Privacy Policy

Effective Date: January 6, 2026

Last Updated: July 27, 2026

Welcome to Be-Inc. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Microsoft applications — the Word Add-in, the Outlook Add-in, and the Teams Bot — and the Be-Inc Analytics Dashboard. By using our Services, you consent to the practices described in this Privacy Policy.

IMPORTANT: Our Services use AI — primarily Mistral AI — to analyze your content for diversity, equity, and inclusion (DE&I) compliance. Your content is sent to our servers and to our AI provider for processing. Please review this Privacy Policy carefully to understand how your data is handled.

1How Each App Handles Your Data

1.1 Word Add-in

  • What is analyzed: Document text you analyze manually or via auto-detection is sent to our AI provider for DE&I analysis
  • What is stored: Flagged terms, their category, explanation, suggested alternatives, and your action (accepted/ignored) are stored in your Be-Inc account to power the History tab and your personal analytics
  • What is NOT stored: Your full document is never stored on our servers — it is discarded immediately after analysis
  • Settings: Preferences (sensitivity, tone, auto-correction) are saved in your Office.js roaming settings

1.2 Outlook Add-in

  • What is analyzed: Email body and subject line text when you request DE&I analysis while composing
  • What is stored: Flagged terms, categories, suggested alternatives, and your actions are stored in your Be-Inc account (same as the Word Add-in)
  • What is NOT stored: Full email content, recipients, attachments, and metadata are never stored

1.3 Teams Bot (Privacy-First Design)

The Teams Bot is designed with privacy as a core principle:

  • Full messages are immediately discarded after AI analysis
  • Only flagged words, categories, and a 3–5 word context snippet are stored
  • User identities are hashed with SHA-256 (one-way, irreversible)
  • No message content is ever written to logs or stored in any database
  • Messages from users not registered with Be-Inc are silently ignored and never processed

1.4 Analytics Dashboard

  • Account information: Your email and name when you sign up for the dashboard
  • Aggregate reporting: DE&I compliance trends built only from flagged terms recorded by the three apps above — never from full documents, emails, or messages

2Information We Collect

2.1 Settings and Preferences

  • Add-in Settings: Your preferences for sensitivity levels, auto-correction, tone, and send validation
  • Correction History: Record of corrections you've accepted or applied

2.2 Technical Information

  • Office Context: Office.js provides us with your user ID and session information
  • Browser Information: Browser type, version, and user agent (collected automatically)
  • Error Logs: Technical error messages if the services encounter issues

2.3 Information We Do NOT Collect

We do NOT collect or store:

  • Full email or document content (beyond what is sent to AI for analysis)
  • Full Teams messages (discarded immediately after analysis)
  • Email recipients, attachments, or metadata
  • Biometric data or health information
  • Location data

3How We Use Your Information

3.1 AI-Powered Analysis

Your content is sent to our AI provider — primarily Mistral AI — for the following purposes:

  • DE&I Compliance Analysis: Identifying potentially problematic language (gendered terms, ableist language, cultural insensitivity)
  • Suggested Alternatives: Generating inclusive language alternatives
  • Compliance Reporting: Aggregating flagged words (not messages) for organizational DE&I analytics

3.2 Analytics Dashboard

  • Aggregate Reporting: DE&I compliance trends across teams and channels (using only flagged words, not messages)
  • User Authentication: Securely managing dashboard access via Supabase authentication

3.3 Caching and Performance

  • LRU Cache: Temporarily caching AI analysis results in-memory to improve performance and reduce API costs
  • Content Hashing: Hashing document content to detect changes (hash only, not content)

4Data Sharing and Third-Party Services

4.1 Mistral AI (Primary AI Provider)

Your content is sent to Mistral AI for AI-powered analysis.

  • Data Sent: Text content you analyze (Word, Outlook) or message content under analysis (Teams — discarded after processing)
  • Model Training: Mistral AI does NOT use API data to train its models
  • Data Residency: Mistral AI is a European (EU-based) provider; API content is processed under its data processing terms
  • Mistral Privacy Policy: mistral.ai/terms

4.2 Microsoft Azure OpenAI (Optional / Fallback)

In the Outlook Add-in you may optionally select Microsoft Azure OpenAI as the analysis provider, and it may serve as a fallback path. When used, content is processed on Microsoft Azure infrastructure; Microsoft does NOT use your data to train AI models.

4.3 Supabase (Database)

  • What is stored: Flagged DE&I terms, categories, suggested alternatives, hashed user IDs (Teams), team/channel names, timestamps, and your correction actions
  • What is NOT stored: Full messages, email content, document content
  • Authentication: User accounts for dashboard access (email, hashed password)

4.4 Microsoft Office.js and Microsoft Graph

  • Roaming Settings: Your preferences sync across your Microsoft 365 account
  • Microsoft Graph API: Used by the Teams Bot to resolve sender email addresses for registration checks

4.5 No Other Third-Party Sharing

We do NOT share your data with advertisers, analytics services, social media platforms, or data brokers.

5Data Storage and Retention

5.1 Where Your Data is Stored

  • Mistral AI: Content processed for analysis (not retained after analysis; not used for training)
  • Supabase Cloud: Flagged DE&I terms, correction history, and dashboard user accounts
  • Office.js Roaming Settings: Add-in settings stored in Microsoft's cloud
  • Browser Memory: AI analysis results cached temporarily in the browser

5.2 Retention Periods

  • AI-analyzed content: Deleted immediately after analysis
  • Flagged DE&I terms: Retained for compliance reporting until deletion is requested
  • Add-in settings: Retained until you uninstall the add-in
  • Dashboard accounts: Retained until you request deletion
  • Cache: Cleared when you close the Office application

6Data Security

  • HTTPS Encryption: All communication uses HTTPS/TLS encryption
  • Password Hashing: Dashboard passwords are hashed with bcrypt (12 rounds)
  • User ID Hashing: Teams user identities are SHA-256 hashed (irreversible)
  • XSS Protection: React's safe rendering prevents cross-site scripting attacks
  • Server-to-server auth: Bot-to-Dashboard communication uses secret-based authentication
  • Row-Level Security: Supabase database uses RLS policies for data isolation
  • Prompt-injection guardrails: Analysis requests pass a moderation pre-check before any AI call

7Your Rights and Choices

7.1 Access and Deletion

  • View Settings: Access your settings via the Settings tab in any add-in
  • Clear History: Delete correction history via the History tab
  • Delete Account: Contact us to delete your dashboard account and all associated data
  • Request Data Deletion: Contact support@be-inc.ai

7.2 Opt-Out of AI Analysis

  • Word/Outlook: Turn off auto-detection in Settings, or uninstall the add-in to stop all data collection
  • Teams: Uninstall the bot from your team to stop message monitoring

7.3 GDPR and CCPA Rights

If you are in the EU or California, you have rights to access, delete, rectify, and port your data. Contact support@be-inc.ai to exercise these rights.

8Children's Privacy

Our Services are NOT intended for children under 13 years old. We do not knowingly collect personal information from children.

9Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be effective when posted. Your continued use constitutes acceptance of the updated Privacy Policy.

10Contact Us

If you have questions about this Privacy Policy, please contact us:

Email: support@be-inc.ai

Website: https://be-inc.ai

© 2026 Be-Inc. All rights reserved.

Privacy Policy - Be-Inc