Skip to main content
Effective date: August 7, 2026
Last updated: August 7, 2026
This Privacy Policy explains how Starman LLC, doing business as Critique Labs and Critique Labs AI (“Critique,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information in connection with Critique Chat, including chat.critique-labs.ai, the public demo, authenticated workspaces, and contracted deployments (collectively, the “Service”). This policy applies only to Critique Chat. Other Critique products have separate notices in this documentation.

1. Our role

For account, website, support, security, and business-administration information, Critique generally determines why and how the information is processed. For documents, prompts, outputs, user directories, and other content submitted to an organizational workspace (“Customer Content”), Critique generally acts on the organization’s instructions. The organization controls its users, source systems, public/private designations, retention instructions, and use of outputs. If you use an employer, school, government, or other organization’s workspace, direct requests about Customer Content to that organization first. A signed customer agreement, order, statement of work, or data processing addendum (a “Customer Agreement”) may provide additional or different privacy, security, residency, and retention terms. The Customer Agreement controls for that deployment.

2. Information we collect

Information you provide

  • Account information: name, email address, profile image, organization, authentication identifier, and account preferences.
  • Customer Content: uploaded documents, extracted text, filenames, prompts, chat messages, outputs, citations, source metadata, folders, public/private designations, and sensitivity declarations.
  • Support and sales information: messages, contact details, meeting requests, implementation requirements, and other information you provide when contacting us or scheduling a meeting.
  • Commercial information: contract, billing, transaction, and tax records for paid customers. Payment-card details, if required, are processed by a payment provider and are not stored in Critique Chat’s application database.

Information collected automatically

  • Usage information: feature interactions, request timestamps, workspace or assistant mode, document and answer size, estimated token usage, rate-limit events, ingestion status, feedback, and administrative activity.
  • Device and network information: IP address, browser and device type, operating system, referring page, and server or security logs.
  • Authentication information: session cookies, sign-in status, and identity-provider tokens needed to authenticate and secure an account.
  • Analytics information: page views and general site interaction data collected through Vercel Analytics. We do not use Critique Chat analytics for targeted advertising.
We may derive aggregate or de-identified statistics that do not reasonably identify an individual, organization, or confidential content.

3. How we collect information

We collect information:
  1. directly from you when you upload a file, ask a question, create an account, contact us, or configure a workspace;
  2. from your organization and its authorized administrators or connected source systems;
  3. automatically from browsers, devices, application servers, and security systems; and
  4. from service providers that support authentication, hosting, AI processing, analytics, scheduling, and support.

4. How we use information

We use information to:
  • provide, operate, authenticate, and support the Service;
  • extract, index, retrieve, and cite Customer Content;
  • generate and verify responses requested by users;
  • enforce public/private access rules and document permissions;
  • administer accounts, source connections, usage, billing, and contracts;
  • monitor reliability, diagnose errors, prevent abuse, and protect security;
  • respond to support, sales, privacy, and legal requests;
  • evaluate and improve Service performance using aggregate, de-identified, or authorized information;
  • comply with law, court orders, government obligations, and enforceable Customer Agreements; and
  • establish, exercise, or defend legal rights.

5. AI model use

Customer Content may be sent to AI and infrastructure providers only as needed to provide the requested Service. Critique does not sell Customer Content and does not use it to train shared or public AI models. For contracted deployments, provider settings and agreements prohibit providers from using inputs and outputs to train shared models. Depending on the deployment and selected features, AI providers may include Anthropic and OpenAI. Public-web research can be disabled, and retrieval can be limited to customer-approved content, as specified in the applicable Customer Agreement. We may use de-identified operational telemetry to evaluate reliability only when it cannot reasonably identify a customer, user, or confidential content. Any materially different model-improvement use requires separate authorization where required by a Customer Agreement or law.

6. The public demo

The public landing-page demo is designed for non-sensitive evaluation:
  • anonymous uploads are processed in server memory rather than a persistent document library;
  • an uploaded document remains in memory until the demo service restarts or the bounded demo cache evicts it;
  • document text and the question are transmitted to the Service and applicable AI providers to generate an answer;
  • the application records limited usage metadata, such as IP address, mode, character counts, estimated tokens, and timestamps, but does not store the full anonymous conversation in its usage table; and
  • rate limits are applied by IP address, or by account identifier and IP address after sign-in.
Do not upload confidential, personal, personnel, financial, health, minors’, export-controlled, or otherwise restricted information to the public demo. Use a contracted, configured workspace for sensitive organizational content.

7. Public and private collections

Private documents are available only to authorized workspace users according to configured access controls. Public documents may be retrieved, quoted, and displayed to anonymous users. Where publishing controls are enabled, a document is private by default and publication is a separate action reserved for authorized roles. Users must review content and make any required sensitivity declaration before publishing. Documents marked sensitive cannot be placed in the public collection. These safeguards reduce risk but do not replace the customer’s responsibility to classify records and authorize publication. For public-sector customers, records may be subject to applicable freedom-of-information, public-records, legal-hold, and records-retention laws. The public body, not Critique, decides whether a record is subject to disclosure. Critique will assist as required by the Customer Agreement.

8. How we disclose information

We disclose information only as reasonably necessary:
  • To your organization: workspace administrators may access account details, content, permissions, activity, and usage associated with their workspace.
  • To service providers and subprocessors: providers support cloud hosting, storage, authentication, AI inference, analytics, scheduling, communications, monitoring, and support. Current or planned Critique Chat providers include Microsoft Azure, Vercel, Auth0, Anthropic, OpenAI, and Calendly, depending on the feature and deployment.
  • For integrations you enable: if an authorized user connects a repository or other service, information is exchanged as needed to provide that integration.
  • For legal and safety reasons: we may disclose information to comply with law or valid process; protect users, Critique, or others; investigate fraud or abuse; or establish and defend legal claims.
  • For a business transaction: information may be transferred in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and continued legal protections.
  • With consent or direction: we disclose information when you or the controlling organization directs or authorizes us to do so.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Content for advertising.

9. Cookies, analytics, and third-party pages

Critique Chat uses necessary cookies and similar technologies for authentication, security, preferences, and session continuity. Vercel Analytics collects site-usage information. We do not use advertising cookies on Critique Chat. Calendly assets load when you choose to open the scheduling widget, and Calendly may collect information under its own privacy notice. Links to external sites and source integrations are governed by those sites’ notices. Because there is no uniform standard for browser “Do Not Track” signals, the Service does not currently respond to them. We honor legally recognized opt-out preference signals where applicable. Since we do not sell personal information or share it for cross-context behavioral advertising, there is no Critique Chat sale or targeted-advertising opt-out to apply.

10. Retention and deletion

We retain information only for as long as reasonably necessary for the purposes described above, subject to a Customer Agreement, legal hold, security need, or legal requirement. Our standard practices are:
  • Public demo uploads: held in volatile server memory until restart or bounded-cache eviction, as described above.
  • Customer Content in an active workspace: retained while the account or Customer Agreement is active, unless the customer deletes it or instructs us otherwise.
  • Authentication, administration, ingestion, security, and relevant query-event logs: generally retained for up to 12 months.
  • Documents and conversations in a contracted deployment: retained for the term of the Customer Agreement plus 30 days, unless the Customer Agreement or lawful retention instruction requires a different period.
  • After contract termination: a standard export is available on timely request; remaining Customer Content is deleted within 60 days, except backups that are protected from routine access and age out under the applicable backup schedule.
  • Account, support, billing, and legal records: retained as needed to administer the relationship, comply with law, resolve disputes, and enforce agreements.
  • De-identified information: may be retained when it cannot reasonably be linked back to a person, customer, or confidential content.
Deletion from active systems may not immediately remove information from security logs or backups. We may retain information when legally required or subject to a documented legal hold.

11. Security and incidents

We use administrative, technical, and organizational measures designed to protect information. Depending on the deployment, these include access controls, role-based permissions, multi-factor authentication, pre-retrieval permission filtering, separate public/private collections, encryption, logging, backups, vulnerability management, and negative-permission testing. Contracted deployments use TLS 1.2 or later in transit and AES-256 or provider-equivalent encryption at rest for databases, object storage, and backups. Backup and recovery commitments, when applicable, are stated in the Customer Agreement. No method of transmission or storage is completely secure. If we confirm a material incident affecting Customer Content, we will notify the controlling customer without unreasonable delay and within any period required by law or the Customer Agreement.

12. Data location and international transfers

Critique is based in the United States, and information may be processed in the United States and other locations where approved providers operate. Contracted production deployments are hosted in the United States unless the Customer Agreement states otherwise. A Customer Agreement may restrict processing to a named provider or region. Where required for an international transfer, we use an appropriate legal mechanism and contractual safeguards.

13. Your privacy choices and rights

Depending on where you live and subject to legal exceptions, you may have rights to:
  • know whether we process your personal information and access a copy;
  • correct inaccurate personal information;
  • request deletion;
  • receive portable information you provided;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent; and
  • appeal a decision on a privacy request where applicable.
To make a request, email support@critique-labs.ai with the subject “Critique Chat Privacy Request.” We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, subject to verification. If your information is controlled by an organization using Critique Chat, contact that organization first. We will assist it with verified requests as required by its Customer Agreement and law. We will not discriminate against you for exercising a privacy right. You may also complain to the privacy or data-protection regulator where you live.

14. Children’s privacy

Critique Chat is not directed to children under 13, and the public demo should not be used to submit children’s personal information. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it as appropriate. An organization using Critique Chat in an educational or public-service setting is responsible for obtaining required authorization and configuring appropriate access and content controls.

15. Changes to this policy

We may update this policy to reflect changes in the Service, law, or our practices. We will post the revised policy and update the date above. We will provide additional notice of material changes when required by law or a Customer Agreement. Changes apply prospectively and do not amend a Customer Agreement unless that agreement allows it.

16. Contact us

For privacy questions or requests: Starman LLC (Critique Labs)
110 Constitution Dr, Apt 621
Menlo Park, CA 94025
support@critique-labs.ai
For general service terms, see the Critique Chat Terms of Service.