Legal

Privacy Policy

What we collect, how we use it, how long we keep it, and the rights you have over it. For a plain-language overview of how ceadr is built, isolated, and secured, see our Trust & Security page.

Last updated: July 2026 · Contact julian@ceadr.ai

1.What We Collect

When you use ceadr, we process the following data:

  • Document content from sources you connect (Google Drive, Notion, Confluence, Slack, GitHub, Jira) or files you upload. To make your knowledge queryable by AI agents, ceadr is a persistent knowledge platform: document content is split into chunks, embedded as vectors, and stored so it can be retrieved and cited. A durable knowledge graph (entities, relationships, and cited excerpts) is built from it. Stored content is encrypted at rest and isolated to your workspace.
  • Connection credentials. OAuth connections to external services are brokered by Nango. Where a connection is brokered by Nango, ceadr stores a connection reference rather than your provider access token, and retrieves a short-lived token from Nango only when a scan runs.
  • Account and authentication data via our authentication provider, Clerk (user identifier, email, and session metadata) to sign you in and associate your workspaces.
  • Analysis results (scores, extracted knowledge, contradictions, and metadata) stored in your workspace so the dashboards, ontology, and agent API can use them.
  • Document metadata such as filenames, titles, word counts, and author names as provided by source connectors.

2.How We Use Your Data

  • Score documents for quality, completeness, and AI readiness
  • Detect contradictions across your knowledge base
  • Identify gaps against industry templates
  • Build knowledge ontologies (entity and relationship extraction)
  • Serve cited answers to the AI agents you connect to your workspace
  • Generate audit reports and executive summaries

We do not sell your data, and we do not use your content to train our own models. Content sent to Anthropic's Claude API is not used by Anthropic to train models.

3.Sub-processors

ceadr engages the following sub-processors to deliver the service. Each receives only the data it needs for its stated purpose. We give 30 days notice before adding a new sub-processor. To object, email julian@ceadr.ai.

  • Anthropic

    policy

    Claude API for scoring, contradiction detection, ontology, summaries. API inputs are not used to train models.

    United States

  • AssemblyAI

    policy

    Audio transcription with speaker diarization and chapter summaries.

    United States

  • OpenAI

    policy

    Optional fallback path for audio transcription via Whisper. The MCP deployment helper also references OpenAI as one of the supported agent endpoints.

    United States

  • Voyage AI

    policy

    Embedding model for document chunks (semantic search and contradiction pairing).

    United States

  • Nango

    policy

    OAuth brokerage and proxied API access to your connected SaaS providers (Google, Notion, Atlassian, Slack, GitHub, Jira).

    United States

  • Clerk

    policy

    Authentication and session management. Stores user identifier, email, and session metadata.

    United States

  • Resend

    policy

    Transactional email (workspace invites, agent notifications, writeback confirmations).

    United States

  • PostHog

    policy

    Product analytics and pageview capture. Only loaded when the visitor opts in via the cookie banner.

    United States

  • Sentry

    policy

    Error and performance reporting (browser + backend). Only loaded when the visitor opts in via the cookie banner.

    United States

  • Google (Calendar Appointments)

    policy

    Booking links for the demo / discovery call flow on the marketing site. Calendar bookings are scheduled directly with Google.

    United States, multi-region edge

  • Vercel

    policy

    Hosting for the ceadr.ai web application. Receives all frontend traffic and edge logs.

    United States, multi-region edge

  • Railway

    policy

    Hosting for the ceadr API engine and worker processes.

    United States

  • Supabase

    policy

    Managed Postgres for workspace metadata, audit log, and contradiction excerpts.

    Configurable per project, defaults to United States

When you connect external sources, your connection is used to access data from Google, Notion, Atlassian, Slack, or GitHub on your behalf. We only read data unless you explicitly approve a writeback action.

Analytics (PostHog) and error reporting (Sentry) are loaded only when you opt in through the cookie banner. You can revisit your choice at any time: .

4.Data Retention

  • Document content and derived knowledge: Chunks, embeddings, extracted entities, and cited excerpts are stored for as long as your workspace is active, so agents can query your knowledge with citations. They are deleted when you erase the underlying data or delete your workspace.
  • Analysis results: Stored for the life of your workspace and removed on erasure or workspace deletion.
  • Connection credentials: Held by Nango. Revoking a connection, or deleting your workspace, removes ceadr's access.
  • Account data: Retained while your account is active (managed via Clerk).

5.Your Rights

To exercise your data subject rights under GDPR Articles 15 to 22 (access, rectification, erasure, portability, restriction, objection), email julian@ceadr.ai. We respond within 30 days. Workspace admins can also open export and erasure requests directly from the workspace settings.

CCPA and UK DPA 2018 requests follow the same path.

6.Cookies

We use strictly necessary cookies to keep you signed in and maintain your session, including cookies set by our authentication provider, Clerk. We do not use advertising or cross-site tracking cookies. We use product analytics (PostHog) and error reporting (Sentry) only when you opt in through the cookie banner (see section 3 to change or withdraw that choice).

7.Cross Border Transfers

Document content is processed by Anthropic's Claude AI, which operates in the United States. Our infrastructure providers (see the sub-processor table above) and OAuth connections to Google, Notion, Atlassian, Slack, and GitHub may also involve data transfer to US based servers. These transfers are governed by the respective providers' data processing agreements.

8.Security

  • Stored content is encrypted at rest and isolated per workspace by database row-level security
  • Secrets and connection credentials are encrypted at rest
  • Session cookies are HttpOnly and Secure
  • Authentication on every endpoint (Clerk sessions for the app, bearer tokens for the agent API)
  • Rate limiting on sensitive operations
  • Every privileged action is recorded in a tamper-evident, append-only audit log

9.Contact

For privacy inquiries or to exercise your data rights, email julian@ceadr.ai.