Privacy Policy
Effective date: 2026-07-07 (draft) · Version: 0.11 (updated 2026-09-17: named the delegated-credentials vault and meeting recordings explicitly; same-day privacidad remediation added Section 6, data about non-users processed via CRM/meetings, and made the registered-agent placeholder an explicit owner-pending item; same-day "datos" audit precised Section 10's export/deletion scope and added Section 9's file-storage retention windows to match what the code actually does)
This Privacy Policy explains how CINTA ("CINTA", "we", "us") collects, uses, shares and protects personal data when you use the CINTA platform and related services (the "Service").
Draft v0.9 — pending review by licensed counsel before production use. Have counsel review against Colombia's Ley 1581 de 2012 (Habeas Data) and, for EU/UK users, the GDPR/UK-GDPR. This document is written to be accurate to the platform's real architecture — do not add claims the product does not honor (Constitution §VI: never mislead about what we do).
1. Who we are (Data Controller)
The data controller is TXR Enterprises LLC, a Wyoming, United States limited liability company, [PENDING — registered agent name and street address, Wyoming; owner to provide before this document leaves draft status], operating the CINTA platform. Contact: privacy@cinta-ai.com (DPO / privacy contact: privacy@cinta-ai.com).
2. What data we process
Account & identity: name, email, authentication identifiers, workspace membership and role.
Content you provide: chat messages, documents, files, automations, memory entries, and connected-account data you authorize us to access.
Connected services (OAuth): when you connect a provider (e.g. Google, GitHub), we store the access/refresh tokens encrypted at rest (AES-256-GCM) and only the scopes you grant.
Third-party site credentials (delegated vault): if you choose to have CINTA log into a third-party site on your behalf (a site with no OAuth support), we store that site's login encrypted at rest (AES-256-GCM), server-decryptable so CINTA can act for you. This is more sensitive than the OAuth tokens above, because CINTA itself can decrypt it to perform the delegated action — it is separate from the zero-knowledge vault the platform also uses for cases where CINTA never needs to read the secret back. You control which sites are in this vault and can remove one at any time.
Meeting recordings: if you use the meeting bot, we process the meeting's audio/video through our transcription providers (Section 5/Subprocessors) and store the transcript, summary, action items and any clips you generate.
Usage & telemetry: feature usage, workflow/execution metrics, model-routing cost/latency, error diagnostics, and audit logs (security and billing events).
Billing: plan, subscription status and payment events. Card data is handled by our payment processor — we do not store full card numbers.
3. How we use it (purposes & legal bases)
Provide the Service (contract): run your agents, automations, memory, and integrations.
Hybrid AI routing (contract/legitimate interest): we route inference locally on capable hardware or to cloud model providers; see Subprocessors.
Security & abuse prevention (legal obligation / legitimate interest): authentication, rate-limiting, audit trails, anti-fraud.
Billing & metering (contract): subscriptions, credits, usage caps, dunning.
Product improvement (legitimate interest, with controls): aggregated/diagnostic analytics. We do not sell personal data.
4. AI processing & training
We do not train foundation models on your content. Cloud model providers process your prompts only to return a response, under their API terms (no training on API data where the provider offers that guarantee).
You can prefer local-only execution where your hardware supports it, keeping data on-device (Constitution: Autonomy + Freedom; CLAUDE.md Rule #1 hybrid).
5. Sharing & subprocessors
We share data only with subprocessors that help us run the Service (model providers, payment processor, hosting, error tracking). The current list and their roles are in Subprocessors. We require each to protect data under terms no less protective than this Policy.
6. Data about people who are not CINTA users
If you use CINTA's CRM features to manage your own clients or service providers, or you invite a service provider or business contact into a CINTA-hosted quote, project, or meeting, we process personal data about that third party on your instructions — they did not sign up for CINTA and CINTA is a data processor for that data, with you (the account holder) as the controller. This includes: name, email, phone, company, notes, and activity history for CRM clients and providers (crm_clients, crm_providers, crm_client_events in the schema), and the name/identity of meeting participants who join a call the meeting bot records, along with their voice in the resulting audio/transcript. We do not use this data for our own purposes; it is retained and deleted under the same rules as the rest of your workspace's data (Section 9), and a data-subject request from one of these third parties should be routed to you as the controller unless law requires us to respond directly.
7. Multi-tenancy & isolation
CINTA is multi-tenant. Each workspace's data is isolated by a workspace_id boundary enforced at the application layer, with database row-level security as a second layer for tenant separation. The platform owner does not access customer data except as needed to operate or support the Service, and such access is audited (Constitution §VII, Principio 2: customer data is sacred).
8. International transfers
Cloud providers may process data in the US/EU/Asia. Where required, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses). EU data-residency options are available on request for eligible plans.
9. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, subject to legal/accounting retention. You can request earlier deletion (Section 10).
Two file-storage areas are deleted on a fixed schedule, independent of account status:
Studio uploads & generated outputs (files you upload to or generate through CINTA Studio): deleted automatically 30 days after last modification (configurable server-side; 30 days is the default). Deleting your account also erases any of your Studio files still within that window.
Browser-extension captures (screenshots, page snapshots, console/network logs the CINTA browser extension records at your request): deleted automatically 30 days after capture. These are matched to your account and removed early on account deletion only when captured while signed in; older captures and ones recorded without an active session are removed solely by this 30-day schedule, not by account deletion (Section 10).
10. Your rights (DSR)
Subject to applicable law (Ley 1581 / GDPR), you may access, correct, delete, export (portability), object to or restrict processing, and withdraw consent. Request these at privacy@cinta-ai.com. Export is self-service in the product (covers your database records; it does not include the file bytes of Studio uploads/outputs or browser-extension captures, which you can still download individually before requesting deletion). Deletion is currently handled manually by our team on request at the address above — it removes your workspace's database records plus your Studio and (where matched to your account — see Section 9) browser-extension files, the same scope self-service deletion will have once it ships. We respond within the legally required timeframe.
11. Security
Encryption in transit (TLS) and at rest for sensitive secrets (OAuth tokens, AES-256-GCM), least-privilege access, audit logging, rate-limiting and secret rotation. Report vulnerabilities via /.well-known/security.txt. No method is 100% secure; we work to protect your data and notify you of breaches as required by law.
12. Children
CINTA is not directed to children under the age of 18. We do not knowingly collect their data.
13. Cookies & local storage
CINTA does not use tracking, analytics, or third-party advertising cookies.
cinta_session— essential,HttpOnly, used solely to authenticate your session. Without it the Service cannot function.cinta_locale— functional preference cookie that remembers your chosen interface language. We treat this as strictly-necessary/preference use exempt from consent banners, subject to confirmation by counsel per jurisdiction.The public landing site uses
localStorageon a first-party basis only to hold your own waitlist-form state in your browser. That data is not tracking, is not transmitted to any third party, and is not linked to an advertising identifier.We do not sell personal data, and we do not use cookies or local storage to build cross-site advertising profiles.
14. Data retention — trial accounts
Trial-account data is automatically deleted 30 days after trial expiration, with advance notice to the account holder before deletion. The deletion sweep and notice mechanics are covered by our data-retention policy in deployment; see Section 10 to request earlier deletion or export at any time.
15. Changes
We will post updates here with a new version/date and, for material changes, notify you in-product or by email.
16. Contact
Privacy: privacy@cinta-ai.com · Controller: TXR Enterprises LLC [PENDING — registered agent address, Wyoming; owner to provide before this document leaves draft status] · Colombia Habeas Data complaints may also be filed with the SIC (Superintendencia de Industria y Comercio).
Draft v0.11 — pending review by licensed counsel before production use. Last updated: 2026-09-17 (draft).
