1. Scope: Managed Cial and OpenCial
This Privacy Notice applies to Managed Cial accounts, managed workspaces, billing, support and the public cial.app website.
OpenCial refers to Cial source code when it is separately distributed as open-source software. This notice does not govern data processed solely in an independently self-hosted OpenCial deployment. The self-hosting operator determines that deployment’s processing, providers, security, retention and legal obligations. If that operator separately uses Managed Cial or support supplied by Techforces, this notice applies only to that separate service.
2. Controller and contact
The Techforces project, based in France and currently in the process of formation, determines why and how personal data is processed for Managed Cial and acts as controller for that processing. Techforces is not represented here as an incorporated company. Its final legal identity, postal address and registration details will be published when registration is complete.
Privacy questions and rights requests can be sent to privacy@cial.app.
3. Data we process
- Account and authentication data: email address, display name, password hash or chosen sign-in provider, verification state, sessions and legal-acceptance records.
- Managed workspace data: instance name, lifecycle state, plan, resource allocation, operational identifiers and the prompts, files, integrations and source changes you place in the workspace.
- Billing data: plan, trial, subscription, invoice, customer and payment-status identifiers. Stripe handles payment-card details; Managed Cial does not store full card numbers.
- Technical and security data: IP address, browser and request metadata, session and abuse signals, transactional-email delivery events, errors, service health and audit records.
- Support data: messages, diagnostic information and other material you choose to send when asking for help or reporting a vulnerability.
4. Where data comes from and what is required
We receive data directly from you, from normal operation of Managed Cial, from providers that deliver the service, and from integrations you choose to connect. An email address and authentication information are required to create and secure an account. Workspace content is optional, but Managed Cial cannot perform a task without the inputs needed for it. Billing details are required only for a paid subscription.
5. Purposes and legal bases
- To create accounts, provide managed workspaces, process requested actions, deliver support and administer plans: steps requested before a contract and performance of the Managed Cial agreement.
- To secure accounts, prevent fraud and abuse, investigate incidents, maintain reliability and improve service operation: our legitimate interests in providing a safe and dependable service.
- To manage subscriptions, invoices, accounting and legally required records: contract performance and compliance with legal obligations.
- For an optional feature that specifically asks permission: consent, which you can withdraw for future processing at any time.
We do not sell personal data or use Managed Cial account data for third-party advertising.
6. Essential cookies and abuse protection
Managed Cial uses essential cookies and similar browser storage to keep you signed in, protect state-changing requests, remember necessary interface settings and operate the service. Cloudflare Turnstile processes technical and interaction signals during protected actions such as registration and password reset to distinguish legitimate use from automated abuse. Managed Cial does not currently use advertising cookies.
7. Managed Cial subprocessors and recipients
The following providers receive or process data only as needed for Managed Cial. Their precise legal role can depend on the service and processing involved:
- Fly.io for managed compute, networking and storage infrastructure.
- Stripe for paid subscriptions, checkout, invoices and payment status.
- Resend for transactional email and delivery events.
- Cloudflare Turnstile for bot and abuse prevention on protected public actions.
Managed Cial also uses a Cial-operated Forgejo service for managed source forks and a Cial-operated error-monitoring system where enabled; both run on the infrastructure described above. Google or GitHub receives sign-in data only after its OAuth option is enabled and you choose that provider.
Model, harness, tool and integration providers you independently connect to an agent receive the information you direct to them under their own terms. They are not Managed Cial subprocessors merely because you connect them. If you choose community support through Discord, Discord processes the information you post under its own terms. Managed Cial does not use workspace content to train a general-purpose AI model.
8. International transfers
Some providers may process data outside the European Economic Area. Where required, we rely on the provider’s applicable contractual safeguards or another lawful transfer mechanism. You can contact privacy@cial.app for information about safeguards relevant to your data.
9. Retention
Account and workspace data is kept while your Managed Cial service is active and then only as long as needed for deletion, recovery, security, disputes and legal obligations. Billing and accounting records are retained for the periods required by law. Security, support and audit records are retained according to their operational purpose and sensitivity, then deleted or anonymised when no longer needed.
Email-verification links expire after 24 hours and password-reset links after one hour. Expiry prevents further use of a token; limited security records may remain for abuse prevention and audit purposes.
10. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on consent. Some billing, security and legal records may need to be retained after an account closes.
Send requests to privacy@cial.app. You may also lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority.
11. Security and changes
Managed Cial uses account verification, access controls, workspace isolation, scoped service credentials, abuse controls and operational monitoring designed to protect data. No online service can guarantee absolute security; report suspected compromise to security@cial.app.
We may update this notice when the service, providers or legal requirements change. The latest update date appears on this page, and material changes may require a new acknowledgement.