Privacy Policy
Last updated: June 2025
1. What we collect
When you sign in with Google we receive your name, email address, and profile picture as provided by Google. We store these to identify your account and personalise your experience.
We also collect information you create within Ceren — such as feedback items, roadmap entries, and changelog releases — to provide the service.
2. How we use your data
- To provide, operate, and improve Ceren.
- To send transactional emails such as invitations and account notices.
- To process billing via Stripe (we never store card details ourselves).
- To respond to support requests.
We do not sell your data or use it for advertising.
3. Data storage
Your data is stored on servers within the EU/EEA. We use Neon (PostgreSQL) for database storage and Vercel for hosting. Both providers comply with applicable data protection regulations.
4. Third-party services
We use a small number of trusted third parties to run the service:
- Google OAuth — authentication only. We do not access your Google Drive, Gmail, or any other Google data.
- Stripe — payment processing. Stripe's privacy policy applies to payment data.
- Vercel — hosting and edge network.
- Neon — database hosting.
5. Cookies
We use a single session cookie to keep you logged in. We do not use tracking, analytics, or advertising cookies.
6. Your rights
You can delete your account at any time from your account settings. This permanently removes your personal data from our systems. You also have the right to request a copy of your data or ask us to correct inaccuracies.
7. Data retention
We retain your data for as long as your account is active. When you delete your account, your personal data is removed within 30 days. Organisation data is retained until the organisation is deleted.
8. Contact
For privacy questions or data requests, please email privacy@ceren.app.