Skip to content
CDSBench
Privacy

Privacy policy — draft for counsel review

Every line describes what the current code does. The legal framing — lawful bases, data-subject rights, the controller’s identity — needs professional drafting before launch.

DRAFT — requires review by qualified counsel before public launch.
What is collected
An email address when you run a private analysis or follow a model, entity or topic; the documents and instrument details you submit for analysis; the results; a voluntary role; anonymous first-party product events (page views, clicks, timings) keyed by a random visitor id; billing identifiers from Stripe (customer, subscription and price ids — never card numbers).
Analytics
First-party events carry ids, event names, paths of public pages and aggregate metadata — never document text, private results or evidence excerpts. Google Analytics is not configured on this deployment. Founder traffic is excluded. Bots are dropped at ingest.
Customer documents
Uploaded documents are parsed on the CDSBench server and stored with the result in the CDSBench database (Cloud SQL, europe-west1) against your email. They are customer-private: not published, not in the benchmark, not searchable, not indexed, not used to train models. Restricted share links you create are random, expiring and revocable. Exactly what the code does →
Model providers
This deployment runs in mock mode: no document text is sent to any external model provider. When live providers are enabled this section lists each vendor, what is sent, its retention setting and its training setting, and a per-source policy decides before every call whether the data may be sent at all.
Billing
Payments are processed by Stripe on Stripe-hosted pages. CDSBench receives and stores the Stripe customer, subscription, price and invoice identifiers and the billing email; card details never touch CDSBench servers.
Retention
Private analyses and their documents are retained until you ask for deletion; there is no automatic expiry yet. Analytics events are retained indefinitely in aggregate form. Backups follow the hosting provider's standard backup window and carry the same classification as the live data; deletion requests are applied to backups as they age out.
Deletion and access
Email the address you used with the subject “delete my analyses” and the records are removed by hand. Self-service deletion and data export are not built yet. (counsel: data-subject rights procedure, timelines)
Cookies
A signed HttpOnly session cookie after email confirmation or checkout; a founder-traffic flag cookie; the consent choice for analytics. No advertising cookies.
Contact
Privacy and rights questions: rights@cdsbench.com. (counsel: controller identity, address, supervisory authority)
Related

Other policies