Skip to content
Ciolkosz Intelligence
Draft — under attorney review

Privacy policy

Effective 2026-09-01

The short version

  • We collect what we need to run your account: who you are, your business details, the records and photos you upload, how you use the product, and technical logs.
  • Your business's client records and photos belong to you. We process them only to provide the service to you. We do not sell personal data and we do not use your content to train AI models.
  • Data is hosted in the United States with a short list of providers: Vercel, Supabase, Stripe, Anthropic and Clerk, plus Resend and Twilio when those features are switched on.
  • We use only the cookies needed to keep you signed in. There is no advertising tracking and our analytics do not use cookies.
  • You can export your data as CSV at any time, and ask us for a full export, a correction or deletion by email. We answer within 30 days.
  • Ciolk OS is not for anyone under 18 and it is not HIPAA compliant. Do not enter protected health information.

011. Who this policy covers

This policy explains how Ciolkosz Intelligence LLC ("Ciolk", "we", "us") collects, uses and shares personal data when you visit ciolkoszintelligence.com or use Ciolk OS (the "service"). It covers visitors to our website, people who create or are invited into a business account, and people we contact about the service.

It also explains how we handle the personal data that our customers put into the service about their own clients and patients. For that data the customer is the controller (or, under US state privacy laws, the business) and we act as its processor (or service provider). We handle it under the customer's instructions and the data processing addendum. If you are a client of a business that uses Ciolk OS and you have a question about your data, please contact that business first; we will help them respond.

022. What we collect

Account data. When you create an account we collect your name, email address, a password or third-party sign-in identity handled by our authentication provider, your role in the business, and the details of any team members you invite. If you subscribe, Stripe collects your payment details; we receive only a token, the last four digits of the card, its expiry, and billing status. We never see or store full card numbers.

Business data. The details of the business you set up: its name, sector, locations, services, prices, hours, staff and the settings you choose. Sector matters because regulated practices are placed on a specific plan.

Photos. Photos you capture or upload for analysis, quotes and evidence. Photos can contain personal data: faces, license plates, vehicle identification numbers, house numbers, documents, and in dental or medical settings, imagery of a person's mouth or body. You are responsible for having a lawful basis to take and upload each photo, including any consent required where you operate. See section 8 on protected health information.

Client records. The people your business serves, as you enter or import them: names, contact details, addresses, vehicle or property details, job and appointment history, quotes, invoices, payment status, and notes. We do not verify or enrich these records from outside sources.

Usage data. What you do in the product: features used, AI actions consumed, quotes sent, corrections made to AI output, and the timing of these events. We use this to meter plans, calibrate estimates for your own account, and understand which parts of the product are used.

Technical logs. IP address, browser and device type, pages requested, response times, error traces and security events. Logs are kept by our hosting provider and by us for a limited period and are used to run and secure the service.

Communications. Emails you send us, support conversations, security reports and, if you fill in a form on the website, the details you give us there.

033. How we use it

  • To provide the service: creating and securing accounts, storing and displaying your records, producing AI analysis you request, generating quotes, invoices and PDFs, scheduling, and processing payments through Stripe.
  • To bill you: metering AI actions against your plan, calculating overage, issuing invoices and handling failed payments.
  • To support you: answering questions, investigating problems, and sending service messages such as trial reminders, first-charge notices, receipts, and notices about changes to terms or security incidents.
  • To keep the service secure: detecting abuse, enforcing rate limits, investigating unauthorised access, and maintaining tamper-evident sealed records.
  • To improve the product: understanding aggregate usage, fixing errors, and measuring the accuracy of AI estimates using the corrections each customer makes. Corrections calibrate that customer's own future estimates only and are not pooled across customers.
  • To comply with law: keeping tax and accounting records, responding to lawful requests, and enforcing our terms.

We do not use personal data or customer content to train machine learning models, our own or anyone else's. Our AI provider processes inputs under commercial API terms that prohibit training on them.

044. Lawful bases

Where a law requires us to identify a lawful basis for processing, we rely on: performance of our contract with you, for account, business, photo, client, usage and billing data needed to deliver the service; our legitimate interests, for security, fraud prevention, product improvement and service communications, balanced against your rights; legal obligation, for tax, accounting and lawful requests; and consent, where we ask for it, for example for optional marketing email, which you can withdraw at any time.

For client records and photos that our customers upload, the customer determines the lawful basis and we process the data on the customer's instructions.

055. Cookies and analytics

We use only strictly necessary cookies: the session cookies set by our authentication provider to keep you signed in and to protect against cross-site request forgery, and a cookie recording your interface preferences if you set any. These are required for the service to work and are not used for advertising or cross-site tracking.

Our website analytics, when enabled, use Vercel Analytics, which is cookie-less and records aggregate page views and web performance without building a profile of any individual. We do not use Google Analytics, advertising pixels or social media tracking. Because we set no non-essential cookies, we do not show a cookie banner.

Do Not Track and Global Privacy Control signals: we do not sell or share personal data for advertising, so there is nothing for these signals to opt you out of. We honor them by default.

066. Who we share data with

We share personal data only with providers that help us run the service, each under a contract that restricts them to processing on our instructions:

  • Vercel — application hosting, edge network and request logs. United States.
  • Supabase — Postgres database where account, business, client and record data is stored, encrypted at rest. United States.
  • Stripe — subscription billing and payment processing, including payments your clients make to you. Stripe is an independent controller of the payment data it collects under its own privacy policy.
  • Anthropic — AI analysis of photos and text you submit for estimates, findings and drafts, under commercial API terms with no training on inputs.
  • Clerk — authentication, session management and sign-in identities.
  • Resend — transactional email such as receipts, reminders and notices, when email sending is enabled.
  • Twilio — telephony and messaging for the phone receptionist feature, when that feature is enabled for your account.

We may also disclose personal data when required by law, subpoena or court order, when necessary to protect the rights, safety or property of Ciolk, our customers or the public, or in connection with a merger, acquisition or sale of assets, in which case this policy continues to apply to the transferred data and we will notify you.

We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not give it to data brokers. We have not sold personal data in the preceding 12 months.

077. International transfers

The service is hosted in the United States and our providers process data there. If you use the service from outside the United States, your data will be transferred to and stored in the United States, where privacy laws may differ from those where you live. Where a law requires a transfer mechanism, we rely on our providers' standard contractual clauses or an equivalent recognized safeguard, and we will make the relevant terms available on request.

088. Health information

Ciolk OS is not HIPAA compliant. We do not sign Business Associate Agreements, and our providers have not signed them with us. Customers must not enter protected health information, including clinical notes, diagnoses, treatment plans, insurance claim details tied to a named patient, or dental or medical imagery that identifies a patient. If we discover such information has been entered we may delete it and suspend the account. Our current status and roadmap are described on the security page.

099. Security

All traffic between your browser and the service, and between the service and its providers, is encrypted in transit with TLS. Data at rest is encrypted by our database provider. Every request that touches business data is scoped to the requesting business in the application itself, so one customer cannot read another's records. Evidence records are sealed with SHA-256 hashes and chained daily into a Merkle root so that later alteration is detectable.

No system is perfectly secure. If you find a vulnerability, email noahciolkosz@ciolkoszintelligence.com; we acknowledge reports within 72 hours. If we confirm a breach that affects your personal data or your customer content, we will notify affected customers without undue delay and within 72 hours of confirming it, with what we know about the nature of the breach, the data involved and the steps we are taking.

1010. Retention

While your account is active we keep your data for the life of the account, because that is what the service is for. Photos are stored as part of the analysis records they belong to, not as a separate library.

After an account is terminated or closed, we keep its data for 90 days so that you can export it or reactivate, then delete it. If you ask us to delete sooner, we will, subject to the exceptions below.

We may keep a limited set of data for longer where we must: billing and tax records for as long as accounting law requires; security and abuse logs for a limited period; and the sealed evidence hashes described in section 9, which contain no record content but allow previously issued verification results to be checked. Backups are rotated on our providers' schedules and expire within a bounded period after deletion.

1111. Your rights

Wherever you live, you can ask us to: tell you what personal data we hold about you and give you a copy (access and portability); correct data that is inaccurate; delete your data; restrict or object to processing that relies on legitimate interests; and withdraw consent where processing relies on it. If you are in a jurisdiction with a data protection authority, you also have the right to lodge a complaint with it. We will not discriminate against you for exercising a right.

For residents of California and other US states with comprehensive privacy laws, this section serves as the required notice of your rights to know, delete, correct and port your data, and of the fact that we do not sell or share personal data. For residents of the European Economic Area, the United Kingdom and similar jurisdictions, these are your rights under the applicable data protection law and the lawful bases in section 4 apply.

To exercise a right, email noahciolkosz@ciolkoszintelligence.com from the address on your account, or ask us to verify your identity another way. We respond within 30 days, and sooner where we can. You may authorize an agent to make a request for you; we will ask for evidence of the authorization.

Account owners can export quotes, invoices, jobs and clients as CSV from within the product without asking us. If your data is held in a business's account as one of its clients or patients, your request should go to that business, which controls it; we will assist the business in responding.

1212. Children

The service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children as users. A customer's client records may include minors, for example a parent's dependants; the customer is responsible for that data and for any consent it requires. If you believe a child has created an account, contact us and we will delete it.

1313. Changes to this policy

We will update this policy when our practices or the law change. Material changes, including any new category of data collected, any new purpose, or any new provider that receives customer content, will be announced by email to account owners at least 30 days before they take effect. The effective date at the top of the page always shows the current version.

1414. Contact

Ciolkosz Intelligence LLC is the controller for account, usage and website data, and the processor for customer content. Privacy questions, rights requests and security reports: noahciolkosz@ciolkoszintelligence.com. A postal address for legal notices will be added once confirmed.

Questions about this document: noahciolkosz@ciolkoszintelligence.com. This is a draft pending attorney review; the version that governs is the one published on this page on the date you rely on it.