COMPAS3 AI Privacy Policy
Effective date: July 22, 2026
This Privacy Policy explains what personal information COMPAS3 AI collects, why we collect it, who we share it with, and what rights you have. It covers our website at compas3.ai, the Aletheia application at app.aletheia.compas3.ai, and any API we make available (together, the "Service").
Please read it alongside our Terms of Use and our Cookie Policy.
Who we are
COMPAS3 AI is the controller of the personal information described in this policy, except where we act as a processor as described under "Content you submit" below.
You can reach us about privacy at [email protected].
What we collect
Account information. Your email address, password (stored hashed, never in plain text), display name and profile image if you provide one, and the identity provider you used if you signed in through a third party.
Organisation information. The organisation your account belongs to, your role in it, other members, and your organisation's credit balance, credit expiry and transaction history.
Content you submit. The documents, reports, claims, prompts and files you upload or enter for verification, and the results the Service produces from them. We refer to this as Customer Content, and it is dealt with separately below.
Billing information. A record of your purchases, amounts, dates and credit grants. Payment card details are collected and stored by Stripe, our payment processor. We never see or store your full card number.
Technical and usage information. IP address, browser and device characteristics, pages visited, timestamps, referring page, page performance measurements, and logs of requests to our API, including errors and rate limit events.
Communications. Messages you send us by email or through support and feedback channels, and our replies.
We do not knowingly collect information from anyone under 18. The Service is intended for business and professional use. If you believe a child has provided us with information, contact us and we will delete it.
Content you submit, and how AI processing works
This section is the most important part of this policy for anyone uploading documents to Aletheia.
To verify a claim, the Service sends the text of your Customer Content, or extracts from it, to third-party large language model providers for analysis, and sends search queries derived from your claims to third-party web search providers to gather evidence. It then retrieves and reads publicly available web pages cited in those results. This processing is inherent to how the product works.
What this means in practice:
- Your Customer Content leaves our infrastructure and is processed by the AI providers listed below.
- Those providers may be located outside the United Kingdom and the European Economic Area. See "International transfers".
- We do not use Customer Content to train our own models, and we select AI providers on terms that do not permit them to use content submitted through their APIs to train their models.
- We do not publish your Customer Content, show it to other customers, or sell it.
- Search queries derived from your claims are visible to the search providers we use. Do not submit claims whose wording alone would disclose something you cannot share with a third-party search engine.
If your Customer Content contains personal data about other people, you are the controller of that data and we process it on your behalf as a processor, on the instructions embodied in your use of the Service and in our Terms of Use. You are responsible for having a lawful basis for providing it to us. Business customers who need a data processing agreement should contact [email protected].
Please do not upload special categories of personal data, such as health, biometric, racial, political or trade union data, or payment card numbers or government identifiers, unless we have agreed to it in writing. The Service is not designed for that content.
How we use information, and our legal bases
| Purpose | Legal basis (UK and EU GDPR) |
|---|---|
| Creating and administering your account and organisation, and delivering verification results | Performance of a contract |
| Processing payments, granting and expiring credits, and keeping billing records | Performance of a contract, and legal obligation for tax and accounting records |
| Providing support and responding to your messages | Performance of a contract, and legitimate interests in supporting our customers |
| Securing the Service, preventing abuse and fraud, enforcing rate limits, and investigating incidents | Legitimate interests in keeping the Service secure and available |
| Measuring performance and reliability, and improving the Service using aggregated statistics | Legitimate interests in improving our product |
| Sending marketing emails about our products | Consent, or legitimate interests where permitted for existing customers. You can opt out at any time |
| Complying with law, and responding to lawful requests from authorities | Legal obligation |
Service, security and billing emails are transactional. You will continue to receive them while you hold an account, even if you opt out of marketing.
Who we share information with
We do not sell your personal information, and we do not share it with advertising networks. We share it only with the service providers below, who act on our instructions under written terms requiring confidentiality and appropriate security.
Infrastructure and operations
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication and file storage | Account details, organisation records, uploaded documents, verification results |
| Railway | Application and API hosting | All data processed in transit by the Service |
| Vercel | Marketing site hosting and page performance measurement | IP address, browser and page performance data |
| Stripe | Payment processing for credit purchases | Email address, payment card details (collected by Stripe, never by us), transaction records |
| Resend | Transactional email (account confirmation, password reset) | Email address, message content |
AI model providers
The Service routes claim extraction and verification to one or more of the following providers. Which provider handles a given request depends on our configuration at the time.
| Provider | Purpose | Data involved |
|---|---|---|
| OpenAI | Claim extraction, verification and reasoning | Document text, claims and prompts submitted for processing |
| Anthropic | Claim extraction, verification and reasoning | Document text, claims and prompts submitted for processing |
| Google (Gemini) | Claim extraction, verification and reasoning | Document text, claims and prompts submitted for processing |
| Alibaba Cloud (Model Studio / Qwen) | Claim extraction, verification and reasoning | Document text, claims and prompts submitted for processing |
| DeepSeek | Claim extraction, verification and reasoning | Document text, claims and prompts submitted for processing |
Evidence retrieval
| Provider | Purpose | Data involved |
|---|---|---|
| Brave Search, SerpAPI, Tavily, You.com and Andi | Web search used to gather evidence for a claim | Search queries derived from the claim being verified |
We may also disclose information: to investigate, prevent or act on suspected illegal activity, fraud, threats to the safety of any person, or breaches of our Terms of Use; where required by law, court order or a valid request from a regulator or law enforcement; to our professional advisers; and to a buyer or successor in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply.
We may publish aggregated or de-identified statistics that cannot be traced back to you, your organisation or your Customer Content.
We update this list as our providers change. Business customers who need advance notice of subprocessor changes should contact [email protected].
International transfers
Our providers operate in a number of countries, including the United States, the European Union, Singapore and the People's Republic of China. Personal information and Customer Content may therefore be transferred outside the United Kingdom and the European Economic Area, including to countries that have not been the subject of an adequacy decision.
Where we make such a transfer, we rely on appropriate safeguards, which for most providers means the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by technical measures including encryption in transit. You can ask us for details of the safeguards applying to a particular provider by writing to [email protected].
If your organisation cannot permit processing in a particular country, contact us before uploading content. We can discuss restricting your traffic to a specific set of providers under an enterprise agreement.
How long we keep information
| Information | Retention |
|---|---|
| Account and organisation records | For as long as your account is open, then deleted on request or when the account is closed |
| Customer Content and verification results | Until you delete it, or until your account is closed. Deleted content may persist in encrypted backups for a limited period before being overwritten |
| Billing and transaction records | Retained as required by tax and accounting law, typically six years |
| Security, access and API logs | Retained for a limited period for security and troubleshooting, then deleted or aggregated |
| Support correspondence | Retained while needed to handle your request and to resolve any related dispute |
We may retain information from closed accounts where we need it to comply with law, prevent fraud, resolve disputes or enforce our Terms of Use. Anything we retain stays subject to this policy.
Security
We take reasonable technical and organisational measures to protect your information, including encryption in transit, encryption at rest for stored data, access controls that restrict data to the personnel who need it, tenant isolation between organisations enforced at the database level, and rate limiting and abuse controls on our APIs.
No system is completely secure and we cannot guarantee absolute security. Use a strong, unique password and do not reuse it on other sites. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority where the law requires it. Report a suspected vulnerability or account compromise to [email protected].
Automated decision-making
The Service uses automated processing to produce verification results. Those results are informational, are intended for review by a person, and do not by themselves produce legal or similarly significant effects on any individual. We do not use your personal information to make automated decisions about you in the sense of Article 22 of the UK and EU GDPR.
Your rights in the UK and EEA
If you are in the United Kingdom or the European Economic Area, you have the right to access your personal information, to have it corrected or erased, to restrict or object to how we process it, to withdraw consent where we rely on it, and in some cases to receive your information in a portable format. Some of these rights apply only in specific circumstances.
To exercise any of them, email [email protected] with the subject line "Data privacy request" and tell us what you would like us to do. We will respond within one month, and will tell you if we need longer because the request is complex. We may need to verify your identity first.
To close your account and delete your personal data, email us with the subject line "Account deletion". Deleting your account removes your access and your Customer Content, and forfeits any unused credits, as set out in our Terms of Use.
You can opt out of marketing emails using the unsubscribe link in any marketing message, or by contacting us. If you are unhappy with how we have handled your information, please raise it with us first. You also have the right to complain to your local supervisory authority. In the United Kingdom that is the Information Commissioner's Office at ico.org.uk.
Your rights in California
If you are a California resident, you have the right to know what personal information we collect, use and disclose, to request access to it and a copy of it, to request correction or deletion, and to limit our use of sensitive personal information. The categories of personal information we collect are set out under "What we collect" above, the purposes are set out under "How we use information", and the categories of recipients are set out under "Who we share information with".
We do not sell or share personal information as those terms are defined under the CCPA and CPRA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
Submit a request by emailing [email protected]. You may use an authorised agent, in which case we will ask for proof of their authority. We will not discriminate against you for exercising your rights: we will not deny you the Service, charge you a different price, or give you a lower quality of service.
Changes to this policy
We may update this policy. We will change the effective date at the top and, where the change is material, tell you by email or in the application before it takes effect.
Contact
Questions about this policy or about how we use your personal information should be sent to [email protected].