Privacy Policy

Last updated: 18 September 2026

NORG (norg.ai) runs Content-Craft: you give us your website, we crawl it, and we publish an AI-readable copy of it so AI assistants can find and cite your business. This policy explains what data that involves, who else sees it, how long we keep it and how to get it deleted.

Section 3 covers the crawling and publishing, because that is the part most worth understanding before you sign up.

1. What data we collect

We keep collection deliberately small. This is everything we hold.

Identity, from signing in

  • Your email address and a subject identifier (a stable, unique user ID issued by our identity service), received when you sign in or grant OAuth consent to a NORG connector.

Details you give us

  • Your business name.
  • Your public website or homepage URL — the site you ask us to crawl and mirror (see section 3).

Billing

  • A Stripe customer ID and a Stripe subscription ID. That is all the billing data we store.
  • Card and payment-instrument details are collected and stored by Stripe, Inc. directly. They never pass through NORG's systems and we never see or store them.

Operational records, generated automatically

  • Authentication and access logs — sign-in events, API and connector requests, timestamps, IP address and user agent.
  • Crawl and publish logs — which pages of your site we fetched, when, and what we published as a result.
  • Cookies used to keep you signed in (see section 9 for the detail).

What we do not collect

  • Card numbers or any other payment-instrument data.
  • The content of your conversations with Claude or any other AI assistant. When an assistant reads your published mirror it reads public pages; we do not receive the conversation around that request.

2. How we use your data

  • Email and subject identifier — to create and secure your account, sign you in, connect an AI assistant to your workspace on your behalf, send service messages about your account, your builds and your billing, and send a one-time transactional welcome email after the connector's first successful authentication.
  • Business name and website URL — to run the crawl you asked for and to build and publish your AI-readable mirror.
  • Stripe customer and subscription IDs — to start, change and cancel your subscription, and to match your account to a payment made in Stripe.
  • Authentication and access logs — to detect and investigate abuse, unauthorised access and outages, and to keep an audit trail of who did what in your workspace.
  • Crawl and publish logs — to show you what was published, to diagnose a failed or partial build, and to avoid re-fetching pages of your site unnecessarily.

We do not sell your personal data, and we do not share it with advertisers or data brokers. The only third parties that receive any of it are the service providers listed in section 4.

3. Crawling your website and publishing a public mirror

This is the core of what NORG does, so please read this section carefully. When you give us your website address, we crawl that site and publish a copy of its content, reorganised so AI assistants can read and cite it. That copy is served publicly on the internet.

What we fetch

  • Pages on the domain you nominate that are already publicly reachable — the HTML, its text, headings, links, structured data and images.
  • We do not sign in to your site, submit forms, or fetch anything behind a login, paywall or members area.
  • We crawl only the domain you give us. If your public pages contain personal data (staff names, customer testimonials, contact details), that data is in what we fetch — so please check what is on your site before you point us at it.

Where it is stored

  • The crawled source content and the generated pages are stored in our databases on Microsoft Azure (Australia East).
  • The published files are stored in Cloudflare R2 object storage and served from Cloudflare's global edge network.

That it is published publicly

The mirror is public. It has no login and is intended to be fetched by AI assistants, agents and crawlers, which may quote or summarise it to their users. Depending on the setup you choose, it is served either from a NORG-operated address or from your own domain through a small Cloudflare Worker you install. Search engines and other bots can reach it too. We do this only because you asked us to, and only for the website you nominated.

Whose Cloudflare account it runs in

  • NORG-hosted (the default): the mirror is published from NORG's own Cloudflare account, at a NORG-operated address. You need no Cloudflare account and nothing runs on your side.
  • Self-hosted: a small Cloudflare Worker runs in your own Cloudflare account, on your own domain. For each request it sends NORG three things — your site identifier, the classified visitor type (which AI bot, or “human”), and the path requested — so NORG knows what to render next and can report visit analytics to you. The worker never sends NORG the page content of your own site.
  • The worker's request logs stay in your Cloudflare account; NORG does not receive them.
  • If you give NORG a Cloudflare API token to install the worker for you, it is stored encrypted, used only to deploy, update or remove the worker on your zone, and you can revoke it in Cloudflare at any time.

How often we re-crawl

  • We crawl when you first connect a site, and again whenever you ask us to rebuild or republish it.
  • We also re-crawl periodically to keep the mirror current — currently around every 30 days.
  • Removing or changing a page on your own site does not remove it from the mirror until the next crawl. Ask us at privacy@norg.ai if you need something taken down sooner.

What happens when you cancel

  • We stop crawling your site as soon as your subscription ends.
  • We take the published mirror down within 30 days of cancellation, so it stops being served from Cloudflare and stops being reachable by AI assistants and crawlers.
  • We cannot remove copies that third parties already made — for example pages another crawler cached, or content an assistant has already used in an answer.

4. Sub-processors

We use a small number of service providers to run NORG. Each one receives only what it needs for the job listed below.

ProviderWhat it receivesWhy
Stripe, Inc.Your email address and billing details you enter on Stripe’s own checkout, plus your Stripe customer and subscription IDs.Payment processing and subscription billing. Stripe collects and stores card details directly — NORG never receives them.
Cloudflare, Inc.The published mirror of your website, and the request metadata (IP address, user agent) of anyone who fetches it.Content hosting in R2 object storage and delivery of the published mirror from Cloudflare’s global edge network — from NORG’s Cloudflare account or, if you self-host, your own Cloudflare account.
Microsoft AzureAll application data at rest and in processing: account records, crawled content, generated pages, and operational logs.Application infrastructure, databases and background workers that run the platform.

Our own identity service

Sign-in and OAuth consent run on Keycloak, an open-source identity product that NORG hosts on its own infrastructure. It holds your email address, your subject identifier and your sign-in sessions. Because we run it ourselves, no separate company receives that data — it stays inside the NORG systems described in this policy.

5. How long we keep data

  • Account data (email, subject identifier, business name, website URL) — kept while your account is open. We delete it within 30 days of you closing your account or asking us to delete it.
  • Crawled content and the published mirror — kept while your subscription is active so we can serve and refresh it. Taken down and deleted within 30 days of cancellation or a deletion request.
  • Authentication and access logs — kept for 90 days, then deleted.
  • Crawl and publish logs — kept for 12 months so we can show you the history of a site and investigate a bad build.
  • Billing records (Stripe customer and subscription IDs, invoices) — kept for about 7 years after your last payment, because tax and audit rules require us to keep records of what we charged. Deleting your account does not delete these.

Deleted data can survive for a short time in encrypted backups until those backups rotate out of storage. It is not restored to the live service or used for anything in the meantime.

6. Deletion and your rights

You can ask us to do any of the following, at any time, whether or not you are still a customer:

  • Access — get a copy of the personal data we hold about you.
  • Correction — fix anything that is wrong or out of date. Most of it you can edit yourself in your account settings.
  • Erasure — delete your account and your data. This includes taking your published mirror offline. We keep only the billing records described in section 5, which we are required to retain.
  • Take a page down — remove a specific page from the published mirror without deleting your whole account.
  • Object or complain — tell us you disagree with how we are handling your data.

Email privacy@norg.ai from the address on your account and tell us what you want. We acknowledge requests within 5 business days and complete them within 30 days. If a request will take longer than that, we will tell you why and give you a date.

We may need to confirm who you are before acting on a request, so that nobody else can delete or download your data.

7. AI and model training

We do not use your personal data to train AI or machine-learning models. We do not use your crawled website content or your published mirror to train AI or machine-learning models, and we do not sell or licence either for anyone else to train on.

We do use AI models to build your pages — that is the product. Your content is sent to a model to generate the mirror, and it is used to produce your output only.

Your published mirror is public, so AI assistants and crawlers can read it, and what those third parties do with public web pages is governed by their own policies, not ours.

8. Where your data goes

  • Our primary infrastructure — databases, application servers and background workers — runs on Microsoft Azure in the Australia East region.
  • Your published mirror is served from Cloudflare's global edge network, so copies of that public content are cached on servers around the world to make it fast to fetch.
  • Stripe processes payments on its own international infrastructure.

This means your data may be processed outside the country you are in. We rely on appropriate contractual and technical safeguards with our providers when data moves across borders, and we choose established providers that offer them.

9. Cookies and tracking

  • Session cookies — set when you sign in, so you stay signed in as you move around the app. Cleared when you sign out.
  • Security cookies — short-lived values used during sign-in and OAuth consent to tie a login attempt to your browser and block request forgery.
  • Preference cookies — remember choices such as which workspace you last had open.

We do not use cookies for advertising, and we do not use them to track you across other websites. Blocking our cookies in your browser will stop you from signing in.

Your published mirror is served as plain pages by Cloudflare. Requests to it are logged (IP address, user agent, page requested) for security and for the delivery statistics we show you.

10. How we protect your data

  • Traffic to the app, our API and your published mirror is encrypted in transit with HTTPS.
  • Data at rest sits in managed Azure database storage and Cloudflare R2, both of which encrypt stored data.
  • Sign-in runs through our identity service, with individual accounts and scoped access tokens rather than shared credentials.
  • Access to production systems and customer data is limited to the staff who need it, and administrative access is logged.
  • API keys and other secrets are held in managed secret storage, never in our source code.

No system is perfectly secure. If we become aware of a breach that affects your data, we will tell you and take the steps the law requires.

11. Children's data

NORG is a business product. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email privacy@norg.ai and we will delete it.

12. Changes to this policy

We update this policy when what we do changes — for example if we add a sub-processor, change a retention period, or change how the published mirror works. When we do, we update the date on this page.

If a change materially affects your rights or how we handle your data, we will email the address on your account before it takes effect.

This version was published on 18 September 2026.

13. Contact us

NORG operates this service and is responsible for the personal data described in this policy.

For privacy questions, data access requests, corrections, deletion requests or complaints, email privacy@norg.ai. For anything else — billing, your account or how the product works — email solutions@norg.ai.