Back to home
CoreCtic AIPrivacy & GDPR

Privacy Policy

Last updated: March 1, 2026 · GDPR compliant

At CoreCtic AI, protecting your data is a priority. This policy explains how we collect, use and protect your personal data, in accordance with the General Data Protection Regulation (GDPR — EU 2016/679).

1. Data controller

CoreCtic AI SAS, registered with the Paris Trade and Companies Register (RCS), is the controller of your personal data. For any question regarding your data, contact our DPO at: privacy@corectic.ai

2. Data we collect

CoreCtic AI collects the following data: • Identity data: first name, last name, email address, company name, registration number (optional) • Usage data: API call logs (model used, number of tokens, estimated cost, timestamp) • Technical data: IP address, browser, interface preferences (language, currency, theme) • Payment data: processed exclusively by our PCI-DSS certified payment provider (Stripe). CoreCtic AI stores no banking data.

3. Purposes of processing

Your data is processed to: • Provide and improve CoreCtic AI services (legal basis: performance of the contract) • Calculate and display your AI consumption statistics (legal basis: performance of the contract) • Send service-related communications, invoices and alerts (legal basis: legitimate interest) • Meet our legal and accounting obligations (legal basis: legal obligation) • Improve the user experience through anonymized aggregated analytics (legal basis: legitimate interest)

4. Data retention

Usage logs are kept for a rolling 24 months. Account data is kept for the entire duration of the subscription, then an additional 36 months for accounting and legal purposes. You may request the deletion of your data at any time (see "Your rights").

5. Data sharing

CoreCtic AI never sells your data to third parties. Your data may be shared with the following sub-processors, all bound by a GDPR-compliant Data Processing Agreement (DPA): • Supabase (database hosting) — secure infrastructure, AWS EU-West-1 servers • Stripe (payments) — PCI-DSS Level 1 certified, servers in the United States (transfers covered by SCCs and the EU–US Data Privacy Framework) • Vercel (application hosting) — secure cloud infrastructure, AWS US-East-1 servers with EU Standard Contractual Clauses • Tinybird (real-time analytics) — ClickHouse storage, AWS EU-West-1 servers, anonymized and aggregated data • Upstash (Redis cache & vector store for semantic caching) — EU servers, ephemeral data with automatic TTL • Cloudflare (infrastructure proxy network, DDoS protection) — global Edge network, no personal data stored permanently • Resend (transactional email delivery) — servers in the United States, transfers covered by SCCs • Sentry (technical error monitoring) — servers in the United States, transfers covered by SCCs • Microsoft Clarity (audience measurement and heatmaps, loaded only after your consent) — Microsoft, servers in the United States, transfers covered by the EU–US Data Privacy Framework • Google Analytics & Google Tag Manager (audience measurement, loaded only after your consent) — Google, servers in the United States, transfers covered by the EU–US Data Privacy Framework Sub-processors located outside the European Union carry out their transfers on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46 GDPR) and/or their certification under the EU–US Data Privacy Framework. Audience measurement tools (Microsoft Clarity, Google Analytics) are only activated after your consent is collected via the cookie banner, and can be refused or withdrawn at any time.

6. Security

CoreCtic AI applies the following security measures: • Encryption in transit (HTTPS/TLS 1.3) • Encryption at rest for sensitive data • Row Level Security (RLS) on all tables — each user only accesses their own data • Third-party API keys masked in the database (only the last 4 characters are visible) • Secure authentication via Supabase Auth (PKCE, short sessions)

7. Your rights (GDPR)

In accordance with the General Data Protection Regulation (GDPR), you have the following rights: • Right of access to your personal data • Right to rectification of inaccurate data • Right to erasure ("right to be forgotten") • Right to data portability • Right to object to processing • Right to restriction of processing To exercise these rights, contact us at: privacy@corectic.ai. You also have the right to lodge a complaint with your data protection authority (in France, the CNIL — www.cnil.fr).

8. Cookies

CoreCtic AI uses cookies strictly necessary for the service to function (authentication session). Audience measurement tools (Google Analytics, Microsoft Clarity) are only loaded after your consent via the cookie banner and can be refused or withdrawn at any time. Interface preferences (theme, language) are stored in localStorage, without transmission to third-party servers.

9. Changes

This policy may be updated periodically. In the event of a substantial change, you will be notified by email at least 30 days before the changes take effect.

Data Protection Officer

privacy@corectic.ai
TermsLegal notice