Skip to main content
Citadel Exchange
TrustPricingSign inGet started

Legal · draft — counsel review required

Privacy Notice

Template draft — have counsel review before reliance. Not legal advice. Product: Citadel Exchange · Language: English · Last updated: 2026-08-01

1. Who we are

Citadel Exchange (“we”, “us”) provides a zero-knowledge secure exchange platform. This notice explains how we process personal data when you use the Service. For customer-controlled room content, see also the DPA.

2. Data we process

CategoryExamplesNotes
Account dataEmail, display name, role assignmentsRequired to operate the tenant
AuthenticationPassword hashes (via auth stack), MFA factors, passkeys, sessionsWe never store your vault password in recoverable form for room keys
Key material (wrapped)Encrypted private keys, salts, IVsCiphertext only; we cannot unwrap without your secret
Room metadataMembership, timestamps, file sizes, delivery stateNot message plaintext
Room contentMessage/file ciphertextEncrypted on device before upload
BillingStripe customer / subscription identifiersProcessed by Stripe as payment processor
DiagnosticsAudit events, health metrics, support ticketsSecurity and reliability
PreferencesLocale, notification settings, timezoneProduct settings

3. Purposes and legal bases (GDPR-style)

  • Contract: provide the Service, authenticate users, bill subscriptions
  • Legitimate interests: secure the platform, prevent abuse, improve reliability
  • Legal obligation: tax, accounting, breach notification where applicable
  • Consent: optional notifications or non-essential cookies if introduced

4. Zero-knowledge boundary

We design the Service so room message and file plaintext is encrypted on the client. We do not operate a plaintext escrow. Metadata necessary to route and authorize access remains visible to the service.

5. Sharing

We share data with sub-processors listed in the DPA (hosting, object storage, email, payments). We do not sell personal data.

6. International transfers

If data is transferred internationally, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) as documented with counsel in the DPA pack.

7. Retention

Account and audit data are retained while the tenant is active and for a limited period afterward for security and legal claims, unless a shorter period is required. Soft-deleted files follow the product retention/purge schedule. You may request erasure subject to legal holds — see in-app Privacy controls and the DPA.

8. Your rights

Depending on jurisdiction, you may have rights to access, rectification, erasure, restriction, portability, and objection. Use in-app export/erasure where available, or contact the privacy address designated at launch. Customers in Québec should review the French (Canada) version of this notice (fr-CA locale), which addresses Law 25 and French-language requirements.

9. Security

See /.well-known/security.txt, our cryptographic controls policy, and the public status page. No method of transmission or storage is perfectly secure.

10. Children

The Service is not directed to children under 16 (or higher age where required).

11. Changes

We will post updates to this notice and adjust the “Last updated” date.

12. Contact

Privacy / legal contact: designate before public launch. Security reports: /.well-known/security.txt.

Privacy Notice