Privacy Policy
Last updated July 29, 2026
This Privacy Policy explains how Candor ("we", "us") collects, uses, and safeguards personal data when you use our website and services (the "Service"). This page is maintained by the operators of Candor and should be reviewed by qualified legal counsel before production launch in your jurisdiction.
1. Who we are
Candor is operated by the Candor team. For privacy questions or to exercise your rights, contact privacy@candor.app.
2. Data we collect
- Account data: full name, organization, email address, hashed password, and the date you accepted our Terms.
- Usage data: the briefs you generate, entities you research, optional focus-area preferences, and follow-up questions.
- Technical data: minimal server logs (IP, user agent, timestamps) for security and abuse prevention.
- Cookies: a single strictly-necessary session cookie set by our authentication provider. See our Cookie Policy.
3. How we use your data
- Provide, secure, and improve the Service.
- Generate research briefs you request.
- Communicate essential account and service notices.
- Comply with legal obligations and enforce our Terms.
4. Legal bases (EU/UK GDPR)
- Contract — to deliver the Service you signed up for.
- Legitimate interests — security, fraud prevention, and service improvement.
- Consent — where required, e.g. optional analytics cookies (currently none in use).
- Legal obligation — to comply with applicable law.
5. Subprocessors
We rely on the following processors to operate the Service:
- Lovable Cloud (managed backend, authentication, database, hosting).
- Google — Gemini API (AI synthesis, via the Lovable AI Gateway). Prompts and entity names are sent for processing.
- Firecrawl (web search and retrieval used during brief research).
Data may be processed in the United States and other countries. International transfers rely on Standard Contractual Clauses or equivalent safeguards.
6. Retention
Account and brief data are retained while your account is active. When you delete your account, your profile, briefs, and follow-ups are erased within 30 days, except where retention is required by law.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to lodge a complaint with a supervisory authority. California residents have equivalent rights under the CCPA/CPRA including the right to know, delete, correct, and limit use of sensitive personal information. We do not sell or share personal data as those terms are defined under the CCPA.
You can export or delete your data directly from your Account page, or email privacy@candor.app.
8. Security
Data is transmitted over HTTPS, stored with row-level access controls, and authenticated sessions use HTTP-only cookies. No system is perfectly secure; we encourage strong, unique passwords.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
10. Changes
We may update this Policy. Material changes will be announced in the Service or by email. Continued use after an update constitutes acceptance of the revised Policy.
11. Contact
Questions or requests: privacy@candor.app.