Terms · Privacy · Celeus

Privacy Policy

Effective date: 2026-07-22

This policy describes what Celeus LLC ("we", "us") collects when you use Celeus ("the Service"), how it is processed, and the rights you have over it. The short version: your research data is processed by a deterministic statistical engine on our servers, your data is never sent to an AI model, and you can permanently delete everything, at any time, yourself.

1. What we collect

We use no advertising trackers and no third-party analytics scripts. There is no cookie banner because there is nothing to consent to: the only cookie is the strictly-functional session-refresh cookie.

2. How analysis works - and what the AI never sees

Two separate systems process your work:

3. Storage and security

Data is stored encrypted at rest in object storage, isolated per workspace. All transport is encrypted (TLS). Every workspace's analysis history is protected by a tamper-evident audit chain. Access within a workspace is role-based; operator access is limited, logged, and never includes browsing dataset contents in the course of normal operations.

4. Retention and deletion

5. Subprocessors

We use the following providers to operate the Service:

Provider Role What they process
Fly.io Application hosting All Service traffic and computation
Tigris Object storage Encrypted datasets, packages, audit chains
Anthropic AI assistant (API) Aggregate metadata and results only - never your dataset
Stripe Billing Payment and subscription data
Google / Microsoft Single sign-on Your sign-in identity

We will update this table before adding or changing subprocessors.

6. HIPAA position

Celeus LLC is a software provider, not a healthcare provider or health plan. The Service is designed so that protected health information (PHI) need not and should not be uploaded in identifiable form: de-identification tooling, PHI screening, and column controls are built in, and the Terms of Service require de-identification before upload. The AI assistant never receives row-level data of any kind, identifiable or not. Customers whose compliance posture requires a Business Associate Agreement should contact legal@celeus.ai to discuss eligibility before uploading any data subject to HIPAA.

7. Your rights (including GDPR)

You can access, export, and permanently delete your data yourself, at any time, from within the Service - including full account and workspace erasure. If you are in a jurisdiction with statutory data rights (such as the GDPR), these self-service controls are how we fulfill access and erasure requests; for anything they do not cover, contact legal@celeus.ai. Data is currently hosted in Celeus LLC's production regions; regional data residency options are on our roadmap and this policy will be updated when they ship.

8. Changes and contact

Material changes to this policy will be announced in the Service or by email with reasonable advance notice. Questions and requests: legal@celeus.ai.