1.Information We Collect
Account Information
- Name, email address, and password (hashed)
- Billing and payment information processed through Stripe
- Organization name and role (for team accounts)
Research Queries & Generated Reports
- Research topics and queries you submit
- Generated reports, including content, citations, and metadata
- Report customization preferences (depth, format, audience)
Usage Data & Analytics
- Feature usage patterns and interaction data
- Report generation timestamps and completion metrics
- Account activity logs for security purposes
Device & Browser Information
- Browser type, version, and language settings
- Operating system and device type
- IP address (anonymized after 30 days)
2.How We Use Your Information
Providing & Improving the Service
- Processing your research queries and generating reports
- Personalizing your experience and report recommendations
- Improving report quality, accuracy, and platform reliability
Processing Research Queries
- Transmitting queries to AI models for analysis and synthesis
- Retrieving relevant web sources and academic literature
- Structuring findings into professional-grade reports
Communication & Support
- Sending transactional emails (report completion, billing receipts)
- Providing customer support and responding to inquiries
- Sending product updates and feature announcements (opt-in only)
Security & Fraud Prevention
- Detecting and preventing unauthorized access or abuse
- Monitoring for anomalous usage patterns
- Enforcing our Terms of Service
3.AI & Data Processing
Your data is never used to train AI models.
CLADAL uses Anthropic's Claude models to process research queries. Under our enterprise agreement with Anthropic, your inputs and outputs are never used to train, fine-tune, or improve any AI model. Your data is processed solely to generate your report and is not retained by Anthropic after processing.
How AI Processing Works
- Your research query is sent to Claude (by Anthropic) via a secure API connection
- AI agents search publicly available web sources and synthesize findings
- Generated reports are stored in your private account on our infrastructure
- No AI model has persistent access to your data between sessions
EU AI Act Compliance
- CLADAL is classified as a limited-risk AI system under the EU AI Act
- All AI-generated content is clearly labeled as such
- Users maintain full control over whether to use, edit, or discard AI outputs
- We maintain transparency logs of AI model versions and processing metadata
Research Output Privacy
- Generated reports are private to your account by default
- Reports are only shared when you explicitly choose to share them
- We do not aggregate, analyze, or mine your reports for any purpose beyond delivering the service
4.Data Sharing & Third Parties
We share data only with the service providers necessary to operate CLADAL. We never sell your personal data to advertisers, data brokers, or any other third party.
Service Providers
- Anthropic — AI model provider. Processes research queries under strict data processing agreements. Zero data retention.
- Supabase — Database and authentication infrastructure. Data encrypted at rest and in transit.
- Stripe — Payment processing. CLADAL never stores your full credit card number; Stripe handles all payment data under PCI DSS Level 1 compliance.
Legal Requirements
We may disclose information if required by law, subpoena, or court order, or if necessary to protect the rights, safety, or property of CLADAL, our users, or the public.
5.Data Retention
- Active account data — Retained for as long as your account remains active and in good standing.
- Generated reports — Stored until you choose to delete them. You can delete individual reports or your entire report history at any time.
- Deleted data — Purged from production systems within 30 days of deletion.
- Backups — Deleted data is removed from backup systems within 90 days.
- Account closure — Upon account deletion, all associated data is queued for purging and removed within the timelines above.
6.Your Rights
Regardless of your location, you have the following rights over your data:
- Access — Request a copy of all data we hold about you
- Deletion — Request deletion of your account and all associated data
- Portability — Export your reports and data in standard formats (PDF, Markdown)
- Correction — Update or correct inaccurate account information
- Opt-out — Unsubscribe from marketing communications at any time
Additional Rights for EU Residents (GDPR)
- Right to restrict processing of your personal data
- Right to object to processing based on legitimate interests
- Right to lodge a complaint with your local Data Protection Authority
- Our lawful basis for processing: contract performance (Article 6(1)(b)) and legitimate interest (Article 6(1)(f))
Additional Rights for California Residents (CCPA)
- Right to know what personal information is collected and how it is used
- Right to delete personal information held by us and our service providers
- Right to opt out of the sale of personal information — we do not sell your data
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at privacy@cladal.com. We will respond within 30 days (or sooner where required by law).
8.Security
- Encryption at rest — All stored data is encrypted using AES-256 encryption.
- Encryption in transit — All network communications use TLS 1.3.
- Access controls — Role-based access with the principle of least privilege. All administrative access is logged.
- Security audits — Regular penetration testing and vulnerability assessments by third-party firms.
- SOC 2 Type II — Compliance program in progress. We follow SOC 2 security principles in our operations today.
- Incident response — In the event of a data breach, we will notify affected users within 72 hours as required by GDPR and applicable law.
9.International Data Transfers
CLADAL is operated from the United States. If you access the platform from outside the US, your data will be transferred to and processed in the United States.
- For EU/EEA users, transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission
- For UK users, transfers comply with the UK International Data Transfer Agreement
- We assess the data protection laws of recipient countries and implement supplementary measures where necessary
10.Children's Privacy
CLADAL is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will promptly delete that information. If you believe a child has provided us with personal data, please contact us at privacy@cladal.com.
11.Changes to This Policy
- We will provide at least 30 days' advance notice before material changes take effect
- Registered users will receive email notification of material changes
- The "Last Updated" date at the top of this page reflects the most recent revision
- Continued use of CLADAL after changes take effect constitutes acceptance of the revised policy
12.Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, reach out to us:
Mailing Address
CLADAL, Inc.
Attn: Privacy Team
[Address to be provided]
We aim to respond to all privacy inquiries within 30 days.