Privacy notice (pilot)
Pilot document · description last checked against the software on 26 July 2026
This is a pilot-stage document, not CAITO360's final published terms. It was written by the engineering team to describe accurately what the software does today, so that pilot users are not asked to agree to a blank page. It has not been through legal review. CAITO360's published documents will replace it, and where the two differ the published ones are the ones that count. CAITO360 is also still in its testing phase and is served from a temporary hosting address rather than its own caito360.ai domain, so the URL in your browser is not the service's permanent home and may change.
What CAITO360 stores
- Your account — email address, name, role, and department or branch if one is set. Your password is stored only as a hash, never as text you typed.
- Your workspace — the company name and details given at registration, and which users belong to it.
- Your documents — the file itself, plus what was extracted from it: its text split into passages, short text descriptions of images found inside it, a numeric representation (an "embedding") of each passage used for search, and a short summary of the document.
- Your chats — the questions you ask, the answers given, which documents each answer cited, and any thumbs up/down you leave.
- Insights — the findings written automatically from documents shared with everyone in your workspace.
- Usage records — per request, which model ran and how many tokens it used, so that cost and quotas can be accounted for.
Who processes it on CAITO360's behalf
CAITO360 does not run its own models or storage. These are the services your content reaches, and what each one receives — this list is the complete set of outbound integrations in the software as of the date above:
- Cloudflare R2 (object storage) — your uploaded files. Your browser uploads each file straight to R2 using a short-lived signed link, and the stored key never contains the filename.
- Anthropic (Claude models, via the Anthropic API) — the passages retrieved for a question plus the question itself, images found in your documents (to describe them), document text (to summarise it), and document summaries (to write insights).
- Google Cloud Vertex AI — document passages and your search queries, to turn them into embeddings and to re-rank search results.
- Microsoft 365 (Microsoft Graph) — the recipient address and message body of platform email: verification links, password resets and team invitations.
- Supabase (hosted PostgreSQL) — everything in the list above that is not the raw file.
- Vercel and Render — the hosting for the web application and for the background workers that process documents, write nightly insights and run the deletion job.
CAITO360 does not train models on your documents and has no other outbound destination for your content: there is no advertising, analytics or data-broker integration in the software, and no path by which one customer's content reaches another. What each provider above may do with data sent to its own API is governed by that provider's terms; the published notice will identify them.
Separation between workspaces and between people
- Every read and write is scoped to one workspace. There is no query in the product that returns another workspace's documents, chats or insights.
- Within a workspace, a document's visibility is enforced on every path — search, chat and insights alike. A private document is visible only to the person who uploaded it, including to owners and admins. A department document is visible to that department, plus owners and admins.
- The Insights board reads only documents shared with everyone in the workspace. Private and department documents are never used for it.
- Chat answers are built only from documents the person asking is allowed to see.
What the CAITO360 team can see
A small, explicitly configured list of CAITO360 staff addresses has access to an internal admin portal. During the pilot that portal shows workspace-level information — company name, registration details, how many users and documents a workspace has, what kinds of documents they are, and model usage and cost — which is what the approval and cost-monitoring work needs. It does not display the contents of your documents or your chats.
Separately, and as with any hosted software, engineers with production database and storage credentials are technically able to reach stored content while operating and supporting the platform.
Deletion and retention
- Deleting a document moves it to Trash and hides it from search, chat and insights immediately.
- After 30 days a scheduled job permanently deletes it: the file and any extracted images are removed from object storage, and the database rows — passages, embeddings, summary and processing records — are deleted with it.
- Making a document private removes any insights that were based on it.
- Beyond that 30-day trash window, this notice does not promise a retention period for accounts, chats or usage records; the published policy will set those.
Cookies and local storage
CAITO360 sets a session cookie when you sign in — that is what keeps you signed in, and it is required for the product to work. Your light/dark theme choice is kept in your browser's local storage so the right theme paints immediately on load. There is no advertising or analytics tracking in the application.
What this notice does not cover
This is an accurate description of what the software does with your data. It is not a complete privacy policy: it does not state the legal bases for processing, the mechanisms used for transfers of data between countries, a process for making access, correction or erasure requests, or the identity of a data controller and any representative. Those are decisions for CAITO360 to make and publish, and they will be in the final notice.
Questions about this document
If you are already using CAITO360, your workspace owner is the fastest route: they registered the workspace and can reach the CAITO360 team directly. If you are evaluating CAITO360, the CAITO360 contact who arranged your pilot access can answer questions about this document or put you in touch with someone who can.
A published contact address will accompany the final documents.