Privacy Policy
This Privacy Policy describes how Cifra LLC ("Cifra LLC," "we," "us," or "our") collects, uses, discloses, protects, and retains information in connection with Cifra (the "Service"), our business and job information organization service.
1. Information Provided Directly
Customers and their authorized users may provide information directly to the Service, including:
- first and last name;
- business name and business contact information;
- address, email, and account/login information;
- profile information, such as profile and business pictures;
- job and project information;
- employee and authorized-user information;
- expenses, labor, and other business records;
- documents and photos uploaded to the Service;
- information submitted when contacting support.
Cifra does not store customers' full payment-card credentials.
2. Google Workspace and Gmail Data
Cifra's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace API data is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Data accessed
Cifra may access, with the user's explicit authorization, new Gmail messages received after the Gmail connection is established, including sender information, subject, message body, message metadata, and attachments such as images and PDFs required for Cifra's email-intake functionality.
Cifra does not perform a historical Gmail inbox import as part of this integration.
How the data is used
Gmail-derived data is used only to provide and improve user-facing Cifra features, including identifying and processing job-related receipts, invoices, documents, photos and job updates and converting them into the user's Cifra workflow.
Cifra does not use Google user data for advertising, advertising profiles, lending/credit decisions, or sale of user data.
AI processing / OpenAI
Cifra uses OpenAI as a service provider to perform classification and structured extraction needed for Cifra's user-facing intake functionality. Gmail-derived message content and relevant attachments may be securely transmitted to OpenAI for this processing.
Cifra does not use Google Workspace API data to train or improve generalized AI/ML models. Cifra's OpenAI API organization has model-feedback sharing, evaluation and fine-tuning sharing, and API input/output sharing disabled.
Data transfer
Google user data is not sold and is not transferred to advertisers or data brokers. It may be disclosed to service providers only as necessary to provide Cifra's user-facing functionality and subject to applicable data-protection obligations.
Data protection
Gmail connection credentials are handled server-side, storage and network transport use encryption, and access to connected-source data is restricted to what is necessary to provide the Service.
Disconnect
Disconnecting Gmail stops future Gmail intake and removes/revokes Cifra's Gmail connection credentials. Cifra records already created from prior messages—such as saved receipts, job updates or photos—may remain as part of the user's Cifra business records.
Retention and deletion
Original Gmail email content and attachment files that do not become retained Cifra records are permanently deleted within 30 days.
Records the user intentionally keeps in Cifra, such as receipts, updates and photos, remain according to Cifra's normal account/data-retention rules until deleted by the user or through applicable account/data deletion.
Users can use Cifra's Delete Gmail data control to permanently delete retained original Gmail source data that Cifra no longer needs to maintain a Cifra record. Cifra business records that the user has chosen to keep—such as filed receipts, job updates, or photos—may remain as Cifra records according to Cifra's normal retention rules. Disconnecting Gmail alone does not delete these retained Cifra business records.
3. Connected Communications and Sources
In addition to the Google Workspace and Gmail disclosures in Section 2, when users connect, forward, or otherwise provide email, SMS, other messages, or attachments to Cifra, the Service may receive and process communication content, metadata, sender and recipient information, attachments, and related information as necessary to provide intake and organization functionality. Not every received communication is necessarily retained as a job record, and automated filtering and classification are not perfect.
Customers control which sources they connect or provide, and should only connect sources they are authorized to use.
4. Automatic and Technical Information
Like most online services, the Service may automatically collect ordinary technical information, such as device and browser information, IP and network information, authentication and security events, timestamps, usage and application events, and diagnostic and error information.
5. How Cifra Uses Information
We use the information we process to:
- provide and operate the Service;
- authenticate users;
- organize business and job information;
- process connected-source intake;
- perform AI/automated classification, extraction, and summaries;
- provide customer support;
- secure the Service and prevent fraud and abuse;
- administer billing and subscriptions;
- debug and improve reliability;
- comply with law;
- improve the Service.
We do not use personal information for marketing without appropriate consent.
6. AI and Automated Processing
Cifra may use automated systems, which may include artificial intelligence, to process Customer Data in order to provide Service functionality such as classification, extraction, summarization, and organization. Cifra does not sell Customer Data.
7. Paddle and Billing Information
Cifra uses Paddle for subscription transactions, and Paddle acts as Merchant of Record and authorized reseller for purchases processed through Paddle. Paddle may collect payment, billing, transaction, tax, fraud-prevention, and related buyer information under Paddle's own privacy terms.
Cifra receives the subscription, customer, and transaction information necessary to provision and support the Service. Cifra does not store customers' full payment-card credentials.
8. Service Providers
Cifra may use service providers for infrastructure, authentication, database and storage, communications, AI/processing, billing, monitoring, security, and related operations. Service providers receive information only as necessary to perform their functions and subject to applicable contractual and legal obligations.
9. Disclosure of Information
We may disclose information:
- to service providers and processors acting on our behalf;
- to Paddle and the payment ecosystem as applicable to a transaction;
- to customer-authorized users within their Cifra organization;
- where required by law or regulation;
- in connection with security or fraud investigations;
- in connection with a corporate transaction, where legally appropriate.
Cifra does not sell personal information for money.
10. Customer Organization Access
Information within a Cifra business or organization may be accessible to authorized account owners, admins, and users according to Cifra permissions. Cifra Pro may permit information access and administration across businesses within the same authorized organization according to configured access.
11. Data Security
Cifra maintains reasonable administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Data Retention
Cifra retains information for as long as reasonably necessary to provide the Service, maintain the account, comply with legal and security obligations, and fulfill legitimate operational purposes.
After a Cifra account is terminated, customer account data is generally retained for up to 30 days before scheduled deletion, subject to legal holds, legal and regulatory requirements, fraud and security needs, backups, and information that must be retained. Payment and transaction information maintained by Paddle is subject to Paddle's retention practices.
See Section 2 for the retention terms specific to Google Workspace and Gmail data.
13. Account Cancellation vs. Termination
A cancellation scheduled to take effect at the end of a paid subscription period does not immediately begin the post-termination retention period. Payment recovery and dunning do not themselves begin Cifra's 30-day post-termination retention period.
14. Data Choices and Control
Depending on your use of the Service, you may update account and profile information, disconnect connected sources where supported, cancel your subscription, or contact Cifra about privacy requests through the support/contact method provided in the Service.
For Gmail-connected accounts, you may also use the Delete Gmail data control described in Section 2.
15. U.S. Privacy Rights
Cifra launches in the United States. Residents of certain U.S. states may have rights under applicable privacy laws, which may include rights to access, correct, delete, or obtain a portable copy of personal information, or to appeal or opt out of certain processing, depending on the jurisdiction and its applicability to Cifra. Requests may be submitted through Cifra's support/contact method provided in the Service.
16. Children
Cifra is a business service and is not intended for children under 13. We do not knowingly solicit personal information from children.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated where required by applicable law, and the updated policy will be posted with a revised effective date.
18. Contact
Privacy questions and requests can be sent to Cifra through the support/contact method provided in the Service.