CerulionCerulionBETA

Legal

Privacy Policy

Last updated:

This Privacy Policy describes how Cerulion ("Cerulion", "we", "us") handles your data across the Cerulion services: the web application at app.cerulion.com, the hosted MCP endpoint at mcp.cerulion.com, and the associated APIs (together, the "Services").

This policy takes effect on September 1, 2025.

1. Data we collect

  • Account data. Your email address and authentication identifiers (email and password, or your GitHub identity if you sign in with GitHub OAuth).
  • Bag data. The robot data recordings you upload, plus the indexes, summaries, and metadata we derive from them to make them searchable and answerable.
  • Usage data. Product analytics events such as pages viewed and features used, collected through PostHog.
  • Technical data. Standard server logs, including IP addresses and request metadata, kept for security and debugging.

2. How we use your data

We use your data to provide and operate the Services: authenticate you, store and index your recordings, answer your questions about them, secure the Services against abuse, understand how the product is used so we can improve it, and communicate with you about your account.

We do not sell your personal data.

3. AI processing of bag data

Content from your uploaded recordings (messages, topics, timestamps, and summaries derived from them) is processed by large language models, specifically Anthropic models running on AWS Bedrock, to answer the questions you ask about your data. Your bag data is not used to train foundation models.

4. Ownership

You retain full ownership of the bag data you upload. Cerulion takes only the limited license described in the Terms of Service, to store, process, and index your data in order to provide the Services.

5. Subprocessors

We rely on the following subprocessors to run the Services:

SubprocessorPurpose
Amazon Web Services (AWS)Cloud hosting and model inference (Bedrock)
SupabaseAuthentication, database, and file storage
AnthropicLarge language models, accessed via AWS Bedrock
PostHogProduct analytics

We will update this list when our subprocessors change.

6. Retention and deletion

We keep your data while your account is active. When you delete a recording or your account, the associated data is removed from the live Services, and residual copies in routine backups are purged on our normal backup cycle, except where we must retain data to comply with law.

7. Security

Data is encrypted in transit, and access to production systems is restricted. No method of storage or transmission is completely secure, and the Services are in beta: keep original copies of your recordings, and do not treat the Services as your only copy of any data.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these rights by contacting us at founders@cerulion.com. You can delete individual recordings directly in the app; to delete your account, contact us at the same address.

9. Changes to this policy

We may update this policy from time to time. If a change is material, we will notify you through the Services or by email before it takes effect.

10. Contact

Privacy questions and requests: founders@cerulion.com. This policy is governed by the laws of the State of Delaware.