Terms · Privacy · Celeus

Privacy Policy

Effective date: 2026-09-29

This policy describes what Celeus LLC ("we", "us") collects when you use Celeus ("the Service"), how it is processed, and the rights you have over it. The short version: your research data is processed by a deterministic statistical engine on our servers, the AI never receives your rows or your file, and you can permanently delete everything, at any time, yourself.

1. What we collect

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We use no advertising trackers and no third-party analytics scripts. There is no cookie banner because there is nothing to consent to: we set five cookies, all of them strictly functional, and none of them an advertising, profiling, or analytics cookie. They are, by name:

We set no other cookies. Separately from cookies, the site keeps a few display preferences (such as your light or dark theme choice) in your browser's own local storage. Those are settings, not identifiers: they stay in your browser, they are never sent to us, and they contain no account data.

2. How analysis works - and what the AI never sees

Two separate systems process your work:

3. Storage and security

Data is stored encrypted at rest in object storage, isolated per workspace. All transport is encrypted (TLS). Every workspace's analysis history is protected by a tamper-evident audit chain. Access within a workspace is role-based; operator access is limited, logged, and never includes browsing dataset contents in the course of normal operations.

4. Retention and deletion

5. Subprocessors

We use the following providers to operate the Service:

Provider Role What they process
AWS Application hosting, database, object storage All Service traffic and computation, the account database, and encrypted datasets, packages and audit chains
Cloudflare Domain, edge network, marketing-site hosting, inbound mail routing Every request to the Service passes through their network, so they handle connection metadata and traffic in transit, including uploads; they host our public marketing pages and route mail sent to our published addresses. They do not hold your datasets or results at rest
Anthropic AI assistant (API) Column names, category names, summary statistics and analysis results - never your rows or your file
Resend Transactional email The email address of a recipient and the content of the message we send them (invitations, security and account notices, replies to your support requests)
Stripe Billing Payment and subscription data
Google Single sign-on Your sign-in identity

We will update this table before adding or changing subprocessors.

6. HIPAA position

Celeus LLC is a software provider, not a healthcare provider or health plan.

Every upload is screened for identifier-looking columns. You may keep those columns in the working dataset; the statistical engine can analyse them. Flagged columns are left out of what the AI is told about your dataset unless you include them; if you use one in an analysis, its name and category names can appear in the results the AI receives. Dropping a column is optional. If the screen itself cannot run, the upload is refused - we do not accept data we were unable to check.

If you are a covered entity (or a business associate of one) under HIPAA, do not upload protected health information for which we would be your Business Associate until we have signed a Business Associate Agreement with you. We do not offer a customer BAA today. We may enter one later; using the Service, paying for it, or reading this policy does not create one.

Two things are always true, whatever you keep in a dataset. The AI assistant never receives row-level data of any kind, identifiable or not. Identifier columns that remain in storage are not de-identified merely because they are hidden from the model.

Identified-data storage is an administrator choice, off by default, and it is gated twice. We must first have enabled it for the deployment - it is not enabled by default, and where it is not enabled no workspace can turn it on at all. Only then may a workspace administrator switch on the storage of datasets that still contain identifying information, which requires an explicit acknowledgement of the added responsibility; the choice, the person who made it, and the time it was made are recorded in the workspace's audit trail. It changes only what may be kept. It does not create, replace or imply a Business Associate Agreement.

We have no Business Associate Agreement with you, and nothing here creates one. Customers whose compliance posture requires a Business Associate Agreement should contact legal@celeus.ai; the honest answer today is that we are not yet signing them. Independent researchers who are not covered entities typically do not need one with us.

7. Your rights (including GDPR)

You can access, export, and delete your data yourself, at any time, from within the Service.

What you can download directly: the reproducible package for any analysis (results, figures, the exact script, the seed and the audit log), the individual files of a run, and any report you export. What is not a one-click download: the original file you uploaded, and a single bundle of your whole account record. Ask us at legal@celeus.ai for either and we will provide it - the absence of a button is a gap in the product, not a limit on your right to the data.

Deletion is self-service throughout: erasing your own account takes effect immediately, and erasing an entire workspace is scheduled at least 7 days ahead and can be cancelled from within the Service at any point before that date. Both are irreversible through the Service once they take effect (see Section 4 for the recovery-buffer and backup windows, safeguards against accidental or malicious deletion, not a way to restore data once erased).

If you are in a jurisdiction with statutory data rights (such as the GDPR, or a United States state privacy law), the controls above together with that address are how we fulfil access, portability and erasure requests.

Controller. Celeus LLC is the controller of account, billing, security-log and usage data. You (or your institution) remain the controller of the research datasets you upload. Contact: legal@celeus.ai.

Legal bases (GDPR Art. 6). We process account and billing data to perform the contract (Art. 6(1)(b)). We process security logs, abuse signals and rate-limit counters for our legitimate interests in operating and securing the Service (Art. 6(1)(f)). Recipients are the subprocessors in Section 5. Data is stored and processed in the United States; AWS Standard Contractual Clauses are the transfer tool once that DPA is in force. If a dataset includes special-category health data (Art. 9), you must have a lawful basis of your own - we do not invent one for you.

Your data is stored and processed in the United States; regional data residency options are on our roadmap and this policy will be updated when they ship.

8. Changes and contact

Material changes to this policy will be announced in the Service or by email with reasonable advance notice. Questions and requests: legal@celeus.ai.