Privacy notice
Last updated: 30 July 2026
This notice explains what personal data Cedreon processes, why, and what you can ask us to do about it. It covers the website, the workspace and any contact you have with us. We have written it in plain language rather than legal boilerplate, because the people who read it carefully are the people we build for.
Who is responsible
The controller for the processing described here is [FILL: legal name and address of the controller]. You can reach us at [email protected].
What we collect
We keep the set small on purpose. In practice it is:
- Account data: your email address, an optional display name, and a hashed password. We never store your password itself.
- Content you send: chat messages, uploaded documents and the replies you receive. Read the next two sections, because how we store this is the substance of the product.
- Usage records: an append-only record of each exchange with timestamps, the model used, counts and token totals. It records what happened, never the content.
- Billing data, if you subscribe: handled by our payment processor. We store a customer reference, never your card details.
- Website data: a first-party session cookie, and, if you arrive from an advertisement, the campaign name so we know which one reached you.
- Anything you send us by email or through a contact form.
What AI providers actually receive
This is the part most notices leave vague. Before a request leaves your workspace, Cedreon screens it and replaces detected sensitive values with placeholders. The AI provider receives the placeholder, not the value. The original stays encrypted in your workspace and is restored in the reply only for you.
Detection is layered and best effort, not a guarantee. It combines checksum patterns with a local recognition model, and unusual formats can be missed. We say so plainly, because a promise of perfect detection would be false.
We only route to providers that do not train on what you send.
The audit record, and what erasure means
Every exchange is written to an append-only, hash-chained record. That record is what lets a firm show what happened, and it is deliberately not editable.
So erasure works in two parts, and we would rather explain it than overpromise. Deleting your data removes the stored content and destroys the encrypted mapping that could restore the original values, which makes them unrecoverable. The chain keeps the hashes, timestamps and counts that prove the sequence was not tampered with. It never held your content in the first place.
Why we process it, and on what basis
To provide the service you asked for, which is performance of our contract with you. To keep the service secure and to account for how it was used, which is our legitimate interest and, for regulated users, often their own professional requirement. To meet our own legal obligations, such as accounting records. Where we ask for consent, for example to send you email about the product, you can withdraw it at any time.
Who else processes data
We keep this list short, and we keep it current:
- AI model providers, which receive screened prompts as described above.
- Our hosting provider, where the application and database run.
- Our payment processor, for subscriptions.
- Our email provider, for transactional messages.
- If you contact us through an advertisement form, the advertising platform hosting that form.
Where processing happens
The application and your stored data are processed in the European Union under the GDPR. Cedreon is developed in Switzerland. Some AI providers may process a screened request outside the EU. Where that happens it is covered by the appropriate safeguards, and because of the screening described above, the values we identified as sensitive are not part of what is sent.
Cookies
We run no advertising or analytics trackers in the workspace. The cookies we set are our own and functional:
- A session cookie, so you stay signed in.
- A short counter for the free trial, so guests get their free messages.
- If you arrive from an advertisement, the campaign name, so we can tell which advertisement reached you. It carries no identifier and expires after 30 days.
How long we keep it
Account data for as long as you have an account, and [FILL: retention period] afterwards. Conversations and documents until you delete them, or not at all if your workspace runs in store-nothing mode. The usage record for [FILL: retention period], because its purpose is to be a durable account of what happened. Billing records for as long as accounting law requires.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, and ask for it in a portable form. Write to [email protected] and we will answer within 30 days. If you are not satisfied, you can complain to the Swiss Federal Data Protection and Information Commissioner, or to your local supervisory authority in the EU.
Changes
If we change this notice materially we will say so on this page and, where the change affects you directly, by email.