| Effective Date | [TBD — set on publish] |
| Last Updated | [TBD — set on publish] |
| Version | v0.2 |
| Controller | CronosPMC LLC (UAE formation no. 2219381), Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates ("CronosPMC", "we") |
| Regulatory regime | CronosPMC is established in Sharjah Media City Freezone (SHAMS) and is therefore subject to UAE Federal PDPL (Decree-Law No. 45/2021). Governing law of the contract with you is DIFC (per Terms §17) — see §2 for the distinction. For your data, additionally: EU GDPR / UK GDPR / CCPA + 19 other US state laws / India DPDP / Saudi PDPL / Australia Privacy Act / Brazil LGPD where you are resident in those jurisdictions. |
| Privacy Officer | Syed Hasan — [TBD: privacy@[domain]] |
| EU Article 27 Representative | [TBD: required per Audit.md §2. Recommend appointing via a commercial provider (Prighter, Maetzler, EU DPO Service; ~€500–1,500/yr). The Art. 27(2) exemption does not apply to a continuous-paid-B2C-AI-SaaS targeting EU users.] |
| UK Article 27 Representative | [TBD: separate appointment from EU rep, post-Brexit. Same vendor options. ~£500–1,500/yr.] |
| Brazil "encarregado" (DPO) | [TBD: needed once Brazilian users > ~5,000 per Audit.md §F; small-business waiver available under ANPD.] |
| Saudi Arabia Local Representative | [TBD: needed once KSA users > ~1,000 per Audit.md §F; SDAIA SCC registration in parallel.] |
| Contact (privacy) | [TBD: privacy@[domain]] |
| Contact (security disclosure) | [TBD: security@[domain] + /.well-known/security.txt] |
1. Summary (layered notice)
This summary is a high-level overview. The full long-form notice begins at §2 and is the legally controlling text. We provide both because GDPR Art. 13/14, UK GDPR Art. 13/14, CCPA §1798.100(b), UAE PDPL Art. 13, and India DPDP §5 each require specific disclosures and we want both readability and completeness.
| You give us | We use it to | Who else sees it | We keep it |
|---|---|---|---|
| Email address | Authenticate, send service emails | Supabase (auth), Resend/Postmark (email delivery) | Until account deletion |
| Display name / avatar | Show your name in the UI | Supabase | Until account deletion or you remove it |
| OpenRouter API key (optional) | Make AI calls on your behalf | Encrypted at rest with AES-256-GCM; decrypted in-memory only when servicing your request | Until you remove it or delete account |
| Prompts and debate sessions | Provide the Service, show your history | Stored in Supabase; sent to OpenRouter and the LLM provider(s) you select | Until you delete the session or your account |
| Payment data (card, billing address) | Process subscriptions | Stripe (independent controller); we never see full card details | Per Stripe's retention rules + tax-law requirements |
| Telemetry (request times, IP, country, errors) | Detect abuse, fix bugs, enforce rate limits | Sentry (errors), Vercel (request logs), Upstash (rate limits) | 30–90 days per Sub-Processor |
You can export everything we hold about you or delete your account at any time from the Settings page — or by emailing [TBD: privacy contact].
2. Who We Are
We are CronosPMC LLC, a UAE limited-liability company (formation no. 2219381) with registered office at Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates ("CronosPMC", "we", "us", "our"). We operate the Service called Model Council. We are the data controller for personal data processed in connection with the Service, except where indicated otherwise (e.g. Stripe is an independent controller for payment data, see §5.2).
Two distinct legal lenses apply. First, the regulatory regime that primarily governs our processing operations: because CronosPMC is established in Sharjah Media City Freezone (a UAE freezone that does not have its own data protection law), we sit under the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45/2021, "UAE PDPL"). Second, the governing law of our contract with you is the Dubai International Financial Centre (DIFC) (per Terms §17); DIFC law governs the interpretation and enforcement of the Terms, but does not displace your local data-protection rights.
This Policy is consistent with — and gives effect to your rights under — UAE PDPL, UK GDPR + Data Protection Act 2018 + Data (Use and Access) Act 2025, EU GDPR (Regulation 2016/679), CCPA/CPRA + 19 other US state privacy laws, India DPDP Act 2023 + DPDP Rules 2025, Saudi PDPL (Royal Decree M/19), Australian Privacy Act 1988 (as amended 2024), and Brazilian LGPD, each according to your place of habitual residence and the relevant law's territorial scope.
3. What We Collect and Why
3.1 Information You Provide Directly
| Data | Purpose | Legal basis — GDPR/UK GDPR | Other-law footing |
|---|---|---|---|
| Email address (required) | Account creation, auth, transactional emails | Contract (Art. 6(1)(b)) | UAE PDPL Art. 5 (contractual necessity); DPDP §6 (consent + necessary uses); CCPA business purpose |
| Display name, avatar | Display in UI | Contract | Same |
| OpenRouter API key (optional) | Forwarded to OpenRouter for AI calls on your behalf | Contract | Same |
| Prompts, debate session content | Generate the Service's core output | Contract | Same |
| Profile preferences | Personalize the Service | Contract | Same |
| Payment data (collected by Stripe) | Process payments | Contract; Stripe is an independent controller (§5.2) | Same |
| Customer support correspondence | Resolve your queries | Legitimate interests (Art. 6(1)(f)) — handling support | UAE PDPL Art. 5(b); DPDP §7(b) "specified purpose" |
3.2 Information Collected Automatically
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Rate limiting, abuse detection, security | Legitimate interests (Art. 6(1)(f)) — preventing fraud and abuse; documented LIA available on request |
| Approximate geolocation (country, region, city from IP via Vercel Edge) | Multi-account abuse detection on Free tier; regional compliance routing | Legitimate interests |
| User agent, request timestamps | Debugging, abuse detection | Legitimate interests |
| Crash and error data (Sentry) | Diagnose and fix bugs | Legitimate interests |
| Strictly necessary cookies (session, theme, consent state) | Required to operate the Service | Strictly necessary (no consent required under PECR / ePrivacy) |
| Non-essential cookies and similar storage | Analytics; AI session replay (Paid tier only) | Consent only — per PECR (as amended by DUAA 2025, in force 5 Feb 2026, max fine £17.5M / 4% turnover). See §10 and our Cookie Policy. |
3.3 Information We Do Not Collect
- We do not knowingly collect personal data from anyone under 16 years (aligned with strictest GDPR Member State threshold).
- We do not solicit GDPR Art. 9 / UK Art. 9 special-category personal data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation, genetic data). Our Terms §6(j) prohibit you from submitting such data in prompts. If you nonetheless input it we will process it under heightened security but cannot retrospectively prevent it reaching the LLM provider you selected; please redact before submitting.
- We do not use third-party advertising trackers, retargeting pixels, or sell personal data to advertisers.
4. AI Processing of Your Prompts
When you submit a prompt:
- The prompt is stored in our database (Supabase) for your debate history.
- The prompt is sent to OpenRouter (an LLM-aggregation gateway operating under New York-law Terms with an incorporated DPA), which forwards it to one or more LLM providers you select.
- The selected provider(s) process the prompt and return responses. Provider treatment varies materially — see §4.1 below.
- Responses are returned through OpenRouter to us, stored in your session, and shown to you.
4.1 Per-Provider Processing (this is the audit-corrected section)
The legal relationship between you, us, and each AI provider differs by provider and is not uniform. The audit identified that some providers act as processors only under a signed commercial DPA, while others act as independent controllers and may train on your inputs. We therefore disclose each route individually.
| Provider | Role w/r/t your prompts | Training on inputs (default) | Retention (default) | Where they process | Notes |
|---|---|---|---|---|---|
| OpenRouter | Sub-processor (commercial DPA incorporated by reference into Terms) | No (Zero-Data-Retention by default; opt-in logging available) | Per provider's commercial DPA; OpenRouter does not retain | US-based; routes globally | See OpenRouter DPA. Each downstream provider classified separately. |
| Anthropic (Claude family) | Processor under Anthropic Commercial DPA when accessed via commercial API. Source: Anthropic Privacy Center — "When a commercial customer creates a Claude for Work account… the customer is the 'Controller'… Anthropic acts as a 'Processor' of the data on behalf of the customer." | No — Anthropic does not use commercial API data to train its models | Up to 30 days for abuse detection then deleted; longer for trust-and-safety holds | US (with EU/UK regional options on Workspaces) | We rely on Anthropic's commercial terms |
| OpenAI (GPT family) | Processor under OpenAI DPA when accessed via API. Source: OpenAI Enterprise Privacy — "OpenAI will retain API Service Customer Data sent through the API for a maximum of thirty (30) days, after which it will be deleted." | No (API tier; ChatGPT consumer tier differs and is not what we use) | 30 days (rolling), then deleted | US | We rely on OpenAI's API terms |
| Google (Gemini family) | Processor under Google Cloud / Vertex AI terms | No (API tier with appropriate plan) | Per Google Cloud retention | US, EU (request-dependent) | We route via [TBD: region] |
| xAI (Grok family) | Likely independent controller. xAI's commercial-API terms typically reserve rights to use Inputs/Outputs for model improvement unless an enterprise ZDR contract is in force. | Possibly yes — assume yes unless we have notified you otherwise | Per xAI policy | US | If you select this model, your prompt is being shared with a controller that may train on it. We display a warning in the model picker. |
| Any other model selected | Per that provider's terms — surfaced in the model picker before submission | Per that provider's policy | Per that provider's policy | Varies | We do not assume processor status for any provider absent contractual evidence. |
No training warranty (where contractually obtained): For Anthropic, OpenAI, and Google API endpoints, we represent that under the commercial terms we use, your prompts are not used to train provider models. We obtain no such warranty for xAI/Grok or other "permissive" endpoints; we will not lie about that.
What this means for you, in practice. If you submit a prompt containing anything you would not want a model provider to retain or improve their models on, do not select xAI/Grok (or any other endpoint we flag as a controller-relationship). Use only the Anthropic/OpenAI/Google routes for sensitive content.
5. Service Providers (this section is materially restructured per audit)
We use two distinct categories of provider. Different legal relationship; different downstream risk.
5.1 Sub-Processors
These providers act as our processors under signed Data Processing Agreements. They process personal data only on our documented instructions and do not use it for their own purposes.
| Sub-processor | Function | Region(s) of processing | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | EU West / Paris (eu-west-3) — primary | DPA signed; SCCs (Module 2) for any US-corp processor obligations |
| Vercel Inc. | Hosting, edge network, request logs | US, EU (request-dependent edge) | DPA signed; SCCs |
| Sentry (Functional Software, Inc.) | Error and performance monitoring | US, EU | DPA signed; SCCs; PII scrubbing configured |
| Upstash Inc. | Rate-limit Redis store (no PII content; user-ID keys only) | EU West / Ireland (eu-west-1) | DPA |
| SendGrid (Twilio SendGrid) | Transactional email delivery (magic links, account notifications) | US, EU | DPA signed via Twilio MSA; SCCs |
| OpenRouter, Inc. | LLM API gateway (no input/output retention by default) | US | DPA (incorporated by reference into Terms); per-route handling per §4.1 |
5.2 Independent Controllers
These parties process personal data on their own terms for their own purposes. We do not control their processing and you may need to refer to their privacy policies directly.
| Party | Function | Their privacy policy |
|---|---|---|
| Stripe, Inc. | Payment processing — Stripe collects card data, address, and tax information directly from you. We never see full card numbers. | https://stripe.com/privacy |
| xAI (and any other "Permissive" LLM endpoint identified in §4.1) | LLM inference where the provider acts as a controller and may use inputs to improve their service | Per that provider's policy at the time of model selection |
| Anthropic, OpenAI, Google | LLM providers in their consumer-tier or non-DPA-covered capacities. Note: under our current configuration (commercial API + DPA), these providers act as processors as described in §4.1. They become independent controllers only if we step outside DPA-covered terms, which we currently do not do. | Per that provider's policy |
A current sub-processor list is maintained on this page. Material additions or changes will be notified by email to active subscribers with 30 days' notice unless the change is required by law or to protect security.
6. International Data Transfers
Personal data may cross borders during normal Service operation. The audit recommended naming each corridor and the legal mechanism in use. We do.
| Corridor | Mechanism | Notes |
|---|---|---|
| Your country → our infrastructure (Supabase EU West / Paris; Vercel edge) | For EU/UK users: intra-EEA / EEA→adequate. For non-EEA users: standard cross-border processing by your consent + contract necessity. | We chose eu-west-3 for data minimization |
| EU/UK → our entity (UAE/DIFC) | EU Commission 2021 SCCs Module 1 (controller-to-controller) + Schrems II Transfer Impact Assessment ("TIA"). UK IDTA or EU SCCs + UK Addendum for UK transfers. | TIA available on request to privacy@[TBD] |
| Our infrastructure → Anthropic / OpenAI / Google (LLM APIs, US) | Module 2 SCCs (controller-to-processor) under their respective commercial DPAs. Schrems II TIA on file. | These providers' DPAs incorporate the SCCs |
| Our infrastructure → xAI / other independent-controller LLM | Module 1 SCCs (controller-to-controller) where signed; consent + transparency where not | See §4.1 — we flag these endpoints at model-selection time |
| UAE → EU/UK/US | UAE PDPL Art. 22 — your explicit informed consent at signup constitutes the lawful basis; UAE-style SCCs added for processor relationships once published by UAE Data Office | Status of UAE Executive Regulations: pending per DLA Piper Jan 2025 |
| Saudi Arabia → outside KSA | SDAIA-approved SCCs (mandatory since Aug 2024) | Applies only to KSA users |
| Brazil → outside Brazil | ANPD Standard Contractual Clauses (Portuguese, full text, no modifications). Grace period ended 23 August 2025 per ANPD Resolution CD/ANPD No. 19/2024. | Applies only to Brazilian users |
| India → outside India | DPDP "negative list" — currently no countries restricted (Feb 2026); we monitor MeitY notifications | Applies only to Indian users |
7. Retention
| Category | Retention |
|---|---|
| Account data (profile, email) | Until you delete your account; immediately purged on deletion |
| Debate sessions and prompts (your copy in our DB) | Until you delete the session or your account |
| OpenRouter API key (encrypted) | Until you remove it from Settings or delete your account |
| Provider-side retention of prompts | Per each provider's policy in §4.1 (typically 30 days for Anthropic/OpenAI/Google API; varies for xAI) |
| Payment records | Per Stripe + applicable tax/accounting law in our jurisdiction (typically 7 years from transaction) |
| Vercel logs | 30 days |
| Sentry errors | 90 days |
| Upstash rate-limit keys | Sliding-window expiry (max 24 hours) |
| Abuse-detection signals (IP, country, region, city, hashed user-agent, per-request) | 90 days rolling, then automatically pruned. Used only for the multi-account velocity rule in §13 (Free-tier abuse prevention). Never sold or shared. |
| Aggregated, anonymized analytics | Indefinite — no personal data |
We may retain certain data after account deletion where required by law (e.g. payment records for tax compliance) or for the establishment, exercise, or defence of legal claims.
8. Your Rights — Jurisdiction Matrix
Different laws give you different rights and different response timelines. We honour each. To exercise any right, use the Settings page (Export My Data / Delete Account) or email [TBD: privacy contact]. We may verify your identity before responding.
| Right | EU/UK GDPR | CCPA/CPRA | UAE PDPL | India DPDP | Saudi PDPL | Australia | Brazil LGPD |
|---|---|---|---|---|---|---|---|
| Access / copy | ✅ Art. 15 | ✅ §1798.100 | ✅ Art. 13 | ✅ §11 | ✅ Art. 4 | ✅ APP 12 | ✅ Art. 18 |
| Rectification | ✅ Art. 16 | ✅ (correction) | ✅ Art. 15 | ✅ §13 | ✅ | ✅ APP 13 | ✅ |
| Erasure | ✅ Art. 17 | ✅ (deletion) | ✅ Art. 16 | ✅ §13 | ✅ | ✅ | ✅ |
| Restriction | ✅ Art. 18 | n/a | ✅ Art. 17 | n/a | ✅ | n/a | ✅ |
| Objection | ✅ Art. 21 | ✅ (opt-out) | ✅ Art. 18 | ✅ §13(c) | ✅ | n/a | ✅ |
| Portability | ✅ Art. 20 (JSON export) | ✅ (portability) | ✅ Art. 14 | n/a | ✅ | n/a | ✅ |
| Withdraw consent | ✅ Art. 7(3) | n/a | ✅ Art. 6(3) | ✅ §6(4) | ✅ | n/a | ✅ |
| Complaint to authority | ICO (UK); your member state DPA (EU) | CPPA / state AG | UAE Data Office | Data Protection Board of India | SDAIA | OAIC | ANPD |
| Solely-automated decisions (Art. 22-equivalent) | ✅ Art. 22 (see §13) | ✅ ADMT regs (2026) | ✅ Art. 19 | n/a (until rules) | ✅ | ✅ (Dec 2026) | ✅ |
| Response timeline | 30 days (extendable by 60 for complex) | 45 days (extendable by 45) | 30 days | "Reasonable period"; Consent Managers within 90 days | 30 days | 30 days | 15 days for access |
9. California-Specific Disclosures (CCPA/CPRA + ADMT Regulations)
In addition to the rights in §8, California residents:
- Have the right to know the categories of personal information collected, sold, and disclosed (none sold — we do not sell personal information).
- Have the right to opt out of "sale" or "sharing." We do not "sell" or "share" personal information in the CCPA/CPRA sense.
- Have a right of non-discrimination for exercising any CCPA right.
- Are subject to the CPPA's ADMT (Automated Decision-Making Technology) regulations that took effect 1 January 2026. We are not currently using ADMT to make "significant decisions" about you (see §13). If we ever do, we will provide the required pre-use ADMT notice and the right to opt out.
- We honour Global Privacy Control (GPC) signals (mandatory in CA, CO, CT, MT, NH, NE, TX, NJ, MN, MD, OR, DE).
10. Cookies and Similar Technologies
We classify cookies and similar storage as either strictly necessary (no consent required under PECR / ePrivacy / equivalent) or non-essential (consent required). Equal Reject/Accept prominence is provided on our consent banner.
| Type | Purpose | Consent |
|---|---|---|
| Session cookie (Supabase Auth) | Keep you logged in | Strictly necessary |
| Theme preference (localStorage) | Remember dark/light mode | Strictly necessary |
| Consent state (localStorage) | Remember your cookie consent choice | Strictly necessary |
| Sentry session replay (Paid tier only) | Diagnose user-reported bugs | Consent required |
| Performance/error metrics with personal data | Diagnose bugs | Consent required |
Full granular categories, retention, third-party setters, and your right to withdraw consent are in our separate Cookie Policy as required by PECR (UK, post-DUAA 2025), ePrivacy Directive (EU), and ICO guidance.
11. Security
We protect your data using:
- TLS 1.3 in transit
- AES-256 encryption at rest (Supabase managed)
- AES-256-GCM application-level encryption of OpenRouter API keys (above-disk encryption, decryption only in-memory when servicing your request — F-06 in our production-readiness plan)
- Row-Level Security (RLS) policies isolating users' data at the database layer
- Column-level grants preventing user roles from modifying billing or system-controlled fields
- Per-user rate limits (5/min, 100/day on AI requests; 10/min on payment endpoints; 5/hr per IP on auth)
- Multi-account abuse detection (IP / geolocation velocity) — see Terms §5
- Stripe-tokenized payment data; we never see full card numbers
- Coordinated vulnerability disclosure programme (SECURITY.md /
/.well-known/security.txt) - Quarterly security review and dependency audit
Breach notification. In the event of a personal data breach we will notify the relevant supervisory authority and affected individuals as required:
| Authority / regime | Timeline |
|---|---|
| UAE Data Office (PDPL Art. 9) | Without undue delay; typically within 72 hours |
| Lead EU Supervisory Authority (GDPR Art. 33) | Within 72 hours of becoming aware |
| ICO (UK GDPR Art. 33) | Within 72 hours |
| Data Protection Board of India (DPDP) | Without delay; detailed report within 72 hours; affected individuals notified without delay |
| ANPD (Brazil LGPD) | In a reasonable time period (ANPD has indicated 2 working days as the benchmark) |
| OAIC (Australia, Notifiable Data Breaches scheme) | Without delay; 30 days outer limit |
| SDAIA (Saudi PDPL) | Per regulations |
| Affected individuals | Without undue delay where likely to result in high risk to their rights |
12. Children
The Service is not directed at and we do not knowingly process personal data from anyone under 16 years. If you believe a child has provided personal data, please contact us at the privacy address in §17 and we will delete it. For US users under 13, COPPA additionally requires verifiable parental consent before we collect any personal information; in that case we will refuse the account.
If you are between [TBD] and 18 in a jurisdiction with an "Age Appropriate Design Code" (e.g. UK), we apply privacy-by-default settings and do not engage in profiling of you for purposes that could be detrimental to your wellbeing.
13. Automated Decision-Making (clarified per audit)
We do not engage in solely automated decision-making producing legal or similarly significant effects on you within the meaning of GDPR Art. 22 / UK GDPR Art. 22 / UAE PDPL Art. 19 / equivalents. The AI debate-synthesis outputs you receive are presented for your evaluation and you remain the decision-maker as to whether and how to act on them.
Our abuse-detection signals (multi-account velocity rules under §3.2, rate limiting under §11) may automatically restrict or rate-limit specific Free tier requests. These restrictions do not produce legal effects on you; you may appeal any such restriction by contacting [TBD: support contact] and a human will review.
Reserve clause. Model Council is a research and ideation tool. Outputs are not a substitute for professional advice and must not be used as the sole basis for any decision producing legal or similarly significant effects on individuals (e.g. employment, housing, lending, insurance, healthcare, or other "consequential decisions" within the meaning of the Colorado AI Act SB 24-205, Texas TRAIGA, or CPPA ADMT regulations). If you intend such use, contact us about a separate enterprise contract — under your standard B2C/B2B account, such use is prohibited by Terms §6(k).
14. AI Training Opt-Out
Even though we do not train any models on your prompts (see §4 — no training warranty against Anthropic/OpenAI/Google commercial routes), users frequently ask:
- We do not use your prompts to train any model.
- We do not sell or transfer your prompts for training by third parties.
- We disclose where the LLM provider you select may itself train on your inputs (§4.1) — and we do this before you submit.
- If you wish to additionally instruct us to disable any future training-related processing (e.g. if law changes), contact [TBD: privacy contact] and we will record your preference. Effect of the preference is "do not enable training" rather than "withdraw past training" because providers like Anthropic/OpenAI/Google already do not train on commercial API inputs.
15. Responsible Disclosure
If you discover a security vulnerability in the Service, please report it via:
- Email: [TBD:
security@[domain]] .well-known/security.txt: published at https://[domain]/.well-known/security.txt- 90-day coordinated disclosure window; we will acknowledge within 5 working days and provide status updates
We do not pursue legal action against good-faith security researchers who comply with the disclosure policy.
16. Changes to This Policy
Material changes will be notified by email to active users at least 14 days before they take effect (GDPR Art. 13(3) and equivalent). The "Last Updated" date above will be revised. The most recent version is always at the policy URL.
A change log of substantive amendments is maintained at the foot of the policy and on GitHub (docs/legal/PRIVACY.md change history) for transparency.
17. Contact
For privacy questions, rights requests, or DPA negotiations:
- General: [TBD:
privacy@[domain]] - Security disclosure: [TBD:
security@[domain]] - Data subject requests (DSAR): [TBD:
privacy@[domain]— DSAR Portal coming with F-08 in our production-readiness plan] - EU Article 27 Representative: [TBD: vendor name + EU contact address]
- UK Article 27 Representative: [TBD: vendor name + UK contact address]
- Privacy Officer: [TBD: name + email]
- Postal: CronosPMC LLC, Shams Business Center, Sharjah Media City Freezone, Al Messaned, Sharjah, United Arab Emirates