Privacy Policy
Last updated: August 10, 2026
This policy explains what data CitedPlan, operated by Kame House Studios LLC (“we”, “us”), collects, how we use it, and the choices you have. The short version: we collect what we need to run the service, we send your documents to AI providers only to power the features you use, and we do not sell your data or show ads.
1. Data we collect
- Account data. Your email address and, if you sign in with Google, your name and basic profile information. Authentication is handled by Supabase; we never see or store your password in our own database.
- Content you provide. Documents you upload or paste, the project boards extracted from them, and your chat messages with the AI assistant.
- Billing data. Payments are processed by Stripe. We store your subscription status and Stripe customer reference — never your card number.
- Usage data. Counts of extractions and AI chat actions per workspace (used to enforce plan limits) and AI token usage for cost tracking.
- Technical data. Server logs and error reports (via Sentry), which may include your IP address and browser information.
2. How we use it
We use this data to provide and improve the service: extracting boards from your documents, answering chat messages, enforcing plan limits, processing subscriptions, securing the service, fixing errors, and responding to support requests. We do not sell personal data and we do not use your content for advertising.
3. AI processing
When you run an extraction or use the chat, the relevant content is sent to our AI providers — Anthropic (Claude models) for extraction and chat, and Voyage AI for document embeddings — as our service providers. Under their API terms, these providers do not use API content to train their models.
4. Service providers
We share data only with the providers that run the service:
- Supabase — database, authentication, and file storage
- Anthropic — AI extraction and chat
- Voyage AI — document embeddings
- Stripe — payment processing
- Vercel — web app hosting
- Railway — API hosting
- Sentry — error monitoring
We may also disclose data if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to data collected under it).
5. Storage and security
Data is encrypted in transit. Access to workspace data is enforced at the application layer and again at the database layer with row-level security, so members of one workspace cannot read another’s data. Uploaded files live in a private storage bucket scoped the same way. No system is perfectly secure, but access to production systems is limited to what operating the service requires.
6. Retention and deletion
We keep your data while your account is active. Deleting a project or workspace deletes its documents, boards, and chat history. To delete your account and all associated data, email us at the address below and we will complete the deletion within 30 days.
7. Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these rights, email us — we will respond within the timeframe the applicable law requires. We do not discriminate against you for exercising them.
8. Cookies and local storage
We use browser storage only to keep you signed in (your Supabase session). We do not use third-party advertising or cross-site tracking cookies.
9. Children
CitedPlan is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the service evolves. If a change is material, we will give notice (for example by email or an in-app notice) before it takes effect. The date at the top always reflects the latest revision.
11. Contact
Privacy questions or requests: kamehousestudiosllc@gmail.com