state, you may have further rights under state privacy law, and we will respect them where they apply. We do not sell personal information and do not share it for targeted advertising. Using your rights will not affect how we treat you. If you are not satisfied with our answer, you can complain to Datatilsynet, which supervises us, or to the consumer protection or privacy authority in your state.
11. Changes to this policy
We update this policy when the product, our subprocessors or the rules change, and as Nrth OS is built. The last updated date on this page shows when it last changed.
If a change is material for how we process personal data, we will tell our customers by email before it takes effect.
This policy is also available in Norwegian, with the same content.