Privacy Policy
Effective date: 2026-09-29
This policy describes what Celeus LLC ("we", "us") collects when you use Celeus ("the Service"), how it is processed, and the rights you have over it. The short version: your research data is processed by a deterministic statistical engine on our servers, the AI never receives your rows or your file, and you can permanently delete everything, at any time, yourself.
1. What we collect
- Account information: your email address and sign-in identity (via Google single sign-on; we never see or store your password with SSO), your workspace membership and role.
- Research datasets you upload: stored to run the analyses you request. We never use your datasets to train models, for advertising, or for any purpose other than operating the Service for you.
- Analysis artifacts: the reproducible packages the Service generates for you (results, figures, scripts, and a sanitized copy of the analyzed data), retained per Section 4.
- Usage counters: aggregate, per-workspace counts (analyses run, AI tokens used, storage bytes) for billing and quota display. No dataset content is in these counters.
- Audit events: a tamper-evident, de-identified log of actions (who did what, when, and the outcome - never data values) that gives your workspace a verifiable record of every analysis.
- Billing information: handled by Stripe. We store subscription state and plan; we never see or store card numbers.
- Network address, for abuse prevention: the IP address your browser connects from. We record the address a workspace was created from, so that one person cannot quietly open a large number of free workspaces, and we count requests per address to enforce rate limits. The signup address is part of your account record and is erased when that record is. The rate-limit counters are keyed by address and are separate from your account. An IP address is never combined with your research data, never used to profile you, and never sent to the AI assistant.
- Security notifications: we may email you about a new sign-in to your account (with the country derived from the request at send time when known - we do not store that country, your IP, or your browser fingerprint for this purpose) and about unusual usage of your workspace's analysis or AI allowance.
- Operational logs: our own server logs - request outcomes, errors, and the address of a request that was rate limited. They are shipped to a separate, access-restricted store, kept only for security and for running the Service for up to 400 days before being deleted, and never contain dataset contents.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We use no advertising trackers and no third-party analytics scripts. There is no cookie banner because there is nothing to consent to: we set five cookies, all of them strictly functional, and none of them an advertising, profiling, or analytics cookie. They are, by name:
celeus_refresh- keeps you signed in by renewing your session. Readable only by our server, never by page scripts.celeus_hint- records only whether someone is signed in (the single character "1" - no identity, no token, no account data) so our public site can offer "Open app" instead of "Sign in". This is the one cookie that page scripts on our own domains can read; that is its entire purpose.celeus_oidc- carries the signed, short-lived state of a sign-in that is in progress, so the response from your identity provider can be verified against the request that started it. It expires within minutes and is readable only by our server.celeus_pending_invite- carries a signed, short-lived record of a workspace invitation you are in the middle of accepting, so your choice survives the redirect to your identity provider. It expires within minutes and is readable only by our server.celeus_device- a random browser token, readable only by our server, so we can tell you when a sign-in arrives from a browser we have not seen on your account before. It is not a fingerprint store: we do not record your IP, user-agent, or country alongside it.
We set no other cookies. Separately from cookies, the site keeps a few display preferences (such as your light or dark theme choice) in your browser's own local storage. Those are settings, not identifiers: they stay in your browser, they are never sent to us, and they contain no account data.
2. How analysis works - and what the AI never sees
Two separate systems process your work:
- A deterministic statistical engine (R) computes every number. It runs on our servers, processes your uploaded data there, and its results are seeded and reproducible.
- An AI assistant (Anthropic's Claude, via API) recommends methods, explains results, and drafts text. The AI never receives your rows or your file. It receives column names, category names, summary statistics with small counts withheld, and analysis results. Columns you exclude from the AI, and columns flagged as likely identifiers unless you include them, are left out of what the AI is told about your dataset. If you use one in an analysis, its name and category names can appear in the results the AI receives. This is enforced in code and covered by automated tests. Anthropic does not train on API data per its commercial terms.
3. Storage and security
Data is stored encrypted at rest in object storage, isolated per workspace. All transport is encrypted (TLS). Every workspace's analysis history is protected by a tamper-evident audit chain. Access within a workspace is role-based; operator access is limited, logged, and never includes browsing dataset contents in the course of normal operations.
4. Retention and deletion
- Reproducible packages are retained 90 days by default (configurable per workspace), after which package files are automatically deleted; runs referenced by a report are kept until the report releases them. If a paid subscription lapses (including a failed card renewal) after having been active at least 30 days, existing reproducible packages are retained for at least 180 days from the subscription's end, giving you time to resubscribe or export your work before anything is deleted.
- Datasets and runs can be deleted individually at any time. Deleting your own account is self-service and takes effect immediately: your user record, your single-sign-on identity, your sessions, and your two-factor credentials are erased as soon as you confirm - erased from the live Service, that is; the backup window described below applies to an account deletion exactly as it applies to a workspace erasure. Erasing an entire workspace is self-service too, but deliberately not immediate: it is scheduled for a date at least 7 days ahead (later, if the workspace's subscription is already set to end after that), the Service shows that date until it arrives, and any workspace administrator can cancel the erasure from within the Service at any point before it. When a workspace erasure is scheduled, we email the workspace owners (and the person who requested it) at the addresses on their accounts, with the scheduled date and a link to cancel from Settings. That delay is a safeguard, because workspace erasure is the wider of the two actions: it deletes every member's account and the workspace's datasets, packages, runs, billing state, and share links. When it does take effect, all of that becomes permanently unrecoverable through the Service. For up to 56 days afterward, deleted bytes may still exist in three places: our storage provider's recovery buffer; our own delete-restricted backup copies of reproducible packages and shared reports; and the encrypted offsite copies we take of the account database, which hold your account record, your workspace membership and your billing state. All three are safeguards against accidental or malicious deletion, none of them is a feature either you or we can use to restore deleted data, and all of them expire automatically, after which the contents are permanently purged. We keep those copies because a reproducible package cannot be reconstructed if it is lost, and because an account database that cannot be restored is an outage nobody recovers from; we deliberately do NOT back up the datasets you upload, so an erased dataset leaves the recovery buffer only and is gone within 30 days.
- Inactive free workspaces: a free workspace that has never had a paid subscription and shows no sign-in activity for approximately three months is automatically erased, with the same effect as the workspace erasure described above. Here the safeguard is the warning sequence rather than the scheduled window: we send two email warnings first, and signing in at any point resets the inactivity clock and cancels the process.
- What remains after erasure: the de-identified audit chain (actions and outcomes, no data values) is retained as an integrity record, with no fixed end date and including backup copies of it, and Stripe retains transaction records as required by financial law. If your account was ever the subject of a payment dispute (chargeback), we retain a hash of your email address together with the dispute count and dates - never the address itself - so a repeat dispute can be recognized; this is the only account-identifying information that survives erasure.
5. Subprocessors
We use the following providers to operate the Service:
| Provider | Role | What they process |
|---|---|---|
| AWS | Application hosting, database, object storage | All Service traffic and computation, the account database, and encrypted datasets, packages and audit chains |
| Cloudflare | Domain, edge network, marketing-site hosting, inbound mail routing | Every request to the Service passes through their network, so they handle connection metadata and traffic in transit, including uploads; they host our public marketing pages and route mail sent to our published addresses. They do not hold your datasets or results at rest |
| Anthropic | AI assistant (API) | Column names, category names, summary statistics and analysis results - never your rows or your file |
| Resend | Transactional email | The email address of a recipient and the content of the message we send them (invitations, security and account notices, replies to your support requests) |
| Stripe | Billing | Payment and subscription data |
| Single sign-on | Your sign-in identity |
We will update this table before adding or changing subprocessors.
6. HIPAA position
Celeus LLC is a software provider, not a healthcare provider or health plan.
Every upload is screened for identifier-looking columns. You may keep those columns in the working dataset; the statistical engine can analyse them. Flagged columns are left out of what the AI is told about your dataset unless you include them; if you use one in an analysis, its name and category names can appear in the results the AI receives. Dropping a column is optional. If the screen itself cannot run, the upload is refused - we do not accept data we were unable to check.
If you are a covered entity (or a business associate of one) under HIPAA, do not upload protected health information for which we would be your Business Associate until we have signed a Business Associate Agreement with you. We do not offer a customer BAA today. We may enter one later; using the Service, paying for it, or reading this policy does not create one.
Two things are always true, whatever you keep in a dataset. The AI assistant never receives row-level data of any kind, identifiable or not. Identifier columns that remain in storage are not de-identified merely because they are hidden from the model.
Identified-data storage is an administrator choice, off by default, and it is gated twice. We must first have enabled it for the deployment - it is not enabled by default, and where it is not enabled no workspace can turn it on at all. Only then may a workspace administrator switch on the storage of datasets that still contain identifying information, which requires an explicit acknowledgement of the added responsibility; the choice, the person who made it, and the time it was made are recorded in the workspace's audit trail. It changes only what may be kept. It does not create, replace or imply a Business Associate Agreement.
We have no Business Associate Agreement with you, and nothing here creates one. Customers whose compliance posture requires a Business Associate Agreement should contact legal@celeus.ai; the honest answer today is that we are not yet signing them. Independent researchers who are not covered entities typically do not need one with us.
7. Your rights (including GDPR)
You can access, export, and delete your data yourself, at any time, from within the Service.
What you can download directly: the reproducible package for any analysis (results, figures, the exact script, the seed and the audit log), the individual files of a run, and any report you export. What is not a one-click download: the original file you uploaded, and a single bundle of your whole account record. Ask us at legal@celeus.ai for either and we will provide it - the absence of a button is a gap in the product, not a limit on your right to the data.
Deletion is self-service throughout: erasing your own account takes effect immediately, and erasing an entire workspace is scheduled at least 7 days ahead and can be cancelled from within the Service at any point before that date. Both are irreversible through the Service once they take effect (see Section 4 for the recovery-buffer and backup windows, safeguards against accidental or malicious deletion, not a way to restore data once erased).
If you are in a jurisdiction with statutory data rights (such as the GDPR, or a United States state privacy law), the controls above together with that address are how we fulfil access, portability and erasure requests.
Controller. Celeus LLC is the controller of account, billing, security-log and usage data. You (or your institution) remain the controller of the research datasets you upload. Contact: legal@celeus.ai.
Legal bases (GDPR Art. 6). We process account and billing data to perform the contract (Art. 6(1)(b)). We process security logs, abuse signals and rate-limit counters for our legitimate interests in operating and securing the Service (Art. 6(1)(f)). Recipients are the subprocessors in Section 5. Data is stored and processed in the United States; AWS Standard Contractual Clauses are the transfer tool once that DPA is in force. If a dataset includes special-category health data (Art. 9), you must have a lawful basis of your own - we do not invent one for you.
Your data is stored and processed in the United States; regional data residency options are on our roadmap and this policy will be updated when they ship.
8. Changes and contact
Material changes to this policy will be announced in the Service or by email with reasonable advance notice. Questions and requests: legal@celeus.ai.