Legal

Privacy Notice

Last updated: July 15, 2026. This notice explains how personal data is handled when you visit or use Norami.

Who is responsible for your data

Norami is operated by AI BLU, LLC, a Delaware limited liability company with a mailing address at 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States.

AI BLU, LLC is the data controller for account registration, service administration, billing, security, fraud prevention, support, and its own business records. For personal data contained in files, datasets, prompts, and other content submitted to a customer workspace, the customer normally decides why and how that data is used and is the controller. AI BLU, LLC processes that workspace data on the customer's behalf as its processor.

Who may use Norami

Norami is for people aged 18 or older acting for a business or professional purpose, including self-service users purchasing for a business. It is not offered for personal, family, or household use.

Unless AI BLU, LLC approves it in writing beforehand, customers must not use Norami to process special-category or similarly sensitive personal data, including health, biometric, genetic, religious, political, trade-union, sexual-life or sexual-orientation data, or personal data concerning criminal convictions and offences.

Personal data we handle

  • Account and organization data: name, business email address, company, legal business name and address, workspace membership, role, and authentication or single-sign-on identifiers.
  • Billing data: subscription, invoice, payment status, and transaction identifiers. Stripe processes payment-card details; Norami does not store full card numbers.
  • Customer workspace content: uploaded files, datasets, schemas, prompts, chat messages, attachments, generated responses, and related metadata.
  • Usage and security data: login and audit events, timestamps, feature and usage counts, IP address, browser or device information, session identifiers, rate-limit events, and diagnostic or error information.
  • Communications: support, privacy, security, billing, and other service-related messages. Norami does not currently send newsletters or promotional marketing emails.

We receive data directly from you, from the business that invites or administers your account, from your use of Norami, and from service providers involved in authentication, billing, security, and service delivery.

Why we use personal data

  • To create accounts, authenticate users, provide workspaces, process subscriptions, answer support requests, and deliver requested features.
  • To operate, secure, troubleshoot, monitor, and improve the reliability of Norami, enforce usage limits, prevent abuse and fraud, and maintain audit records.
  • To comply with accounting, tax, legal, regulatory, and lawful government requirements and to establish, exercise, or defend legal claims.

Depending on the circumstances, AI BLU, LLC relies on performance of a contract or steps requested before entering a contract (GDPR Article 6(1)(b)); compliance with legal obligations (Article 6(1)(c)); and its and its customers' legitimate interests in providing, administering, securing, supporting, and improving a reliable business service (Article 6(1)(f)). Where a user is acting for an employer or another customer rather than being personally party to the contract, service administration generally relies on those legitimate interests.

For customer workspace content, the customer determines the applicable legal basis and instructs AI BLU, LLC through the customer agreement and Data Processing Addendum.

AI processing and service providers

To answer a request, Norami may send the relevant prompt, query result, rows, values, or attachment content to approved AI providers such as OpenAI or Anthropic. When code execution is required, relevant data may be loaded into an isolated execution sandbox. Norami sends the information needed for the requested operation rather than an entire dataset by default.

AI BLU, LLC also uses providers for hosting and databases, network delivery, authentication, payment processing, email, security and error monitoring, sandboxed code execution, and optional business-context research. Providers receive only the data needed for their function and are subject to contractual and confidentiality restrictions. A current provider list and change-notice process are available on the Subprocessors page.

Customer workspace administrators may access account activity and workspace content according to their roles. AI BLU, LLC may also disclose information where required by law, to protect legal rights or service security, or as part of a corporate transaction subject to appropriate safeguards.

AI BLU, LLC does not sell personal data or customer content and does not use customer workspace content to train AI models. Its API providers are engaged under business data-processing terms that restrict processing to providing their services.

International processing

Norami's primary infrastructure and contracting entity are in the United States. Authorized personnel of the same AI BLU, LLC entity may administer the service remotely from Chile. Service providers may process data in the United States and other locations stated on the Subprocessors page.

Where EEA personal data is transferred to a country without an applicable adequacy decision, AI BLU, LLC uses an appropriate transfer mechanism where required. For transfers of customer workspace data to AI BLU, LLC in the United States, this ordinarily includes a Data Processing Addendum and the EU Standard Contractual Clauses, Module 2. Provider transfers may rely on an adequacy decision, an active EU–U.S. Data Privacy Framework certification, or Standard Contractual Clauses, as applicable. You may request information or a copy of the applicable safeguards by emailing privacy@norami.ai.

How long we retain data

  • Account profiles are kept for the life of the account and during a 30-day deletion grace period.
  • Customer datasets and chat history are generally kept for the life of the workspace. Raw uploaded files are deleted when no longer referenced; abandoned pre-ingestion uploads normally expire after 24 hours.
  • Chat attachments normally expire after 30 days.
  • Generated data-export files expire after 7 days.
  • Pre-workspace signup-funnel records containing an email address expire after 90 days.
  • Security audit records are retained on a rolling basis for up to 730 days.
  • Billing, tax, fraud-prevention, and legal records are retained for the period required or justified for those purposes and are deleted or anonymized when they are no longer needed.

Deleted information may remain temporarily in provider-managed backups until the relevant backup cycle expires. Where AI BLU, LLC acts as a processor, the customer agreement may provide more specific instructions.

Cookies

Norami uses cookies and similar storage that are necessary for authentication, security, single sign-on, remembering the active workspace, and maintaining a user session. Norami does not currently use advertising cookies or third-party behavioral tracking cookies. If optional tracking is introduced, this notice and the applicable consent controls will be updated before it is enabled.

Your data-protection rights

Depending on your location and the circumstances, you may have the right to request access to, correction of, deletion of, restriction of, or portability of your personal data and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing. These rights may be subject to lawful limitations and exceptions.

You can use the available account settings or email privacy@norami.ai. We may verify your identity before acting. We will respond without undue delay and ordinarily within one month. If your request concerns personal data controlled by a Norami customer, we will route it to that customer and assist them as required.

EEA individuals may also lodge a complaint with the data-protection supervisory authority in their country of residence, place of work, or the place of the alleged infringement.

Automated decisions

Norami generates analytical outputs, but AI BLU, LLC does not use those outputs to make decisions about individuals that produce legal or similarly significant effects. Customers are responsible for reviewing outputs and deciding how they use them.

Security

AI BLU, LLC uses technical and organizational safeguards designed for the risk, including encryption in transit and at rest, tenant-level access controls, authentication controls, audit logging, data minimization, retention controls, and incident-response procedures. No system can be guaranteed completely secure.

Changes to this notice

We may update this notice as Norami, its providers, or legal requirements change. The current version and its effective date will remain available here. We will provide additional notice when a change materially affects how we use personal data.

Contact

For privacy questions, rights requests, or information about transfer safeguards, contact privacy@norami.ai or write to AI BLU, LLC, 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States.

Business customers can review how AI BLU, LLC processes workspace data on the Data Processing Addendum page.