Our legal documents are provided in English. The English version is the legally binding version.

Privacy Policy

Last updated: June 5, 2026 · Version 2026-06-05

This Privacy Policy explains how B2 Group LLC ("B2 Group", "we", "us", or "our"), a Wyoming limited liability company, handles personal data in connection with the website and software-as-a-service product SentiTrack.ai ("SentiTrack", "the Service") available at https://sentitrack.ai. It is important to understand that we act in two very different roles depending on the data involved, and this Policy is organized around that distinction. For our website, marketing, and customer-account data we act as a controller. For the email metadata, sentiment scores, and employee records that our customers send through the Service, we act as a processor / service provider on the customer's behalf — the customer is the controller. Please read this Policy together with our Terms of Service, Cookie Policy, and Imprint.

1.Who We Are and How to Contact Us

B2 Group LLC is the operator of SentiTrack.ai. Our registered address is 1309 Coffeen Ave, Sheridan, WY 82801, United States.

For privacy questions, data-subject requests, or consumer-rights requests, contact our privacy team at [email protected]. You can also reach us at:

We do not maintain a public telephone number for privacy matters; please use the email addresses above. Full operator identification is available in our Imprint.

The Service is primarily directed at the United States market but is also made available to customers in other countries. It is the customer's sole responsibility to verify that use of the Service is lawful in their jurisdiction; customers outside the United States use the Service entirely at their own risk.

2.Our Two Roles: Controller vs. Processor

SentiTrack measures the sentiment of an organization's email communications (expressed as a score from 1 to 10) and aggregates those scores across organizational and demographic dimensions such as department, branch or location, role, age, and gender. Because of how the Service works, the personal data involved falls into two distinct contexts:

Context A — Data we handle as a Controller

For our public website, our marketing, and the accounts of the organizations and individuals who sign up to administer SentiTrack, we determine the purposes and means of processing. Here we are the "controller" under the EU/UK General Data Protection Regulation (GDPR/UK-GDPR) and the "business" under US state privacy laws.

Context B — Customer Data we handle as a Processor

When a subscribing organization (our "Customer") uses the Service to monitor its email communications, the Customer decides what mail to monitor, whom to monitor, and which attributes to record. The Customer is the "controller" / "business" for that data, and B2 Group acts only as a "processor" / "service provider" that processes such "Customer Data" strictly on the Customer's documented instructions and as described in our Terms of Service and any applicable data processing agreement. We do not use Customer Data for our own purposes.

It is the Customer's responsibility — not ours — to establish a lawful basis for monitoring, to perform any required Data Protection Impact Assessment (DPIA), to give any legally required notice to monitored individuals and to obtain any required consent, and to confirm that monitoring email and using the Service is lawful in the Customer's jurisdiction and permitted under the Customer's own internal and company policies.

B2 Group does not control and is not responsible for the Customer's decisions regarding whom or what to monitor, the lawfulness of the Customer's monitoring, or the Customer's mail-flow configuration; liability for these matters rests with the Customer as set out in our Terms of Service.

3.Data We Collect as a Controller (Context A)

When you visit our website or create and use a SentiTrack account, we collect the following categories of data as a controller:

Account and registration data

  • Identification and contact details of the administrators who register an organization and any users they invite, such as name, work email address, and password (stored only as a salted hash).
  • Organization details, such as the organization name and the configuration choices made in the account (for example, the selected AI provider and model, retention setting, and whether optional demographic attributes are enabled).
  • Authentication and session data, such as access and refresh tokens used to keep you signed in (stored in your browser's local storage).

Billing data (via Stripe)

Paid subscriptions are processed by Stripe, Inc. We receive limited billing information from Stripe such as your billing name, billing email, plan, subscription status, the last four digits and brand of your card, and transaction history. We never see or store full payment-card numbers; full card details are handled directly by Stripe under its own privacy practices.

Support communications

If you contact us for support, sales, legal, or privacy matters, we collect the contents of those communications and your contact details so we can respond and keep records.

Website, device, and cookie data

When you use our website we collect technical data such as IP address, browser and device information, pages viewed, and similar usage data, including through cookies and similar technologies. See our Cookie Policy for details and choices.

4.Customer Data We Process as a Processor (Context B)

Each Customer organization is assigned a unique 10-character ingest address at our domain (for example, [email protected]). The Customer configures a mail-flow rule on its own mail server, or instructs its employees to manually BCC that address, so that monitored inbound and/or outbound mail is copied to the ingest address. A polling worker reads that mailbox, routes each message to the owning organization, and submits the message body to the third-party AI provider selected by that organization for sentiment scoring (see "How Email Bodies Are Scored" below).

Email metadata and sentiment scores

For each processed message we store only the following metadata and the resulting score:

  • Sender email address (From) and recipient email addresses (To and Cc);
  • Timestamp and direction of the message (inbound or outbound);
  • A one-way cryptographic hash of the subject line (not the plaintext subject);
  • A one-way cryptographic hash of the message identifier (used for deduplication);
  • A token count; and
  • The integer sentiment score (1–10).

Employee / monitored-individual records and attributes

Customers register the individuals they monitor ("employees" or "monitored individuals") together with arbitrary attributes such as display name, email address, role, department, and branch or location. Customers may optionally enable additional demographic or special-category attributes — for example age, gender, religion, or ethnicity — to aggregate sentiment across those dimensions.

Demographic and special-category attributes are turned OFF by default and must be deliberately enabled by the Customer per organization. Where such data is special-category data under GDPR Article 9 or comparable laws, it is the Customer's sole responsibility to ensure a valid legal basis, to obtain any required explicit consent, and to provide any required notice. B2 Group processes these attributes only as a processor on the Customer's instructions and does not determine whether their collection is lawful.

5.How Email Bodies Are Scored

To compute the 1–10 sentiment score for a message, the message body is transmitted to a third-party AI provider selected by the Customer organization. The body is sent to that provider only transiently, for the sole purpose of computing the score, and is not persisted by us. Once a score is returned, we retain only the metadata and score described in this Policy.

Selecting an AI provider

Each Customer organization selects one AI provider — Anthropic (Claude), OpenAI, or Google (Gemini) — to score its email bodies. The selected provider receives email bodies transiently for scoring and acts under its own terms and privacy practices.

API keys and bring-your-own-key (BYOK)

By default, scoring with the selected provider uses platform-held API credentials maintained by B2 Group. A Customer may instead choose to bring its own API key (BYOK) for the selected provider, in which case the processing by that provider occurs under the Customer's own account and arrangements with that provider. Whether platform keys or a Customer's own key is used, we persist only the metadata and score and do not store the email body.

6.What We Do NOT Store

We designed SentiTrack to minimize the personal data we retain. We do NOT store:

  • The body or content of any email;
  • The plaintext subject line of any email (we keep only a one-way hash); or
  • Any attachments.

Email bodies are transmitted to the Customer-selected third-party AI provider (Anthropic, OpenAI, or Google) only transiently, for the sole purpose of computing the 1–10 sentiment score, and are not persisted by us. Once a score is returned, we retain only the metadata and score described above.

7.Sub-Processors and Third Parties

We rely on the following categories of third parties to provide the Service. Where they process Customer Data, they act as our sub-processors under the Customer's instructions; each operates under its own privacy practices.

AI sentiment providers

Each Customer organization selects one of Anthropic (Claude), OpenAI, or Google (Gemini) to score its email bodies. The selected provider receives email bodies transiently for scoring and acts under its own terms and is responsible for its own compliance. Where the Customer brings its own API key (BYOK), the processing occurs under the Customer's own account and arrangements with that provider.

Payment processing

Stripe, Inc. processes payments and manages subscription billing on our behalf.

Hosting and infrastructure

The Service is hosted on infrastructure operated by B2 Group on its own Linux server (managed via aaPanel), with data stored in a MariaDB database.

Optional connected integrations

A Customer may choose to enable optional integrations, such as Microsoft 365, Google Workspace, RingCentral, Microsoft Teams, Slack, or Zoom. Data shared through those integrations is governed by the third party's own terms and privacy practices, and enabling them is the Customer's decision.

We may engage additional or replacement sub-processors as the Service evolves. Where we engage sub-processors that process Customer Data, we impose data-protection obligations substantially consistent with those applicable to us. Details of our current sub-processors and any change-notification commitments are set out in our data processing agreement, which governs in the event of any conflict with this Policy. We do not sell personal data to any of these parties.

8.Purposes and Legal Bases for Processing

We process personal data for the purposes set out below. Where the GDPR or UK-GDPR applies and we act as a controller (Context A), the corresponding legal bases under Article 6 are indicated.

  • Providing and administering accounts, authenticating users, and operating the Service — performance of a contract (Art. 6(1)(b)).
  • Processing payments, billing, and managing subscriptions through Stripe — performance of a contract (Art. 6(1)(b)) and compliance with legal obligations such as tax and accounting (Art. 6(1)(c)).
  • Responding to support, sales, legal, and privacy enquiries — legitimate interests in operating and supporting our business (Art. 6(1)(f)) and, where relevant, performance of a contract (Art. 6(1)(b)).
  • Operating, securing, maintaining, and improving our website and the Service, including fraud prevention and abuse detection — legitimate interests (Art. 6(1)(f)).
  • Using cookies and similar technologies — where strictly necessary, on the basis of our legitimate interests and/or the strictly-necessary exemption under applicable e-privacy rules; otherwise, on the basis of your consent (Art. 6(1)(a)) where required. See our Cookie Policy.
  • Complying with our legal obligations and establishing, exercising, or defending legal claims — compliance with legal obligations (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)).

For Customer Data we process as a processor (Context B), the legal basis is determined by the Customer as controller, and we process it only on the Customer's documented instructions. Where any monitored data constitutes special-category data under GDPR Article 9 (such as data revealing religion, ethnicity, or other sensitive attributes), the Article 9 condition — including any required explicit consent — and any required DPIA and notice are the responsibility of the Customer, not B2 Group.

9.Data Retention and Deletion

For Customer Data processed in Context B, retention is configurable by the Customer on a per-organization basis, with a default retention period of 365 days. After the configured period, records are eligible for deletion.

We provide a hard-delete capability so that a Customer can request deletion of its Customer Data. Following termination of the Customer's subscription, we will, on the Customer's documented instruction, delete or return Customer Data, and absent such instruction we may delete it after a commercially reasonable wind-down period. Customer Data may persist in routine, rolling backups for a limited period until those backups are overwritten in the ordinary course, and we may retain data where required by applicable law or for the establishment, exercise, or defense of legal claims.

Monitored individuals who wish to have their data deleted should generally direct that request to the Customer (their employer), who controls the data; we will assist the Customer in giving effect to such requests as required by law and our agreement with the Customer.

For data we hold as a controller (Context A), we retain account and related data for as long as your account is active and thereafter as needed to comply with legal, tax, accounting, and dispute-resolution obligations, after which it is deleted or anonymized.

10.Security

We implement technical and organizational measures designed to protect personal data appropriate to the nature of the data and the risks involved, including:

  • Storing passwords only as salted bcrypt hashes;
  • Storing only one-way hashes of email subjects and message identifiers, and never storing email bodies, plaintext subjects, or attachments;
  • Transmitting email bodies to the Customer-selected AI provider only transiently for scoring, and not persisting them;
  • Encrypting sensitive secrets and API keys at rest (Fernet symmetric encryption for stored keys);
  • Encrypting data in transit using TLS;
  • Enforcing tenant isolation so that each query is scoped to the authenticated organization; and
  • Applying access controls that limit access to personal data to those who need it to operate and support the Service.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim any third-party certification or attestation (such as HIPAA, SOC 2, or ISO certification) that we do not in fact hold. You and our Customers are responsible for safeguarding account credentials and for the security of your own systems and mail-flow configuration.

The measures described in this section are provided for transparency and are not warranties or guarantees; the Service is provided "as is" and our liability is limited as set out in our Terms of Service.

11.International Data Transfers

B2 Group is based in the United States, and our hosting and processing infrastructure is located in the United States. If you or our Customers are located outside the United States, personal data — including Customer Data — will be transferred to and processed in the United States, which may have data-protection laws that differ from those in your country.

To compute sentiment scores, email bodies are transmitted to the Customer-selected third-party AI provider (Anthropic, OpenAI, or Google), which may process them in accordance with its own infrastructure and policies, including in jurisdictions outside your own. The selected AI provider acts under its own terms and is responsible for its own transfer compliance; where the Customer uses its own API key (BYOK), all processing by that provider occurs under the Customer's own arrangements and we are not responsible for it.

Where required for transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism. Customers outside the United States acknowledge and accept that their use of the Service involves processing in the United States and use the Service at their own risk.

12.Your Privacy Rights (GDPR / UK-GDPR)

The rights described below apply only to the extent required by, and are subject to the conditions, exceptions, and identity-verification requirements of, applicable law, and only to personal data for which we act as controller (Context A). If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have the following rights with respect to your personal data:

  • The right to access your personal data and obtain a copy;
  • The right to rectification of inaccurate or incomplete data;
  • The right to erasure ("right to be forgotten") in certain circumstances;
  • The right to restrict or object to processing in certain circumstances;
  • The right to data portability;
  • The right to withdraw consent at any time where processing is based on consent, without affecting prior processing; and
  • The right to lodge a complaint with your local supervisory authority.

Where we act as a controller (Context A), you may exercise these rights by contacting us at [email protected]. We may need to verify your identity before acting on a request.

For Customer Data we process as a processor (Context B), the Customer is the controller and we have no independent authority to grant access, deletion, correction, or portability. We will neither act on nor be obligated to act on such requests except on the documented instruction of the controlling Customer. If you are a monitored individual, you should direct your request to your employer (the Customer), who is responsible for responding; if you contact us directly about such data, we will refer you to the relevant Customer and will assist that Customer in responding as required by law and our agreement with them.

13.Your California Privacy Rights (CCPA / CPRA)

The rights described below apply only to the extent required by, and are subject to the exceptions, conditions, and verification requirements of, applicable law, and only to personal information for which we act as a business (Context A). If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), provides you with certain rights regarding your personal information.

Categories of personal information we collect

As a business in Context A, we collect the following statutory categories: identifiers (such as name and email); commercial information (such as subscription and billing records via Stripe); internet or other electronic network activity (such as website and device/cookie data); and, depending on your interactions, professional or employment-related information and the contents of your communications with us. Sensitive personal information is not required to use our website or account.

We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

Your California rights

  • The right to know what personal information we collect, use, and disclose;
  • The right to delete personal information we have collected, subject to exceptions;
  • The right to correct inaccurate personal information;
  • The right to opt out of the sale or sharing of personal information (we do not engage in either); and
  • The right not to receive discriminatory treatment for exercising your rights.

To exercise these rights with respect to data we control, contact us at [email protected]. We will verify your request and may use an authorized agent process where applicable.

For Customer Data we process as a service provider on a Customer's behalf (Context B), we process that information only for the business purposes specified by the Customer and as permitted by the CCPA/CPRA for service providers. We do not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by law, and we have no independent authority to grant access, deletion, correction, or portability with respect to it. We will neither act on nor be obligated to act on such requests except on the documented instruction of the controlling Customer. If you are a monitored individual, please direct your requests to the relevant Customer (your employer), and we will assist the Customer as required.

14.Children's Privacy

The Service is a business tool intended solely for use by Customers and their authorized adult personnel and is not directed to or intended for individuals under 18. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, please contact [email protected] and we will delete it as required by law.

15.Cookies and Similar Technologies

We use cookies and similar technologies on our website for purposes such as keeping you signed in (including by storing access and refresh tokens in your browser's local storage), remembering preferences, and understanding how the website is used. For details about the cookies and similar technologies we use and the choices available to you, please see our Cookie Policy.

16.Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we do, we will revise the "Last updated" date and version string at the top of this Policy and, for material changes, we may provide additional notice (for example, by email to account administrators or a notice within the Service or on our website). Material changes will be governed by the notice and acceptance mechanism in our Terms of Service.

Changes are effective prospectively only and do not retroactively alter how we treated personal data before the update. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy to the extent permitted by applicable law; where applicable law requires affirmative consent for a change, we will obtain it.

The current version is 2026-06-05, effective June 5, 2026.

© 2026 B2 Group LLC · 1309 Coffeen Ave, Sheridan, WY 82801, USA · Operator of SentiTrack.ai