1. Introduction
Thank you for choosing Cipher. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our personal knowledge management platform.
If you have any questions or concerns about this privacy policy or our practices, please contact us at [email protected].
2. Information We Collect
We collect several types of information for various purposes:
Personal Information You Provide:
- Account information (email address, name)
- Journal entries and personal notes
- Goals and reflections
- Profile preferences
Automatically Collected Information:
- Device information (IP address, browser type, device type)
- Usage data (interaction with features, time stamps)
- Location data (based on IP address)
- Contextual metadata (weather, device information)
3. How We Use Your Information
We use your information for the following purposes:
- To provide and maintain our Service
- To process and analyze your journal entries using our AI infrastructure
- To generate insights and patterns from your data
- To communicate with you about service updates
- To process your subscription payments
- To protect our Services from misuse
Important: We do not sell your data or use it to train generalized AI models.
4. AI Processing and Data Security
Our AI infrastructure includes:
- Integration with OpenAI, Anthropic, and Google AI models for analysis
- Self-hosted PostgreSQL and Qdrant databases for secure storage
- End-to-end encryption for data in transit (TLS 1.3)
- AES-256 encryption for data at rest
- Regular security audits and updates
While we implement comprehensive security measures, no method of electronic storage or transmission is 100% secure. We strive to protect your personal information but cannot guarantee its absolute security.
5. Data Sharing and Third Parties
We use various third-party services to operate, maintain, and improve our Service. Here's a comprehensive list of our service providers and how they process your data:
AI and Analysis Services:
- OpenAI, Anthropic, Google - Process journal entries for insights generation
Infrastructure and Hosting:
- Amazon Web Services (AWS) - Cloud infrastructure provider for hosting and scaling our services
- Self-hosted ELK Stack (Elasticsearch, Logstash, Kibana) - Internal logging and monitoring
- Honeycomb.io - Application performance monitoring and distributed tracing
Analytics and Usage Tracking:
- Google Analytics - Website analytics and user behavior tracking (collects anonymized usage data, IP addresses, and device information)
Payment Processing:
- Stripe - Secure payment processing for subscriptions (handles payment information, we never store credit card details)
Data Processing Commitments:
- All service providers are carefully selected and contractually bound to maintain data privacy and security
- We only share the minimum information necessary for each service to function
- All data processing complies with Australian Privacy Principles and applicable data protection laws
- Where possible, we use self-hosted solutions to minimize data exposure
Note: Our Google Analytics implementation is configured to respect user privacy by anonymizing IP addresses and disabling data sharing for advertising purposes.
6. Your Rights and Choices
Under the Australian Privacy Principles (Privacy Act 1988), you have the following rights:
- To be informed about the collection and use of your personal information
- To request access to your personal information we hold
- To request correction of your personal information if it is inaccurate, out-of-date, incomplete, irrelevant, or misleading
- To make a complaint if you believe we have breached the Australian Privacy Principles
- To request information about whether we will disclose your information overseas
Additional rights we provide:
- To export your data in a machine-readable format
- To delete your account and associated data
- To opt-out of non-essential data collection and processing
For more information about your privacy rights, visit the Office of the Australian Information Commissioner's website at www.oaic.gov.au.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymize your information unless required to retain it by law.
8. Children's Privacy
Our Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us.
9. Changes to Privacy Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date.
10. Contact Information
If you have any questions about this Privacy Policy, please contact us at:
[email protected]