Privacy Policy
Effective date: 2026-07-22
This policy describes what Celeus LLC ("we", "us") collects when you use Celeus ("the Service"), how it is processed, and the rights you have over it. The short version: your research data is processed by a deterministic statistical engine on our servers, your data is never sent to an AI model, and you can permanently delete everything, at any time, yourself.
1. What we collect
- Account information: your email address and sign-in identity (via Google or Microsoft single sign-on; we never see or store your password with SSO), your workspace membership and role.
- Research datasets you upload: stored to run the analyses you request. We never use your datasets to train models, for advertising, or for any purpose other than operating the Service for you.
- Analysis artifacts: the reproducible packages the Service generates for you (results, figures, scripts, and a sanitized copy of the analyzed data), retained per Section 4.
- Usage counters: aggregate, per-workspace counts (analyses run, AI tokens used, storage bytes) for billing and quota display. No dataset content is in these counters.
- Audit events: a tamper-evident, de-identified log of actions (who did what, when, and the outcome - never data values) that gives your workspace a verifiable record of every analysis.
- Billing information: handled by Stripe. We store subscription state and plan; we never see or store card numbers.
We use no advertising trackers and no third-party analytics scripts. There is no cookie banner because there is nothing to consent to: the only cookie is the strictly-functional session-refresh cookie.
2. How analysis works - and what the AI never sees
Two separate systems process your work:
- A deterministic statistical engine (R) computes every number. It runs on our servers, processes your uploaded data there, and its results are seeded and reproducible.
- An AI assistant (Anthropic's Claude, via API) recommends methods, explains results, and drafts text. It receives only whitelisted, aggregate metadata: column names and types, summary statistics with small groups suppressed, and the statistical results themselves - never rows, never cell values, never your dataset. This is enforced by a single, test-guarded code path; there is no other route from your data to the model. Anthropic does not train on API data per its commercial terms.
3. Storage and security
Data is stored encrypted at rest in object storage, isolated per workspace. All transport is encrypted (TLS). Every workspace's analysis history is protected by a tamper-evident audit chain. Access within a workspace is role-based; operator access is limited, logged, and never includes browsing dataset contents in the course of normal operations.
4. Retention and deletion
- Reproducible packages are retained 90 days by default (configurable per workspace), after which package files are automatically deleted; runs referenced by a report are kept until the report releases them.
- Datasets and runs can be deleted individually at any time. Account and entire-workspace erasure are self-service and permanent: datasets, packages, runs, billing state, and share links are hard-deleted.
- What remains after erasure: the de-identified audit chain (actions and outcomes, no data values) is retained as an integrity record, and Stripe retains transaction records as required by financial law.
5. Subprocessors
We use the following providers to operate the Service:
| Provider | Role | What they process |
|---|---|---|
| Fly.io | Application hosting | All Service traffic and computation |
| Tigris | Object storage | Encrypted datasets, packages, audit chains |
| Anthropic | AI assistant (API) | Aggregate metadata and results only - never your dataset |
| Stripe | Billing | Payment and subscription data |
| Google / Microsoft | Single sign-on | Your sign-in identity |
We will update this table before adding or changing subprocessors.
6. HIPAA position
Celeus LLC is a software provider, not a healthcare provider or health plan. The Service is designed so that protected health information (PHI) need not and should not be uploaded in identifiable form: de-identification tooling, PHI screening, and column controls are built in, and the Terms of Service require de-identification before upload. The AI assistant never receives row-level data of any kind, identifiable or not. Customers whose compliance posture requires a Business Associate Agreement should contact legal@celeus.ai to discuss eligibility before uploading any data subject to HIPAA.
7. Your rights (including GDPR)
You can access, export, and permanently delete your data yourself, at any time, from within the Service - including full account and workspace erasure. If you are in a jurisdiction with statutory data rights (such as the GDPR), these self-service controls are how we fulfill access and erasure requests; for anything they do not cover, contact legal@celeus.ai. Data is currently hosted in Celeus LLC's production regions; regional data residency options are on our roadmap and this policy will be updated when they ship.
8. Changes and contact
Material changes to this policy will be announced in the Service or by email with reasonable advance notice. Questions and requests: legal@celeus.ai.