This Privacy Policy explains how Cearsi AI ("Cearsi", "we", "us", or "our") collects, uses, shares, and protects information when you visit cearsi.dev, create an account, or use the Cearsi product, dashboard, APIs, and related services (collectively, the "Service"). It is drafted to reflect the requirements of the EU and UK General Data Protection Regulation ("GDPR"/"UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana consumer privacy statutes, Canada's PIPEDA, Brazil's LGPD, and Australia's Privacy Act. It is a plain-language reference and is not legal advice. By using the Service you acknowledge the practices below.
1.Information we collect
1.1Account information
When you create an account we collect your email address, a salted password hash, an internal user identifier, and any profile details you choose to provide (display name, avatar, time zone, preferences). If you sign in with a third-party identity provider, we receive the basic profile fields that provider shares with us in accordance with the permissions you grant.
1.2Content you submit
We process the prompts, messages, uploaded files and images, watchlists, notes, plans, and other content you submit ("Your Content") so Cearsi can respond, save your work, and personalize the experience. Your Content is stored under your account and scoped to you via row-level database policies. We do not use Your Content to train foundation models, and we do not sell it.
1.3Billing information
If you subscribe to a paid plan, Stripe (our PCI-DSS Level 1 payment processor) collects the billing details needed to complete the transaction (name, billing address, payment method, and tax identifiers where applicable) directly through embedded checkout. Cearsi receives only limited details such as the last four digits of the card, brand, expiration month/year, country, subscription status, invoice history, and Stripe customer/subscription identifiers. We never see or store full card numbers, CVCs, or bank credentials.
1.4Usage and device data
We automatically collect basic diagnostic and usage data, including IP address (which may be treated as personal data under GDPR), coarse geolocation derived from IP, browser and device type, operating system, referring URL, feature interactions, timestamps, request identifiers, and error reports. This data is used to secure the Service, prevent abuse and fraud, and improve reliability.
1.5Cookies
We use strictly necessary cookies and equivalent local-storage entries to keep you signed in, remember your theme and layout preferences, and protect the Service against CSRF and session hijacking. We may use limited first-party analytics to understand aggregate usage. We do not use cross-site advertising cookies. Where required by law (for example, the EU/UK ePrivacy rules), non-essential cookies are set only after you consent. You can grant, refuse, or withdraw consent at any time from our in-app Cookie Preferences Center at /cookies or via the "Cookie preferences" link in the site footer. You may also manage cookies through your browser; disabling strictly necessary cookies will break authenticated features.
When you grant the "Marketing" category, we load the TikTok Pixel (analytics.tiktok.com), which allows TikTok to receive your IP address, user agent, referring URL, and pageview events so we can measure ad performance and attribution for campaigns that bring visitors to Cearsi. TikTok acts as an independent controller for this data; see the TikTok Privacy Policy. The pixel is not loaded and no data is sent to TikTok until you opt in, and it stops collecting further events as soon as you withdraw consent.
1.6Categories of personal information (CCPA/CPRA)
In the last 12 months we have collected the following CCPA categories: identifiers (email, user ID, IP), commercial information (subscription and purchase history), internet or network activity (usage and diagnostic logs), inferences drawn from usage, and any content you voluntarily submit. We do not knowingly collect sensitive personal information, precise geolocation, biometric data, or information about children.
2.How we use information
We use the information described above to:
- Operate, maintain, and improve the Service;
- Authenticate accounts and prevent fraud, abuse, and unauthorized access;
- Generate AI responses to the prompts and content you submit, including routing to third-party model providers under contractual data-processing terms;
- Process payments, manage subscriptions, and send billing communications;
- Provide customer support and respond to your requests;
- Send service announcements, security alerts, and, with consent where required, product updates;
- Monitor performance, debug issues, and improve reliability and quality;
- Detect, investigate, and prevent security incidents, fraud, and illegal activity;
- Comply with legal obligations (tax, accounting, sanctions, anti-money-laundering, lawful requests) and enforce our Terms of Service.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use Your Content to train foundation models.
3.Legal bases for processing
Where the GDPR, UK GDPR, or similar laws apply, we process personal data on the following legal bases: (a) performance of a contract with you (delivering the Service you request and billing); (b) our legitimate interests in operating, securing, and improving the Service, provided those interests are not overridden by your rights; (c) your consent for optional processing such as marketing communications and non-essential cookies, which you may withdraw at any time; and (d) compliance with a legal obligation to which we are subject.
4.How we share information
4.1Service providers
We rely on a limited set of subprocessors to run Cearsi, including our hosting and edge provider (Cloudflare), managed database and authentication provider (Supabase), payment processor (Stripe), transactional email provider, and the AI model providers that power responses (which may include OpenAI, Anthropic, Google, and other model vendors accessed through our AI gateway). These vendors act as processors on our behalf under written data-processing agreements that restrict how they may use data. A current list of subprocessors is available on request at support@cearsi.dev.
4.2Legal and safety
We may disclose information if we reasonably believe it is required by law, subpoena, or valid legal process, or where necessary to protect the rights, property, or safety of Cearsi, our users, or others, including to enforce our Terms, detect fraud, respond to abuse, or comply with sanctions and anti-money-laundering obligations.
4.3Business transfers
If Cearsi is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections. We will notify you of any change in ownership or use of your personal information as required by applicable law.
5.International data transfers
Cearsi is operated from the United States and our vendors may process information in the U.S., the EU/EEA, the UK, and other jurisdictions. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary technical measures such as encryption in transit and at rest. A copy of the safeguards we use is available on request.
6.Data retention
We retain personal data only as long as needed for the purpose it was collected:
- Account records and Your Content: for the life of your account, then deleted or anonymized within 30 days of account deletion;
- Billing, invoice, and tax records: up to 7 years, as required by applicable tax and accounting law;
- Security, audit, and abuse-prevention logs: up to 12 months;
- Application diagnostic logs: up to 90 days;
- Encrypted backups: rolling window of up to 35 days before being overwritten.
We may retain data longer where required to comply with a legal obligation, resolve disputes, or enforce our agreements.
7.Security
We use technical and organizational measures designed to protect your information, including TLS 1.2+ encryption in transit, encryption at rest with our managed database provider, salted password hashing, row-level security policies, principle-of-least- privilege administration, secret management, and continuous automated security scanning. No online service is 100% secure; you are responsible for safeguarding your account credentials. See our Security page for more.
8.Your rights and choices
Depending on where you live, you may have the right to (a) know or access the personal information we hold about you; (b) request correction of inaccurate data; (c) request deletion of your data; (d) receive a portable copy of your data; (e) restrict or object to certain processing, including profiling with legal or similarly significant effects; (f) opt out of the "sale" or "sharing" of personal information and of targeted advertising (we do not engage in either); and (g) withdraw consent at any time where processing is based on consent. California residents may designate an authorized agent and have the right not to receive discriminatory treatment for exercising these rights. You can exercise these rights by emailing support@cearsi.dev. We will respond within the timeframes required by applicable law (typically 30 days under GDPR/UK GDPR and 45 days under U.S. state laws). We may need to verify your identity before acting on a request. If we deny a request, you have the right to appeal by replying to our decision. You may also unsubscribe from marketing emails using the link in any such message, and lodge a complaint with your local data protection authority (for the EU, your national supervisory authority; for the UK, the ICO at ico.org.uk).
9.Children's privacy
Cearsi is not directed to and not intended for children. The Service is not offered to anyone under 18, and paid subscriptions require legal capacity to contract. We do not knowingly collect personal information from children under 13 (or the minimum age in your country, e.g., 16 in parts of the EU under GDPR). If you believe a child has provided us data, contact us and we will delete it.
10.Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. AI output generated by the Service is informational and requires your review; see the "No financial advice" section of our Terms.
11.Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email.
12.Contact
Questions or requests about this policy, including GDPR/CCPA rights requests, should be sent to support@cearsi.dev. The data controller for personal information processed under this policy is Cearsi AI. If you are located in the EEA or UK and would like to reach us regarding data protection, please use the same address and mark your message "Attn: Data Protection."
