Legal

Privacy Policy

This Policy explains how Colzera handles information when you create a baseline, model a decision, run live research, or manage an account.

Effective and last updated July 21, 2026

1. Information we collect

Account information. Email address, name, authentication provider, selected plan, billing interval, and account identifiers. If you use Google sign-in, Google and Supabase provide the information needed to authenticate you.

Decision information. Baseline values you choose to save, prompts, generated forms, answers, reports, assumptions, scenarios, timelines, follow-up conversations, live-research requests, source links, and outcomes you record.

Technical information. Authentication cookies, browser or device information, IP address, timestamps, request and error logs, and service-security or usage information generated when you use Colzera.

Payment information. If paid billing is offered, the payment provider processes card or bank details. Colzera may receive billing status, transaction identifiers, plan, and limited payment metadata rather than complete card numbers.

2. Where information is stored

Your current baseline and recent decision history may be stored in your browser. When you are signed in and memory is enabled, Colzera also stores decision reports, follow-up jobs, and recorded outcomes in the private portion of our Supabase database so they can support later decisions. Authentication sessions are stored using secure cookies.

Turning baseline memory off prevents saved profile values from being included with new requests. Local controls and cloud records are separate; clearing browser storage does not necessarily delete information already associated with your signed-in account.

3. How we use information

We use information to authenticate users; generate forms, research, reports, comparisons, and timelines; personalize decisions from context you approve; preserve and recover background jobs; enforce plan limits; provide support; maintain security; prevent misuse; diagnose failures; improve performance; communicate about accounts; and comply with legal obligations.

Colzera does not sell personal information. Colzera does not use your approved baseline to retrain the underlying third-party foundation model unless we clearly disclose that use and obtain any consent required by law.

4. AI processing and web research

To respond to a request, relevant approved profile values and decision details may be sent to the configured AI provider, currently Google Gemini or OpenAI depending on deployment settings. Requests requiring current information may use the provider’s web-search tools. Search queries can reveal the general subject, location, budget, or constraints needed to find useful results, so avoid entering information that is not necessary.

AI providers and search or listing websites process information under their own terms and privacy practices. Generated reports identify live research when available and attach sources so you can verify material facts.

5. Service providers and disclosure

We disclose information only as reasonably necessary to operate Colzera, including to hosting and infrastructure providers such as Vercel; authentication and database services such as Supabase; AI and search providers such as Google or OpenAI; transactional-email services such as Resend; and payment providers if billing is enabled.

We may also disclose information when required by law; to protect users, the public, our rights, or the security of the Service; in connection with a merger, financing, acquisition, reorganization, or asset sale subject to appropriate protections; or with your direction or consent.

6. Retention and deletion

We retain information for as long as needed to provide the Service, maintain account and transaction records, resolve disputes, prevent abuse, and meet legal obligations. Retention differs by data type. Backups and security logs may remain for a limited period after deletion.

The Profile page lets you inspect or delete browser-stored baseline and history data. Signed-in users may request access, correction, export, or deletion of account-associated information through the support contact made available in the Service. We may verify identity before completing a request, and some records may be retained where law permits or requires.

7. Security

We use reasonable administrative, technical, and organizational safeguards, including account authentication and database row-level access controls. No storage or transmission method is completely secure. Protect your login credentials and do not submit passwords, government identifiers, complete financial account numbers, private medical records, or information you are not authorized to use.

8. Your choices and rights

You can edit your local baseline, disable its use in new decisions, clear local data, sign out, and choose whether to use Google or email authentication. Depending on where you live, you may have additional rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal certain privacy decisions.

We will not discriminate against you for exercising a privacy right. Some features cannot work without the information necessary to provide them.

9. Children

Colzera is not directed to children under 13. Users under the age of legal majority may use the Service only through an account created and supervised by a parent or legal guardian. If you believe a child provided personal information improperly, contact us through the support channel available in the Service.

10. Changes and contact

We may update this Policy as Colzera changes. If an update materially affects how we use personal information, we will provide reasonable notice through the Service, by email, or as required by law. Questions and privacy requests may be submitted through the support contact made available in your account.