Privacy Policy

Effective July 3, 2026

This is the plain-English version of how we handle your data. No legal maze: what we collect, why, who touches it, and how you stay in control.

Who we are

Cerqular Inc. is a Delaware C-Corporation operating the Cerqular Intelligence platform at cerqular.ai ("Cerqular", "we"). For anything in this policy, write to privacy@cerqular.ai. We respond to every request.

What we collect

  • Account data. Your name, email address, and login credentials (handled by our authentication provider; we never see your password in plain text).
  • Business data you connect. When you connect a service such as Stripe, we read the data you authorize (for example revenue, payments, and customer records) to measure and attribute your revenue. The Stripe connection can also create a trackable checkout link, so a sale can be traced to the work that drove it; it can never move money, issue a refund, or charge anyone. Connections that do not need to write stay limited to reading.
  • Content you create. The offers, drafts, posts, emails, and other work you write or generate on the platform, and the materials you provide so the AI can learn your voice.
  • Usage telemetry. Which features you use, basic device and browser information, and technical logs. We use first-party analytics; we do not run third-party advertising trackers.

Why we collect it

  • To provide the service. Connecting your data is the product: it is how Cerqular does the revenue work for you.
  • To measure attributed revenue. Our core promise is proving which dollar came from which action. That requires reading your connected revenue data.
  • To improve the product. Aggregated usage patterns tell us what works and what breaks.
  • To run the business. Billing, support, security, fraud prevention, and legal compliance.

We do not sell your personal data. We do not share it for third-party advertising. Ever.

How AI processing works

Cerqular is an AI platform. The content you create and the business data you connect are processed by AI models (including Anthropic's Claude models, accessed through their API) to generate work and insights for you: drafts in your voice, revenue analysis, follow-ups, and recommendations.

Your content and connected business data are not used to train third-party foundation models. Our AI providers process your data under API terms that exclude training. What the AI produces for you is yours (see our Terms of Service), and every revenue figure it shows you carries an honest Measured, Estimated, or Modeled label.

Who processes your data

We use a small set of processors, each for one job:

  • Stripe: payment processing for your subscription, and the revenue data you choose to connect.
  • Supabase: database hosting and storage, with row-level security isolating each account.
  • Anthropic: AI processing through their API, under terms that exclude model training on your data.
  • Resend: transactional email (receipts, notifications, account messages).
  • Vercel: web application hosting.
  • Render: backend infrastructure hosting.
  • PostHog: product analytics, and only if you accept analytics cookies. PostHog is a third-party processor in the United States, so we name it rather than call our analytics first-party.
  • Termly: renders the long-form legal policies on our legal pages.

The same list, with roles explained, lives on our Data Processing page. If we add a processor that touches your data, we update both pages first.

Google user data (YouTube integration)

Cerqular is adding a read-only YouTube integration. When you connect it, we will access your channel and video metadata and the analytics you explicitly authorize through Google's consent screen, and nothing more.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely:

  • Google user data is used only to provide user-facing features you can see: attributing revenue and performance to your own content inside your own dashboard.
  • It is never used for advertising, never sold, and never transferred to data brokers or third parties except as needed to provide those features, for security, or to comply with law.
  • No human reads it unless you ask us to (support with your consent), it is required for security or abuse investigation, or the law requires it.
  • It is not used to train generalized AI or machine-learning models.
  • You can revoke access at any time from your Google account security settings, and the connection dies immediately.

Your rights

Depending on where you live, the GDPR (Europe and the UK), the CCPA and CPRA (California), the Australian Privacy Act, and similar laws give you rights over your data. We honor them for everyone, not just where the law forces us to:

  • Access: ask what we hold about you.
  • Correction: fix anything wrong.
  • Deletion: delete your account and data.
  • Export: take your data with you in a portable format.
  • Objection and restriction: limit how we process your data.
  • Complaint: raise the issue with your local data protection authority. We would rather you raise it with us first, but that is your right.

Send any request to privacy@cerqular.ai. We verify it is you, then act within the timeframes the law requires. We never punish or degrade the service for exercising your rights.

How long we keep data

We keep your data while your account is active. When you delete your account, we delete your account data and connected business data within 30 days, and it ages out of encrypted backups within 90 days. Aggregated, de-identified usage statistics that no longer identify you may be retained. Where the law requires us to keep specific records (for example billing records for tax), we keep only those, only as long as required.

How we protect it

  • Encryption in transit (TLS) and at rest; connection credentials are additionally encrypted with AES-256-GCM.
  • Row-level security is enabled on every data table and denies direct access by default. Your browser never queries the database; every read runs through our API, scoped to your signed-in account. The practical outcome: no other account can reach your data.
  • Least-privilege access internally; no cross-contamination between accounts or between integrations.

No system is unbreakable, and we will not pretend ours is. If a breach affects your data, we notify you and the relevant authorities as the law requires. Our full posture is on the Trust page.

Cookies

Minimal, and gated. Signing you in and keeping your session alive needs cookies, so those are always on. Everything else is off until you say yes: analytics cookies (set on our own domain, processed by PostHog, a third-party analytics processor) and a country cookie that picks your currency. You choose on first visit and can change it anytime on our Cookies page. No third-party advertising cookies, no cross-site tracking.

International transfers

Our infrastructure runs in the United States. Where data moves from regions that restrict transfers (such as the EEA, UK, or Australia), we rely on recognized safeguards such as standard contractual clauses.

Children

Cerqular is a business tool and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, tell us and we will delete it.

Changes to this policy

If we make a material change, we will notify you by email or in the product before it takes effect, and update the effective date above. We will never quietly weaken your protections.

The full live policy

Below is the complete, automatically maintained privacy policy document. It updates as laws change. The plain-English sections above are our own commitments and always apply alongside it.

The live policy is loading. Our summary above always applies.

Start 30 days for $1