Privacy Policy
Effective: {EFFECTIVE_DATE}. This describes how {LEGAL_ENTITY} (“we”, “Citavo”) handles your data when you use the hosted service at {DOMAIN}.
⚠️ Template for review. This is an accurate plain-language draft of how the software actually processes data. Have a qualified lawyer review and adapt it (and confirm your GDPR obligations, sub-processor agreements, and governing law) before you rely on it.
1. Who we are
The service is operated by {LEGAL_ENTITY}, {LEGAL_ADDRESS}. For any privacy question or request, contact {CONTACT_EMAIL}. We are the data controller for your account data; for the documents you upload we act as a processor on your instructions.
2. What we collect
- Account data — your email address and a securely hashed password; optional two-factor settings.
- Your documents — when you add a source, we extract its text and store that text in our database to answer your questions. We do not keep the original uploaded file.
- Questions & answers — the questions asked of your assistants and the generated answers (conversation history).
- Usage metadata — counts of questions answered, timestamps, and technical logs (e.g. IP address) needed to run and secure the service.
- Payment data — handled by our payment processor (Stripe). We never see or store full card details.
- Your AI provider keys (BYOK) — if you connect your own key, it is encrypted at rest and never shown again or exported.
3. How your documents are used (important)
Your document text is stored on our servers and searched locally. When someone asks a question, we send that question together with the most relevant excerpts — never your whole document library — to the configured AI provider so it can write the answer. AI answers are machine-generated and labelled as such (EU AI Act, Article 50).
If you configure a local model (self-hosted), nothing is sent to any outside AI service. If you self-host Citavo entirely, your data never reaches us at all.
4. Where your data is stored
Hosted data is stored on our servers located in {HOSTING_REGION} (currently Fly.io, Paris/EU). If you self-host, it stays on your own infrastructure.
5. Sub-processors (third parties who may process data)
- AI provider(s) — receives your question + relevant excerpts to generate answers. On the hosted service the default is {MANAGED_AI_PROVIDER} (e.g. DeepSeek); if you bring your own key, it is the provider you chose (e.g. OpenAI, Anthropic, Google). Review that provider’s own privacy terms.
- Stripe — payment processing.
- Email provider — sending verification and password-reset emails.
- Hosting provider — {HOSTING_PROVIDER} (infrastructure).
6. Retention & deletion
We keep your data while your account is active. You can export all your data or delete your account at any time from Settings; deletion permanently removes your account, projects, document text, and search index. Backups and logs are retained for a limited period for security and recovery.
7. Your rights
Subject to applicable law (including the GDPR for EU/EEA users), you may request access, correction, deletion, a portable copy, or restriction of your personal data, and you may object to certain processing. Use the in-app tools (Settings → Download my data / Delete account) or contact {CONTACT_EMAIL}. You may also lodge a complaint with your data-protection authority.
8. Security
We use HTTPS in transit, hashed passwords, AES-256-GCM encryption for stored provider keys, CSRF protection, rate limiting, and access controls. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Children
The service is not directed to children under 16, and we do not knowingly collect their data.
10. Changes
We may update this policy; we will post the new effective date here and, for material changes, notify you.
Questions? {CONTACT_EMAIL}