Last updated: 18 September 2026
NORG (norg.ai) runs Content-Craft: you give us your website, we crawl it, and we publish an AI-readable copy of it so AI assistants can find and cite your business. This policy explains what data that involves, who else sees it, how long we keep it and how to get it deleted.
Section 3 covers the crawling and publishing, because that is the part most worth understanding before you sign up.
We keep collection deliberately small. This is everything we hold.
We do not sell your personal data, and we do not share it with advertisers or data brokers. The only third parties that receive any of it are the service providers listed in section 4.
This is the core of what NORG does, so please read this section carefully. When you give us your website address, we crawl that site and publish a copy of its content, reorganised so AI assistants can read and cite it. That copy is served publicly on the internet.
The mirror is public. It has no login and is intended to be fetched by AI assistants, agents and crawlers, which may quote or summarise it to their users. Depending on the setup you choose, it is served either from a NORG-operated address or from your own domain through a small Cloudflare Worker you install. Search engines and other bots can reach it too. We do this only because you asked us to, and only for the website you nominated.
We use a small number of service providers to run NORG. Each one receives only what it needs for the job listed below.
| Provider | What it receives | Why |
|---|---|---|
| Stripe, Inc. | Your email address and billing details you enter on Stripe’s own checkout, plus your Stripe customer and subscription IDs. | Payment processing and subscription billing. Stripe collects and stores card details directly — NORG never receives them. |
| Cloudflare, Inc. | The published mirror of your website, and the request metadata (IP address, user agent) of anyone who fetches it. | Content hosting in R2 object storage and delivery of the published mirror from Cloudflare’s global edge network — from NORG’s Cloudflare account or, if you self-host, your own Cloudflare account. |
| Microsoft Azure | All application data at rest and in processing: account records, crawled content, generated pages, and operational logs. | Application infrastructure, databases and background workers that run the platform. |
Sign-in and OAuth consent run on Keycloak, an open-source identity product that NORG hosts on its own infrastructure. It holds your email address, your subject identifier and your sign-in sessions. Because we run it ourselves, no separate company receives that data — it stays inside the NORG systems described in this policy.
Deleted data can survive for a short time in encrypted backups until those backups rotate out of storage. It is not restored to the live service or used for anything in the meantime.
You can ask us to do any of the following, at any time, whether or not you are still a customer:
Email privacy@norg.ai from the address on your account and tell us what you want. We acknowledge requests within 5 business days and complete them within 30 days. If a request will take longer than that, we will tell you why and give you a date.
We may need to confirm who you are before acting on a request, so that nobody else can delete or download your data.
We do not use your personal data to train AI or machine-learning models. We do not use your crawled website content or your published mirror to train AI or machine-learning models, and we do not sell or licence either for anyone else to train on.
We do use AI models to build your pages — that is the product. Your content is sent to a model to generate the mirror, and it is used to produce your output only.
Your published mirror is public, so AI assistants and crawlers can read it, and what those third parties do with public web pages is governed by their own policies, not ours.
This means your data may be processed outside the country you are in. We rely on appropriate contractual and technical safeguards with our providers when data moves across borders, and we choose established providers that offer them.
No system is perfectly secure. If we become aware of a breach that affects your data, we will tell you and take the steps the law requires.
NORG is a business product. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email privacy@norg.ai and we will delete it.
We update this policy when what we do changes — for example if we add a sub-processor, change a retention period, or change how the published mirror works. When we do, we update the date on this page.
If a change materially affects your rights or how we handle your data, we will email the address on your account before it takes effect.
This version was published on 18 September 2026.
NORG operates this service and is responsible for the personal data described in this policy.
For privacy questions, data access requests, corrections, deletion requests or complaints, email privacy@norg.ai. For anything else — billing, your account or how the product works — email solutions@norg.ai.