Privacy Policy
Last updated: May 18, 2026
Endor (the "Service") is an internal tool operated by Ridgeline Agency for its clients and their authorized support agents. This policy covers both the Endor web application and the Endor Chrome extension ("Extension").
1. Who this policy is for
The Service is not offered to the general public. Access is granted by invitation only, scoped to specific client workspaces. If you do not have an Endor account, this policy does not apply to you.
2. What we collect
Account data
- Your name and email address (from Google Sign-In).
- Your role within Endor and the client workspaces you are assigned to.
- Timestamps of sign-ins and activity within the Service.
Ticket data (processed, not stored long-term)
When you analyze or draft a reply for a Gorgias ticket, the Service fetches that ticket's contents (customer messages, agent replies, metadata) from Gorgias using the workspace's API credentials. This data is sent to Anthropic's Claude API to produce a summary, suggested reply, recommended action, and sentiment.
We retain a short-lived cache of the latest analysis per ticket (up to 15 minutes) to avoid repeated AI charges for the same ticket. We retain operational telemetry per call (latency, token counts, cost, error codes) for billing and reliability monitoring.
Extension-specific data
The Extension stores your Endor session token in Chrome's local extension storage so you stay signed in. It detects the current Gorgias ticket only from the page URL — it does not read or transmit the ticket's DOM content. Backend calls always go through Endor's servers, never directly to Gorgias from the Extension.
3. How we use data
- To authenticate you and authorize access to the right workspaces.
- To generate ticket analyses and draft replies on your request.
- To prevent abuse via rate limiting and audit logging.
- To monitor cost and reliability.
We do not sell your data. We do not use your data to train AI models beyond the immediate request to Anthropic, which processes data per its own enterprise privacy terms.
4. Who we share with
- Supabase — hosts our database, authentication, and serverless functions.
- Anthropic — processes ticket text to generate analyses and reply drafts.
- Gorgias — source of the ticket data we analyze on your behalf.
- Google — provides Sign-In identity for your Endor account.
5. Retention
- Account data: retained while your account is active.
- Ticket analysis cache: 15 minutes per ticket.
- Operational telemetry: retained for the lifetime of the workspace.
- Drafted replies you generate: retained so managers can review quality. Removed on workspace deletion.
6. Security
All traffic is encrypted in transit. API keys for third-party services are stored as encrypted secrets and are never exposed to the browser or the Extension. Access to ticket data is gated by per-workspace role checks enforced server-side.
7. Your choices
You can disconnect the Extension at any time by removing it from Chrome. You can request that your account be deactivated by contacting your Endor administrator. Deactivation removes access immediately; backups may persist for up to 30 days.
8. Contact
Questions about this policy? Contact your Endor administrator or email privacy@ridgelineagency.com.
9. Changes
We will update the "Last updated" date above when this policy changes. Material changes will be communicated to administrators.