Privacy
How we handle your data.
Effective April 2, 2026 · Updated September 5, 2026
1. Who We Are
CallSherpa is a call-for-proposals management platform operated from Canada. This policy applies to all users: organizers who create calls, applicants who submit proposals, and reviewers who score submissions.
2. Data We Collect
Account data (all users)
- Name and email address (collected via Clerk authentication)
- Optional profile fields: phone, company, role, location, website
Organizer data
- Call details you create (title, description, form fields, rubric)
- An optional OpenRouter API key you add to a specific call, and a SourceVerify key (both stored encrypted with AES-256-GCM)
- Polar payment information (processed directly by Polar; we store order identifiers only)
Applicant data
- Proposal responses (text, file uploads) for each call you apply to
- Application status and submission timestamps
- References you provide (may be submitted to SourceVerify for verification — see Section 4)
Reviewer data
- Review scores, comments, and recommendations you submit
- Assignment and completion timestamps
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Operating the platform (authentication, saving drafts, submitting proposals) | Contractual necessity |
| Enabling organizers to manage their review process | Contractual necessity |
| Sending transactional emails (invite links, assignment notifications, decision notifications) | Contractual necessity |
| AI-assisted call creation (processing pasted documents) | Consent (organizer action) |
| AI-assisted review (processing proposal text for reviewer chat) | Consent (disclosed at time of use) |
| AI-drafted decision emails (processing proposal data and reviewer comments) | Legitimate interest |
| Reference verification via SourceVerify | Consent (checkbox on application form) |
| Billing and subscription management | Contractual necessity |
4. Third-Party Data Processors
The processors listed below are based in the United States, except that OpenRouter may route an AI request to a model provider located outside the United States (see Section 5). Data transferred outside Canada is subject to the law of the receiving country. Canadian users are advised that this constitutes a cross-border transfer under PIPEDA Schedule 1, Principle 7.
| Processor | Purpose | Data Transferred |
|---|---|---|
| Clerk | Authentication | Name, email, password credentials |
| Convex | Database and file storage | All application data, proposals, reviews, files |
| Polar | Payment processing | Payment card data, billing address |
| OpenRouter | AI model inference (routing to the models listed in Section 5) | Proposal text, reviewer comments, and call content (when AI features are used) |
| Resend | Transactional email | Recipient email addresses, email content |
| SourceVerify | Reference verification | Reference citation text only (when enabled by organizer) |
| Cloudflare R2 | File storage | Uploaded proposal files, PDFs, attachments, and call banner images |
SourceVerify only receives individual reference citation strings — never the full proposal text. Full proposal content is only sent to OpenRouter when AI features are actively used. CallSherpa does not currently operate any voice or speech-synthesis feature, so no audio is collected, transmitted, or stored.
5. AI Models and Data Retention
All AI features run through OpenRouter, which routes each request to the model provider named below. CallSherpa chooses the model; you cannot be routed to a model that is not on this list.
No data retention
CallSherpa sets provider.data_collection: "deny" on every OpenRouter request that supports it. OpenRouter honours this by routing only to provider endpoints that do not log or train on the inputs they receive, and by refusing the request rather than falling back to an endpoint that would. This applies on every plan, including when an organizer supplies their own OpenRouter key.
Requests to the decision model (typesafe/jev-1.13, below) — the routing decision behind reviewer chat, and the screening-criteria check — are sent to a different OpenRouter endpoint that accepts no provider field. They are covered instead by the same guarantee at the account level — data retention is disabled on the CallSherpa OpenRouter account, which applies to every request we send, whether or not the individual request can carry the flag.
Models in use
| Model | Used for |
|---|---|
openai/gpt-5.4-nano | Reviewer chat, call control center, navigation, data questions, deliberation, setup wizard |
typesafe/jev-1.13 | Routes each reviewer chat turn to the right response, and checks whether the application form asks what each screening criterion needs, reading the form's questions, never an applicant's answers — it decides, it does not write any text you see |
openai/gpt-5-nano | Decision-letter replies and drafted email sections |
openai/gpt-5-mini | Extracting call details from a pasted PDF or document |
z-ai/glm-5.3-flash | AI eligibility pre-screening, call translation, and the organizer's daily memo |
This list is kept in step with the code that calls the models — a model cannot be added to the platform without being published here. For what each model is and is not allowed to do, see our Responsible AI page.
6. No Selling or Sharing
We do not sell, rent, or share your personal data with third parties for their own marketing or commercial purposes. Your data is only shared with the third-party processors listed above, solely to operate the platform and provide the services you use. We do not use your proposal content, review comments, or any other user data to train AI models.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account data | Until account deletion |
| Submitted proposals | 3 years after the associated call closes |
| Draft applications (never submitted) | 90 days after last update |
| Review scores and comments | 3 years after the associated call closes |
| Reviewer invites | 1 year after creation |
| Reference verification results | 1 year after completion |
| Polar order records | 7 years (tax records) |
8. Your Rights
Under PIPEDA (and where applicable, GDPR), you have the right to:
- Access: Request a copy of your personal data. Contact privacy@callsherpa.ai.
- Correction: Update incorrect data via your Profile page.
- Erasure: Delete your account via Profile > Delete Account. This removes your account, all proposals you submitted, uploaded files, reviews you wrote, and any calls you own.
- Portability: Request an export of your submitted proposals and review history.
- Withdrawal of consent: Where processing is based on consent (AI features, reference verification), you may withdraw consent by not using those features or by contacting us.
- Complaint: You may lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
9. Applicant-Specific Rights
Your submitted proposal is shared with the organizer of the call and any reviewers the organizer assigns. If the organizer enables blind review, reviewers will not see your name or identity fields, but they will see your proposal content.
If the organizer uses AI features, your proposal content may be processed by AI services (see Section 4). If you consent to reference verification, the reference citations you provide will be submitted to SourceVerify. Your full proposal is never sent to SourceVerify.
10. Security
Account passwords and social sign-in are managed by Clerk. API keys are encrypted at rest using AES-256-GCM with a per-deployment derived key. Files are stored in Convex managed file storage with access-controlled URLs. All editor, reviewer, and applicant operations are protected by role-based authorization checks.
11. Cookies
CallSherpa uses only essential cookies required for the platform to function. We do not use analytics, advertising, or tracking cookies.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| __session | Clerk | Authentication session | Session |
| __client_uat | Clerk | Session freshness check | Session |
| callsherpa-cookies | CallSherpa | Records cookie consent | 1 year |
Because these cookies are strictly necessary for the platform to operate, they do not require opt-in consent under PIPEDA or GDPR. You can disable cookies in your browser settings, but this may prevent you from signing in.
12. Changes to This Policy
We will notify users of material changes by email or by posting a notice on the platform. Continued use after the effective date constitutes acceptance.
Beta data collection
While CallSherpa is in public beta, we record the contents of chats between users and Sherpa (the user's message, Sherpa's reply, the AI model used, and token counts). We use these records only to understand what our users find most useful and to improve the product. Records are not sold, shared with third parties, or used to train external models. Each record is automatically deleted 60 days after it is created. To request earlier deletion of your records, email privacy@callsherpa.ai.
13. Contact
Privacy inquiries: privacy@callsherpa.ai