Privacy Policy

Effective Date[TBD — set on publish]
Last Updated[TBD — set on publish]
Versionv0.2
ControllerCronosPMC LLC (UAE formation no. 2219381), Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates ("CronosPMC", "we")
Regulatory regimeCronosPMC is established in Sharjah Media City Freezone (SHAMS) and is therefore subject to UAE Federal PDPL (Decree-Law No. 45/2021). Governing law of the contract with you is DIFC (per Terms §17) — see §2 for the distinction. For your data, additionally: EU GDPR / UK GDPR / CCPA + 19 other US state laws / India DPDP / Saudi PDPL / Australia Privacy Act / Brazil LGPD where you are resident in those jurisdictions.
Privacy OfficerSyed Hasan — [TBD: privacy@[domain]]
EU Article 27 Representative[TBD: required per Audit.md §2. Recommend appointing via a commercial provider (Prighter, Maetzler, EU DPO Service; ~€500–1,500/yr). The Art. 27(2) exemption does not apply to a continuous-paid-B2C-AI-SaaS targeting EU users.]
UK Article 27 Representative[TBD: separate appointment from EU rep, post-Brexit. Same vendor options. ~£500–1,500/yr.]
Brazil "encarregado" (DPO)[TBD: needed once Brazilian users > ~5,000 per Audit.md §F; small-business waiver available under ANPD.]
Saudi Arabia Local Representative[TBD: needed once KSA users > ~1,000 per Audit.md §F; SDAIA SCC registration in parallel.]
Contact (privacy)[TBD: privacy@[domain]]
Contact (security disclosure)[TBD: security@[domain] + /.well-known/security.txt]

1. Summary (layered notice)

This summary is a high-level overview. The full long-form notice begins at §2 and is the legally controlling text. We provide both because GDPR Art. 13/14, UK GDPR Art. 13/14, CCPA §1798.100(b), UAE PDPL Art. 13, and India DPDP §5 each require specific disclosures and we want both readability and completeness.

You give usWe use it toWho else sees itWe keep it
Email addressAuthenticate, send service emailsSupabase (auth), Resend/Postmark (email delivery)Until account deletion
Display name / avatarShow your name in the UISupabaseUntil account deletion or you remove it
OpenRouter API key (optional)Make AI calls on your behalfEncrypted at rest with AES-256-GCM; decrypted in-memory only when servicing your requestUntil you remove it or delete account
Prompts and debate sessionsProvide the Service, show your historyStored in Supabase; sent to OpenRouter and the LLM provider(s) you selectUntil you delete the session or your account
Payment data (card, billing address)Process subscriptionsStripe (independent controller); we never see full card detailsPer Stripe's retention rules + tax-law requirements
Telemetry (request times, IP, country, errors)Detect abuse, fix bugs, enforce rate limitsSentry (errors), Vercel (request logs), Upstash (rate limits)30–90 days per Sub-Processor

You can export everything we hold about you or delete your account at any time from the Settings page — or by emailing [TBD: privacy contact].


2. Who We Are

We are CronosPMC LLC, a UAE limited-liability company (formation no. 2219381) with registered office at Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates ("CronosPMC", "we", "us", "our"). We operate the Service called Model Council. We are the data controller for personal data processed in connection with the Service, except where indicated otherwise (e.g. Stripe is an independent controller for payment data, see §5.2).

Two distinct legal lenses apply. First, the regulatory regime that primarily governs our processing operations: because CronosPMC is established in Sharjah Media City Freezone (a UAE freezone that does not have its own data protection law), we sit under the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45/2021, "UAE PDPL"). Second, the governing law of our contract with you is the Dubai International Financial Centre (DIFC) (per Terms §17); DIFC law governs the interpretation and enforcement of the Terms, but does not displace your local data-protection rights.

This Policy is consistent with — and gives effect to your rights under — UAE PDPL, UK GDPR + Data Protection Act 2018 + Data (Use and Access) Act 2025, EU GDPR (Regulation 2016/679), CCPA/CPRA + 19 other US state privacy laws, India DPDP Act 2023 + DPDP Rules 2025, Saudi PDPL (Royal Decree M/19), Australian Privacy Act 1988 (as amended 2024), and Brazilian LGPD, each according to your place of habitual residence and the relevant law's territorial scope.

3. What We Collect and Why

3.1 Information You Provide Directly

DataPurposeLegal basis — GDPR/UK GDPROther-law footing
Email address (required)Account creation, auth, transactional emailsContract (Art. 6(1)(b))UAE PDPL Art. 5 (contractual necessity); DPDP §6 (consent + necessary uses); CCPA business purpose
Display name, avatarDisplay in UIContractSame
OpenRouter API key (optional)Forwarded to OpenRouter for AI calls on your behalfContractSame
Prompts, debate session contentGenerate the Service's core outputContractSame
Profile preferencesPersonalize the ServiceContractSame
Payment data (collected by Stripe)Process paymentsContract; Stripe is an independent controller (§5.2)Same
Customer support correspondenceResolve your queriesLegitimate interests (Art. 6(1)(f)) — handling supportUAE PDPL Art. 5(b); DPDP §7(b) "specified purpose"

3.2 Information Collected Automatically

DataPurposeLegal basis
IP addressRate limiting, abuse detection, securityLegitimate interests (Art. 6(1)(f)) — preventing fraud and abuse; documented LIA available on request
Approximate geolocation (country, region, city from IP via Vercel Edge)Multi-account abuse detection on Free tier; regional compliance routingLegitimate interests
User agent, request timestampsDebugging, abuse detectionLegitimate interests
Crash and error data (Sentry)Diagnose and fix bugsLegitimate interests
Strictly necessary cookies (session, theme, consent state)Required to operate the ServiceStrictly necessary (no consent required under PECR / ePrivacy)
Non-essential cookies and similar storageAnalytics; AI session replay (Paid tier only)Consent only — per PECR (as amended by DUAA 2025, in force 5 Feb 2026, max fine £17.5M / 4% turnover). See §10 and our Cookie Policy.

3.3 Information We Do Not Collect

  • We do not knowingly collect personal data from anyone under 16 years (aligned with strictest GDPR Member State threshold).
  • We do not solicit GDPR Art. 9 / UK Art. 9 special-category personal data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation, genetic data). Our Terms §6(j) prohibit you from submitting such data in prompts. If you nonetheless input it we will process it under heightened security but cannot retrospectively prevent it reaching the LLM provider you selected; please redact before submitting.
  • We do not use third-party advertising trackers, retargeting pixels, or sell personal data to advertisers.

4. AI Processing of Your Prompts

When you submit a prompt:

  1. The prompt is stored in our database (Supabase) for your debate history.
  2. The prompt is sent to OpenRouter (an LLM-aggregation gateway operating under New York-law Terms with an incorporated DPA), which forwards it to one or more LLM providers you select.
  3. The selected provider(s) process the prompt and return responses. Provider treatment varies materially — see §4.1 below.
  4. Responses are returned through OpenRouter to us, stored in your session, and shown to you.

4.1 Per-Provider Processing (this is the audit-corrected section)

The legal relationship between you, us, and each AI provider differs by provider and is not uniform. The audit identified that some providers act as processors only under a signed commercial DPA, while others act as independent controllers and may train on your inputs. We therefore disclose each route individually.

ProviderRole w/r/t your promptsTraining on inputs (default)Retention (default)Where they processNotes
OpenRouterSub-processor (commercial DPA incorporated by reference into Terms)No (Zero-Data-Retention by default; opt-in logging available)Per provider's commercial DPA; OpenRouter does not retainUS-based; routes globallySee OpenRouter DPA. Each downstream provider classified separately.
Anthropic (Claude family)Processor under Anthropic Commercial DPA when accessed via commercial API. Source: Anthropic Privacy Center — "When a commercial customer creates a Claude for Work account… the customer is the 'Controller'… Anthropic acts as a 'Processor' of the data on behalf of the customer."No — Anthropic does not use commercial API data to train its modelsUp to 30 days for abuse detection then deleted; longer for trust-and-safety holdsUS (with EU/UK regional options on Workspaces)We rely on Anthropic's commercial terms
OpenAI (GPT family)Processor under OpenAI DPA when accessed via API. Source: OpenAI Enterprise Privacy — "OpenAI will retain API Service Customer Data sent through the API for a maximum of thirty (30) days, after which it will be deleted."No (API tier; ChatGPT consumer tier differs and is not what we use)30 days (rolling), then deletedUSWe rely on OpenAI's API terms
Google (Gemini family)Processor under Google Cloud / Vertex AI termsNo (API tier with appropriate plan)Per Google Cloud retentionUS, EU (request-dependent)We route via [TBD: region]
xAI (Grok family)Likely independent controller. xAI's commercial-API terms typically reserve rights to use Inputs/Outputs for model improvement unless an enterprise ZDR contract is in force.Possibly yes — assume yes unless we have notified you otherwisePer xAI policyUSIf you select this model, your prompt is being shared with a controller that may train on it. We display a warning in the model picker.
Any other model selectedPer that provider's terms — surfaced in the model picker before submissionPer that provider's policyPer that provider's policyVariesWe do not assume processor status for any provider absent contractual evidence.

No training warranty (where contractually obtained): For Anthropic, OpenAI, and Google API endpoints, we represent that under the commercial terms we use, your prompts are not used to train provider models. We obtain no such warranty for xAI/Grok or other "permissive" endpoints; we will not lie about that.

What this means for you, in practice. If you submit a prompt containing anything you would not want a model provider to retain or improve their models on, do not select xAI/Grok (or any other endpoint we flag as a controller-relationship). Use only the Anthropic/OpenAI/Google routes for sensitive content.

5. Service Providers (this section is materially restructured per audit)

We use two distinct categories of provider. Different legal relationship; different downstream risk.

5.1 Sub-Processors

These providers act as our processors under signed Data Processing Agreements. They process personal data only on our documented instructions and do not use it for their own purposes.

Sub-processorFunctionRegion(s) of processingSafeguards
Supabase, Inc.Database, authentication, file storageEU West / Paris (eu-west-3) — primaryDPA signed; SCCs (Module 2) for any US-corp processor obligations
Vercel Inc.Hosting, edge network, request logsUS, EU (request-dependent edge)DPA signed; SCCs
Sentry (Functional Software, Inc.)Error and performance monitoringUS, EUDPA signed; SCCs; PII scrubbing configured
Upstash Inc.Rate-limit Redis store (no PII content; user-ID keys only)EU West / Ireland (eu-west-1)DPA
SendGrid (Twilio SendGrid)Transactional email delivery (magic links, account notifications)US, EUDPA signed via Twilio MSA; SCCs
OpenRouter, Inc.LLM API gateway (no input/output retention by default)USDPA (incorporated by reference into Terms); per-route handling per §4.1

5.2 Independent Controllers

These parties process personal data on their own terms for their own purposes. We do not control their processing and you may need to refer to their privacy policies directly.

PartyFunctionTheir privacy policy
Stripe, Inc.Payment processing — Stripe collects card data, address, and tax information directly from you. We never see full card numbers.https://stripe.com/privacy
xAI (and any other "Permissive" LLM endpoint identified in §4.1)LLM inference where the provider acts as a controller and may use inputs to improve their servicePer that provider's policy at the time of model selection
Anthropic, OpenAI, GoogleLLM providers in their consumer-tier or non-DPA-covered capacities. Note: under our current configuration (commercial API + DPA), these providers act as processors as described in §4.1. They become independent controllers only if we step outside DPA-covered terms, which we currently do not do.Per that provider's policy

A current sub-processor list is maintained on this page. Material additions or changes will be notified by email to active subscribers with 30 days' notice unless the change is required by law or to protect security.

6. International Data Transfers

Personal data may cross borders during normal Service operation. The audit recommended naming each corridor and the legal mechanism in use. We do.

CorridorMechanismNotes
Your country → our infrastructure (Supabase EU West / Paris; Vercel edge)For EU/UK users: intra-EEA / EEA→adequate. For non-EEA users: standard cross-border processing by your consent + contract necessity.We chose eu-west-3 for data minimization
EU/UK → our entity (UAE/DIFC)EU Commission 2021 SCCs Module 1 (controller-to-controller) + Schrems II Transfer Impact Assessment ("TIA"). UK IDTA or EU SCCs + UK Addendum for UK transfers.TIA available on request to privacy@[TBD]
Our infrastructure → Anthropic / OpenAI / Google (LLM APIs, US)Module 2 SCCs (controller-to-processor) under their respective commercial DPAs. Schrems II TIA on file.These providers' DPAs incorporate the SCCs
Our infrastructure → xAI / other independent-controller LLMModule 1 SCCs (controller-to-controller) where signed; consent + transparency where notSee §4.1 — we flag these endpoints at model-selection time
UAE → EU/UK/USUAE PDPL Art. 22 — your explicit informed consent at signup constitutes the lawful basis; UAE-style SCCs added for processor relationships once published by UAE Data OfficeStatus of UAE Executive Regulations: pending per DLA Piper Jan 2025
Saudi Arabia → outside KSASDAIA-approved SCCs (mandatory since Aug 2024)Applies only to KSA users
Brazil → outside BrazilANPD Standard Contractual Clauses (Portuguese, full text, no modifications). Grace period ended 23 August 2025 per ANPD Resolution CD/ANPD No. 19/2024.Applies only to Brazilian users
India → outside IndiaDPDP "negative list" — currently no countries restricted (Feb 2026); we monitor MeitY notificationsApplies only to Indian users

7. Retention

CategoryRetention
Account data (profile, email)Until you delete your account; immediately purged on deletion
Debate sessions and prompts (your copy in our DB)Until you delete the session or your account
OpenRouter API key (encrypted)Until you remove it from Settings or delete your account
Provider-side retention of promptsPer each provider's policy in §4.1 (typically 30 days for Anthropic/OpenAI/Google API; varies for xAI)
Payment recordsPer Stripe + applicable tax/accounting law in our jurisdiction (typically 7 years from transaction)
Vercel logs30 days
Sentry errors90 days
Upstash rate-limit keysSliding-window expiry (max 24 hours)
Abuse-detection signals (IP, country, region, city, hashed user-agent, per-request)90 days rolling, then automatically pruned. Used only for the multi-account velocity rule in §13 (Free-tier abuse prevention). Never sold or shared.
Aggregated, anonymized analyticsIndefinite — no personal data

We may retain certain data after account deletion where required by law (e.g. payment records for tax compliance) or for the establishment, exercise, or defence of legal claims.

8. Your Rights — Jurisdiction Matrix

Different laws give you different rights and different response timelines. We honour each. To exercise any right, use the Settings page (Export My Data / Delete Account) or email [TBD: privacy contact]. We may verify your identity before responding.

RightEU/UK GDPRCCPA/CPRAUAE PDPLIndia DPDPSaudi PDPLAustraliaBrazil LGPD
Access / copy✅ Art. 15✅ §1798.100✅ Art. 13✅ §11✅ Art. 4✅ APP 12✅ Art. 18
Rectification✅ Art. 16✅ (correction)✅ Art. 15✅ §13✅ APP 13
Erasure✅ Art. 17✅ (deletion)✅ Art. 16✅ §13
Restriction✅ Art. 18n/a✅ Art. 17n/an/a
Objection✅ Art. 21✅ (opt-out)✅ Art. 18✅ §13(c)n/a
Portability✅ Art. 20 (JSON export)✅ (portability)✅ Art. 14n/an/a
Withdraw consent✅ Art. 7(3)n/a✅ Art. 6(3)✅ §6(4)n/a
Complaint to authorityICO (UK); your member state DPA (EU)CPPA / state AGUAE Data OfficeData Protection Board of IndiaSDAIAOAICANPD
Solely-automated decisions (Art. 22-equivalent)✅ Art. 22 (see §13)✅ ADMT regs (2026)✅ Art. 19n/a (until rules)✅ (Dec 2026)
Response timeline30 days (extendable by 60 for complex)45 days (extendable by 45)30 days"Reasonable period"; Consent Managers within 90 days30 days30 days15 days for access

9. California-Specific Disclosures (CCPA/CPRA + ADMT Regulations)

In addition to the rights in §8, California residents:

  • Have the right to know the categories of personal information collected, sold, and disclosed (none sold — we do not sell personal information).
  • Have the right to opt out of "sale" or "sharing." We do not "sell" or "share" personal information in the CCPA/CPRA sense.
  • Have a right of non-discrimination for exercising any CCPA right.
  • Are subject to the CPPA's ADMT (Automated Decision-Making Technology) regulations that took effect 1 January 2026. We are not currently using ADMT to make "significant decisions" about you (see §13). If we ever do, we will provide the required pre-use ADMT notice and the right to opt out.
  • We honour Global Privacy Control (GPC) signals (mandatory in CA, CO, CT, MT, NH, NE, TX, NJ, MN, MD, OR, DE).

10. Cookies and Similar Technologies

We classify cookies and similar storage as either strictly necessary (no consent required under PECR / ePrivacy / equivalent) or non-essential (consent required). Equal Reject/Accept prominence is provided on our consent banner.

TypePurposeConsent
Session cookie (Supabase Auth)Keep you logged inStrictly necessary
Theme preference (localStorage)Remember dark/light modeStrictly necessary
Consent state (localStorage)Remember your cookie consent choiceStrictly necessary
Sentry session replay (Paid tier only)Diagnose user-reported bugsConsent required
Performance/error metrics with personal dataDiagnose bugsConsent required

Full granular categories, retention, third-party setters, and your right to withdraw consent are in our separate Cookie Policy as required by PECR (UK, post-DUAA 2025), ePrivacy Directive (EU), and ICO guidance.

11. Security

We protect your data using:

  • TLS 1.3 in transit
  • AES-256 encryption at rest (Supabase managed)
  • AES-256-GCM application-level encryption of OpenRouter API keys (above-disk encryption, decryption only in-memory when servicing your request — F-06 in our production-readiness plan)
  • Row-Level Security (RLS) policies isolating users' data at the database layer
  • Column-level grants preventing user roles from modifying billing or system-controlled fields
  • Per-user rate limits (5/min, 100/day on AI requests; 10/min on payment endpoints; 5/hr per IP on auth)
  • Multi-account abuse detection (IP / geolocation velocity) — see Terms §5
  • Stripe-tokenized payment data; we never see full card numbers
  • Coordinated vulnerability disclosure programme (SECURITY.md / /.well-known/security.txt)
  • Quarterly security review and dependency audit

Breach notification. In the event of a personal data breach we will notify the relevant supervisory authority and affected individuals as required:

Authority / regimeTimeline
UAE Data Office (PDPL Art. 9)Without undue delay; typically within 72 hours
Lead EU Supervisory Authority (GDPR Art. 33)Within 72 hours of becoming aware
ICO (UK GDPR Art. 33)Within 72 hours
Data Protection Board of India (DPDP)Without delay; detailed report within 72 hours; affected individuals notified without delay
ANPD (Brazil LGPD)In a reasonable time period (ANPD has indicated 2 working days as the benchmark)
OAIC (Australia, Notifiable Data Breaches scheme)Without delay; 30 days outer limit
SDAIA (Saudi PDPL)Per regulations
Affected individualsWithout undue delay where likely to result in high risk to their rights

12. Children

The Service is not directed at and we do not knowingly process personal data from anyone under 16 years. If you believe a child has provided personal data, please contact us at the privacy address in §17 and we will delete it. For US users under 13, COPPA additionally requires verifiable parental consent before we collect any personal information; in that case we will refuse the account.

If you are between [TBD] and 18 in a jurisdiction with an "Age Appropriate Design Code" (e.g. UK), we apply privacy-by-default settings and do not engage in profiling of you for purposes that could be detrimental to your wellbeing.

13. Automated Decision-Making (clarified per audit)

We do not engage in solely automated decision-making producing legal or similarly significant effects on you within the meaning of GDPR Art. 22 / UK GDPR Art. 22 / UAE PDPL Art. 19 / equivalents. The AI debate-synthesis outputs you receive are presented for your evaluation and you remain the decision-maker as to whether and how to act on them.

Our abuse-detection signals (multi-account velocity rules under §3.2, rate limiting under §11) may automatically restrict or rate-limit specific Free tier requests. These restrictions do not produce legal effects on you; you may appeal any such restriction by contacting [TBD: support contact] and a human will review.

Reserve clause. Model Council is a research and ideation tool. Outputs are not a substitute for professional advice and must not be used as the sole basis for any decision producing legal or similarly significant effects on individuals (e.g. employment, housing, lending, insurance, healthcare, or other "consequential decisions" within the meaning of the Colorado AI Act SB 24-205, Texas TRAIGA, or CPPA ADMT regulations). If you intend such use, contact us about a separate enterprise contract — under your standard B2C/B2B account, such use is prohibited by Terms §6(k).

14. AI Training Opt-Out

Even though we do not train any models on your prompts (see §4 — no training warranty against Anthropic/OpenAI/Google commercial routes), users frequently ask:

  • We do not use your prompts to train any model.
  • We do not sell or transfer your prompts for training by third parties.
  • We disclose where the LLM provider you select may itself train on your inputs (§4.1) — and we do this before you submit.
  • If you wish to additionally instruct us to disable any future training-related processing (e.g. if law changes), contact [TBD: privacy contact] and we will record your preference. Effect of the preference is "do not enable training" rather than "withdraw past training" because providers like Anthropic/OpenAI/Google already do not train on commercial API inputs.

15. Responsible Disclosure

If you discover a security vulnerability in the Service, please report it via:

  • Email: [TBD: security@[domain]]
  • .well-known/security.txt: published at https://[domain]/.well-known/security.txt
  • 90-day coordinated disclosure window; we will acknowledge within 5 working days and provide status updates

We do not pursue legal action against good-faith security researchers who comply with the disclosure policy.

16. Changes to This Policy

Material changes will be notified by email to active users at least 14 days before they take effect (GDPR Art. 13(3) and equivalent). The "Last Updated" date above will be revised. The most recent version is always at the policy URL.

A change log of substantive amendments is maintained at the foot of the policy and on GitHub (docs/legal/PRIVACY.md change history) for transparency.

17. Contact

For privacy questions, rights requests, or DPA negotiations:

  • General: [TBD: privacy@[domain]]
  • Security disclosure: [TBD: security@[domain]]
  • Data subject requests (DSAR): [TBD: privacy@[domain] — DSAR Portal coming with F-08 in our production-readiness plan]
  • EU Article 27 Representative: [TBD: vendor name + EU contact address]
  • UK Article 27 Representative: [TBD: vendor name + UK contact address]
  • Privacy Officer: [TBD: name + email]
  • Postal: CronosPMC LLC, Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates