> ## Documentation Index
> Fetch the complete documentation index at: https://docs.critique-labs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> Privacy Policy for Critique AI services operated by Starman LLC

# Privacy Policy

**Effective Date:** August 5, 2026\
**Last Updated:** August 5, 2026

This Privacy Policy describes how Starman LLC, doing business as Critique AI ("Critique," "we," "us," or "our"), collects, uses, and protects information when you use the Critique AI document-grounded assistant and related services at critique-labs.ai and chat.critique-labs.ai (the "Services"). By using the Services, you agree to this Policy. For terms governing use of the Services, see our [Terms of Service](/terms-of-service). Product-specific privacy notices may supplement this Policy for other Critique products; they do not authorize training of shared or public models on customer content, sale of personal data, or advertising use of customer content.

We are based in Menlo Park, California.

## Information We Collect

### Account data

When you create an account, we collect information such as email address and name. Authentication and identity are handled via Auth0.

### Documents, prompts, and responses

We process documents you upload, prompts and queries you submit, and the responses generated by the Services, in order to provide the Services to you.

### Usage telemetry

We collect operational metrics such as token counts, timings, feature usage, and related technical logs needed to operate, secure, and support the Services.

### Payment data

Paid plans are processed by Stripe. We do not store card numbers on our systems.

### Technical data

We may collect IP address, browser or client information, and similar technical data necessary for security, fraud prevention, and service operation.

## Demo and Anonymous Sessions

Anonymous demo uploads on chat.critique-labs.ai are session-only and are deleted at session end. Demo uploads are never used to train shared or public models.

## How We Use Information

We use the information we collect only to:

1. Provide, maintain, secure, and support the Services
2. Process transactions and manage accounts
3. Detect, prevent, and investigate abuse, fraud, and security incidents
4. Comply with legal obligations
5. Communicate with you about service-related matters

De-identified operational telemetry may be used only where it cannot reasonably identify the customer, users, or confidential content.

### What we do not do

1. We do not train shared or public models on customer content — ever
2. We do not sell personal data
3. We do not use customer content for advertising

## Subprocessors

We use the following subprocessors to operate the Services. We maintain this published, current list and update it when our subprocessors change:

| Subprocessor    | Purpose                     | Notes                                                                              |
| --------------- | --------------------------- | ---------------------------------------------------------------------------------- |
| Microsoft Azure | Hosting and infrastructure  | United States                                                                      |
| Anthropic       | Model inference             | Enterprise API terms; API inputs/outputs are not used to train their shared models |
| OpenAI          | Model inference             | Enterprise API terms; API inputs/outputs are not used to train their shared models |
| Stripe          | Payment processing          | We do not store card numbers                                                       |
| Auth0           | Identity and authentication |                                                                                    |

We may update this list as our infrastructure evolves. Material changes will be reflected on this page.

## Retention

| Data type                                | Retention                                                                                                                            |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| Audit and query event logs               | 12 months                                                                                                                            |
| Documents and conversations (self-serve) | Life of the account                                                                                                                  |
| Documents and conversations (enterprise) | Contract term plus 30 days, unless otherwise agreed                                                                                  |
| After account closure                    | Deletion of remaining customer data within 60 days, except backups that age out under policy and records retained as required by law |

Anonymous demo session uploads are deleted at session end, as described above.

## Security

We implement technical and organizational measures designed to protect customer data, including:

1. TLS 1.2 or higher in transit
2. AES-256 encryption (or provider-equivalent encryption) at rest across database, object storage, and backups
3. Multi-factor authentication (MFA) availability
4. Role-based access control (RBAC) for team and enterprise deployments
5. United States data residency for government deployments, where contracted

### Incident notification

If we confirm a material security incident affecting customer data, we will notify affected customers without unreasonable delay and within seventy-two (72) hours of confirmation.

### Certifications posture

Our controls are aligned to SOC 2 Type II criteria. Critique does not currently hold a formal SOC 2 certification. Underlying Microsoft Azure infrastructure is independently audited by Microsoft.

## Government Deployments

Content processed for government customers may be subject to that jurisdiction's public-records and similar disclosure laws. Critique will reasonably assist with search, export, and legal holds as required by the applicable agreement and law.

## Your Rights

Depending on your location and applicable law, you may have the right to:

1. Access personal data we hold about you
2. Correct inaccurate personal data
3. Request deletion of personal data
4. Export your data in a portable format
5. Object to or restrict certain processing
6. Withdraw consent where processing is based on consent

To exercise these rights, contact [support@critique-labs.ai](mailto:support@critique-labs.ai). We may need to verify your identity before fulfilling a request.

### California (CCPA/CPRA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know, delete, and correct personal information, and the right to opt out of the "sale" or "sharing" of personal information. **We do not sell or share personal information** as those terms are defined under CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising.

We will not discriminate against you for exercising your privacy rights. Authorized agents may submit requests as permitted by law; we may require proof of authorization and identity verification.

## Children's Privacy

The Services are not directed to children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

## International Users

The Services are operated from the United States. If you access the Services from outside the United States, you understand that your information may be processed in the United States and other jurisdictions where our subprocessors operate.

## Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated Policy and revise the "Last Updated" date. Material changes may also be communicated by email or in-product notice. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

## Contact

Starman LLC (d/b/a Critique AI)\
Menlo Park, California

Privacy and support: [support@critique-labs.ai](mailto:support@critique-labs.ai)
