Privacy Policy

Effective Date: August 22, 2026

Introduction: The Cognitive Refinery Ethos

Cloud4Christ AI (C4CAI) is engineered as an Exoskeleton of Reason and a Vault of Confidentiality. We serve professionals bound by strict ethical and legal privilege, including Law Firms, Pastoral Counselors, and Enterprise IT. To fulfill this mandate, our Privacy Policy is not a marketing document; it is a direct reflection of our codebase’s physical architecture. We prioritize Data Sovereignty, Zero Data Retention (ZDR) for model training, and atomic data destruction.

1. Data We Collect (And Data We Refuse)

We collect only the absolute minimum data required to facilitate your access to the platform:

  • Account Data: Your email address and secure authentication tokens (JWT).
  • Billing Data: Processed securely via our PCI-compliant payment gateways (e.g., Stripe). We do not store full credit card numbers on our servers.
  • Voluntary Input: The text, documents, and images you explicitly upload during a chat session.

What We Refuse to Collect: We do not collect behavioral biometrics, device fingerprints for marketing, or shadow profiles. We do not monetize your data.

2. The Zero-Tracker Guarantee

C4CAI utilizes zero third-party marketing trackers. There is no Google Analytics, no Meta Pixel, and no advertising telemetry injected into our frontend interface. Your browsing behavior and interactions on our platform are entirely dark to the advertising industry.

3. Sub-Processors & Stateless Processing

C4CAI operates under a strict Zero Data Retention (ZDR) architecture for model training. We do not use intermediary routers. We transmit data statelessly via direct B2B Enterprise API endpoints to our sub-processors: Anthropic, OpenAI, Google, xAI, and Mistral. Under our binding Data Processing Agreements (DPAs), these sub-processors are contractually and legally prohibited from logging, retaining, or utilizing your chat data, documents, or prompts to train their models. Your data remains your exclusive intellectual property.

External Tools: If you utilize the Live Web Search tool, LLM-extracted search keywords (scrubbed of PII) are routed through our search sub-processor, Tavily. If you upload files, they are securely housed in Google Cloud Storage (GCS) solely for the duration of your session.

4. The Pre-Transmission PII Shield

To guarantee Enterprise-Grade confidentiality for professionals bound by privilege (including Attorney-Client and Pastoral Privilege), C4CAI employs a Default-ON PII Shield. Before your chat input or extracted document text (PDF, CSV, TXT, MD) leaves our servers for LLM processing, our engine automatically redacts sensitive identifiers, including SSNs, phone numbers, emails, credit cards, and API keys.

Limitation of Technology: The PII Shield operates on text strings, not pixel data. It cannot redact sensitive information embedded in raw image uploads (JPG, PNG). Users must not upload unredacted photographs of sensitive physical documents (e.g., driver’s licenses, physical case files).

5. Data Destruction (The Right to be Forgotten)

We do not utilize “soft deletes” or hidden retention logs. When you delete a chat session or your account, our backend executes an atomic Hard Delete. All conversational database records are immediately wiped. Concurrently, our storage engine issues a physical destruction command to our Google Cloud Storage buckets, permanently eradicating all associated PDFs, images, and generated Office files. Your deleted data leaves zero behavioral fingerprints on our servers. This architecture natively fulfills GDPR Article 17 (Right to Erasure) and CCPA deletion requirements.

6. Security & Encryption

All data transmitted between your browser, our servers, and our sub-processors is encrypted in transit using TLS 1.3. All persistent data (Account records, session histories pending deletion, and active storage buckets) is encrypted at rest using AES-256 encryption.

7. Compliance & User Responsibility

While C4CAI provides elite architectural safeguards to protect legally and pastorally privileged information, the User retains ultimate responsibility for data sovereignty. Users must not bypass the PII Shield when handling sensitive client data, and must adhere to their respective industry compliance frameworks (e.g., HIPAA) regarding the transmission of raw Protected Health Information (PHI).

8. Contact Information

For privacy inquiries, data export requests, or compliance audits, please contact our Data Protection Officer at:

Privacy & Data Protection
privacy@c4cai.org
Company
Grace Technology
Location
Longview, TX, United States
Website
c4cai.org

See also our Terms of Service.