← Cinepsus

Privacy Policy — Cinepsus

Last updated
[DATE OF PUBLICATION]
Effective
[DATE]

DRAFT FOR COUNSEL REVIEW. NOT PUBLISHED, NOT EXECUTED. Every [BRACKETED] item is a fact about the company that has not been established and must be supplied. Every [LAWYER DECISION] marker is a point where a qualified lawyer must choose, not the drafter.


1. Who we are

Cinepsus is a service that lets you upload scientific papers and ask questions about them, answered by an AI model that reads the paper's text.

The controller of your personal data is:

  • Entity name: [LEGAL ENTITY NAME]
  • Registered address: [REGISTERED ADDRESS]
  • Company number / registry: [COMPANY NUMBER, REGISTRY]
  • Contact for privacy questions: [PRIVACY CONTACT EMAIL]

Data Protection Officer. [LAWYER DECISION] — a DPO is required under GDPR Art. 37 only if core activities involve regular and systematic monitoring on a large scale, or large-scale processing of Art. 9 data. Neither appears to apply on the current design (we do not collect special-category data and do not monitor users' behaviour), so the working assumption is no DPO is required. Confirm, then either name one here or delete this paragraph.

EU representative

[TO BE COMPLETED: depends on place of establishment]

If the controller is not established in the European Union and offers services to people in the EU, GDPR Art. 27 requires a written designation of a representative in a Member State where our users are, and that representative must be named here with a contact address. The same applies separately under UK GDPR Art. 27 if we target users in the United Kingdom.

  • EU representative: [NAME, ADDRESS, CONTACT — TO BE COMPLETED]
  • UK representative: [NAME, ADDRESS, CONTACT — TO BE COMPLETED, or delete if the UK is not targeted]

If the controller is established in the EU, delete this whole section and instead identify the lead supervisory authority. [LAWYER DECISION]


2. What we collect

We collect only what the service needs to work. We do not run advertising, we do not sell or share your personal data, and we do not operate analytics or tracking software.

2.1 Account data

DataWhere it comes from
Email addressYou, via our identity provider at sign-up
Display nameYou, or your identity provider
Identity-provider user IDOur identity provider
Subscription plan and plan overridesYour purchase, synchronised from our billing provider
Preferences: explanation level, themeYou
Account statusUs
Usage counters (how many messages, uploads and runs you used in a period)Generated by the service, to enforce plan limits

We do not collect your date of birth or any age information. See the minimum-age clause in the Terms of Service.

Legacy credentials. Some older accounts may still hold a stored password hash from before we moved to a hosted identity provider. We are removing these. If your account has one, it is treated as account data and deleted with your account. [CONFIRM BEFORE PUBLICATION: whether any such values remain]

2.2 Content you give us

DataNotes
The PDF files you uploadStored in object storage
The extracted full text of those PDFsStored in our database; this is what the AI model reads
Document metadata: title, authors, page count, outlineExtracted from the file
OCR'd copies of scanned documentsOnly created for scanned PDFs
Page thumbnailsGenerated by us
Your highlights: the passage or region you selected, the quoted text, any caption, and an image crop of the region
Your questions and the AI's answers, including citations and per-message token counts
Python code you run in the sandbox, its output, generated plots and result files
LaTeX source you export and its preview image
Knowledge-graph nodes and edges derived from your documents
Studies (collections of documents) and their titles

Please note: the content of what you upload and type is entirely your choice. Free-text fields are not filtered. Do not upload documents containing, or type into the chat, sensitive personal information about yourself or others — in particular health, biometric, political, religious, trade-union, sexual-orientation or criminal-offence data (GDPR Art. 9 and Art. 10 categories). The service is not designed to process that kind of data and we do not want to receive it.

2.3 Support data

DataNotes
Support ticket: your email address, title, issue type, free-text descriptionYou, when you open a ticket
Ticket replies, including the full body of emails you send to our support reply addressYou and our support staff
An identifier for each email messageOur email provider

2.4 Administrative records

When a member of our staff performs an administrative action on an account (for example resetting usage or deleting an account), we log the action, the staff member's email address, the affected account identifier and a short description. This is an accountability record kept under GDPR Art. 5(2). [LAWYER DECISION] — we currently store the affected user's email address in these records, which means an email address can outlive an erasure request. The recommendation in the accompanying audit is to replace it with the account UUID or a salted hash and to time-limit the log. Confirm the final position and describe it accurately here before publication.

2.5 What we do not collect

  • No cookies for analytics, advertising or profiling. See §7.
  • No device fingerprinting, no session recording, no heatmaps.
  • No location data beyond what is inherent in an IP connection.
  • No date of birth or age.
  • No payment card details — these go directly to our payment processor and we never see or store them.

3. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Creating and running your accountAccount dataArt. 6(1)(b) — performance of a contract
Storing your documents and letting you read themContent you give usArt. 6(1)(b)
Sending your document text and your question to an AI model so it can answerDocument full text, highlights, chat history, questionArt. 6(1)(b)
Running Python code you write, in an isolated sandboxCode and its outputArt. 6(1)(b)
Fetching metadata and open-access copies of papers your document citesCitation strings from your documentArt. 6(1)(b)
Enforcing plan limits and preventing abuseUsage countersArt. 6(1)(b), and Art. 6(1)(f) legitimate interests in preventing abuse
Taking payment and managing subscriptionsAccount data, planArt. 6(1)(b)
Answering your support requestsSupport dataArt. 6(1)(b), and Art. 6(1)(f) where you are not yet a customer
Sending service emails (ticket updates, billing confirmations)Email addressArt. 6(1)(b)
Keeping records of administrative actionsAdministrative recordsArt. 6(1)(c) and Art. 6(1)(f) — accountability under Art. 5(2)
Security, debugging and keeping the service runningTechnical logsArt. 6(1)(f)

[LAWYER DECISION] — Whether marketing email (as distinct from transactional email) is ever sent, and if so whether it rests on consent or on the ePrivacy soft-opt-in for existing customers. No marketing mail exists in the current design; if that changes, this table and §7 both need updating.

We do not carry out automated decision-making that produces legal or similarly significant effects about you (GDPR Art. 22). The AI generates answers about documents; it does not make decisions about you, assess you, score you, or evaluate your abilities.


4. AI processing — what actually happens to your documents

This section is deliberately blunt, because it is the most important thing in this policy.

When you ask a question, we send to a third-party AI model provider:

  • the full extracted text of the document or documents in scope,
  • your question,
  • your recent chat history in that conversation (capped),
  • any highlight you selected, including an image crop where relevant, and
  • a compact serialisation of the knowledge graph for that document, where one exists.

We do this for every question. There is no retrieval step that sends only fragments; the model reads the whole document.

Which provider receives it: [STATE THE CONFIGURED PROVIDER AT PUBLICATION — see §5 and §6]. This is a configuration choice and it determines where in the world your document text is processed. If it changes, we will update this policy and notify account holders before the change takes effect.

AI answers can be wrong. The model can misread, omit, or attribute a statement to the wrong page. Answers and citations must be checked against the source document. This is also stated in the product interface.

We do not use your documents, questions or answers to train AI models. [LAWYER DECISION / VERIFY BEFORE PUBLICATION] — this statement can only be made if the contract with the chosen model provider actually prohibits training on submitted data and the correct no-training API tier is in use. Verify the provider's terms and the account configuration before publishing this sentence. Do not publish it on trust.


5. Who we share it with (sub-processors)

We use the following processors. Each is engaged under a written contract meeting GDPR Art. 28. [CONFIRM EXECUTION STATUS — see the DPA checklist]

Sub-processorWhat it doesWhat it receivesWhere it processes
ClerkAuthentication, session management, hosted account UI, and the billing front endEmail address, name, account identifiers, subscription status[US / OTHER — CONFIRM]
StripePayment processing, connected through Clerk BillingBilling identifiers, payment details you enter, subscription events[US / OTHER — CONFIRM]
Z.ai / Zhipu AI (if configured as the model provider)Generates answersFull document text, your questions, chat history, highlight text and image cropsPeople's Republic of China — see §6
Anthropic (if configured as the model provider)Generates answersSame as above[US / OTHER — CONFIRM]
ResendSends transactional email and receives inbound support repliesYour email address, ticket contents, email bodies you send us[US / OTHER — CONFIRM]
Object storage provider [NAME]Stores uploaded PDFs, thumbnails, OCR copies, highlight crops, code-run outputs, LaTeX previews and fetched figuresAll stored files[REGION — CONFIRM]
Database and cache hosting [NAME]Runs our PostgreSQL database and Redis queueAll database contents, including document text and chat messages[REGION — CONFIRM]
Application hosting [NAME(S)]Runs the web and API applicationsAll data in transit through the application[REGION — CONFIRM]
LangSmith / LangChainconditional; only if tracing is enabledDeveloper tracing of AI agent runsFull prompts, meaning document text and chat content[US — CONFIRM]

On the LangSmith entry. Our software supports an optional tracing mode. It is off by default. If it is ever switched on in production, LangSmith becomes a processor that receives full document text and chat content, and this policy must be updated before it is enabled. [STATE PLAINLY AT PUBLICATION WHETHER TRACING IS ON OR OFF] — do not publish an ambiguous answer.

We also disclose personal data where we are legally required to (court order, lawful request from a competent authority), and to professional advisers under duty of confidence. In a merger or asset sale, data may transfer to the acquirer; you would be told.

We do not sell personal data and we do not share it for cross-context behavioural advertising, in the sense those terms are used in United States state privacy laws.


6. International transfers (GDPR Art. 13(1)(f), Chapter V)

Some of our processors are outside the European Economic Area.

United States processors. [LIST WHICH]. Transfers rely on [EU-US DATA PRIVACY FRAMEWORK certification where the recipient is certified / EU Standard Contractual Clauses (2021/914) plus a transfer impact assessment]. [LAWYER DECISION] — check each recipient's current DPF certification individually rather than assuming; certification is per-entity and can lapse.

China. If Z.ai / Zhipu AI is the configured model provider, the full text of your uploaded documents and your chat messages are transferred to and processed in the People's Republic of China.

The European Commission has not adopted an adequacy decision for China. A transfer therefore requires an Art. 46 safeguard — in practice the 2021 Standard Contractual Clauses — supported by a documented transfer impact assessment that addresses the possibility of access by public authorities under PRC law, together with any supplementary measures that assessment concludes are necessary.

[LAWYER DECISION — BLOCKING] This policy must not be published describing a China transfer as lawful until (a) the SCCs are executed with the recipient, (b) a written transfer impact assessment exists and is retained, and (c) its conclusion is that the transfer can proceed, with the supplementary measures it identifies actually implemented. If any of those is missing, the correct action is to change the configured provider rather than to publish this paragraph.

You may request a copy of the safeguards we rely on by writing to [PRIVACY CONTACT EMAIL].


7. Cookies and similar technologies

We do not use analytics, advertising or tracking cookies. There is no cookie banner because there is nothing to consent to.

The only cookies set are those our authentication provider needs to sign you in and keep you signed in, plus session and security cookies set by our own application.

Cookie categoryPurposeSet byRoughly how long
Session / authenticationKeeping you signed in, and protecting the sessionClerk and our applicationSession, or up to [N] days for "remember me" [CONFIRM ACTUAL LIFETIMES FROM THE PROVIDER]
Security (CSRF and similar)Preventing forged requestsOur applicationSession
PreferenceRemembering your theme choiceOur application[N] months [CONFIRM]

Why there is no consent prompt. Article 5(3) of the ePrivacy Directive requires consent for storing or accessing information on your device, but exempts storage that is strictly necessary to provide a service you have explicitly requested. Authentication cookies for a service you signed in to fall within that exemption. We are relying on the exemption, and we are telling you about the cookies here because GDPR Art. 13 requires transparency regardless of whether consent is needed.

Internal review gate. The moment any analytics, product-telemetry, session-recording, A/B-testing, heatmap or advertising technology is introduced — including a self-hosted one — the strictly-necessary exemption stops covering it. Before any such tool ships, a compliant consent management platform must be in place (prior, granular, freely given, as easy to refuse as to accept, with no pre-ticked boxes and no cookie walls), this section must be rewritten, and §3 must gain a consent legal basis. This is recorded here as a standing engineering and legal gate, not an aspiration.


8. How long we keep things

Full detail is in our retention schedule [LINK]. In summary:

DataKept for
Account dataWhile your account is open
Uploaded documents, extracted text, highlights, chat history, code runs, LaTeX runs, knowledge graphsWhile your account is open, subject to an inactivity sweep based on when you last opened the document
Support tickets and support email repliesA fixed period after the ticket is resolved — these contain whatever you chose to write to us, so they are on a shorter clock than your documents
Usage countersA rolling window sufficient to enforce plan limits, then deleted
Administrative recordsA fixed period, as an accountability record
Billing recordsAs required by tax and accounting law in [JURISDICTION] — typically the longest retention we apply, and it overrides deletion requests for the invoice data itself

When you delete your account, we delete your database records and the files in object storage. Backups are overwritten on their own cycle; deleted data can persist in backups for up to [N] days [CONFIRM ACTUAL BACKUP ROTATION], after which it is gone. We do not restore deleted accounts from backup.


9. Your rights

If the GDPR applies to you, you have the right to: access your data (Art. 15); correct it (Art. 16); have it erased (Art. 17); restrict processing (Art. 18); receive it in a portable format (Art. 20); object to processing based on legitimate interests (Art. 21); and, where processing rests on consent, withdraw that consent at any time without affecting what happened before.

How to exercise them. In the application: [DESCRIBE THE IN-PRODUCT CONTROLS ONCE THEY EXIST — an account-deletion control and a data-export control are both required and are being built]. Or write to [PRIVACY CONTACT EMAIL].

We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend (Art. 12(3)). We do not charge, unless a request is manifestly unfounded or excessive.

Complaints. You can complain to your national data protection authority. [IF THE CONTROLLER IS EU-ESTABLISHED, NAME THE LEAD SUPERVISORY AUTHORITY]. We would prefer you raise it with us first, but you do not have to.

If you are in the United States: the rights available to you depend on your state and on whether we meet that state's applicability thresholds. As a small pre-revenue service we do not currently meet the thresholds of the California Consumer Privacy Act or of most comparable state statutes. We will honour access and deletion requests from US residents anyway, on the same process as above. If and when a state law does apply to us, this section will be expanded with the specific rights and the required notices.

Children. The service is not for children. See the minimum-age clause in the Terms of Service (13 and over generally; 16 and over in the EU/EEA unless the local age is lower). We do not knowingly collect data from anyone below those ages, and we do not collect date of birth. If you believe a child has an account, write to [PRIVACY CONTACT EMAIL] and we will delete it.


10. Security

We host data with reputable providers, encrypt data in transit, restrict administrative access, and run user-submitted code in an isolated sandbox that is refused execution if isolation cannot be established. Files are served through short-lived signed links rather than public URLs.

No service is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours (GDPR Art. 33) and tell affected users where the risk is high (Art. 34).

[EXPAND ONCE THE SECURITY POSTURE IS DOCUMENTED — do not overstate. Every security claim in a privacy policy is a representation that can be held against the company under FTC Act §5 and under EU unfair-commercial-practices law. Only claim what is actually true and evidenced.]


11. Changes

We will post changes here and update the date at the top. For changes that materially affect how your data is handled — in particular a change of AI model provider or a change in where document text is processed — we will notify account holders in advance by email.

12. Contact

[PRIVACY CONTACT EMAIL] [POSTAL ADDRESS]