Legal · draft — counsel review required
Privacy Notice
Template draft — have counsel review before reliance. Not legal advice. Product: Citadel Exchange · Language: English · Last updated: 2026-08-01
1. Who we are
Citadel Exchange (“we”, “us”) provides a zero-knowledge secure exchange platform. This notice explains how we process personal data when you use the Service. For customer-controlled room content, see also the DPA.
2. Data we process
| Category | Examples | Notes |
|---|---|---|
| Account data | Email, display name, role assignments | Required to operate the tenant |
| Authentication | Password hashes (via auth stack), MFA factors, passkeys, sessions | We never store your vault password in recoverable form for room keys |
| Key material (wrapped) | Encrypted private keys, salts, IVs | Ciphertext only; we cannot unwrap without your secret |
| Room metadata | Membership, timestamps, file sizes, delivery state | Not message plaintext |
| Room content | Message/file ciphertext | Encrypted on device before upload |
| Billing | Stripe customer / subscription identifiers | Processed by Stripe as payment processor |
| Diagnostics | Audit events, health metrics, support tickets | Security and reliability |
| Preferences | Locale, notification settings, timezone | Product settings |
3. Purposes and legal bases (GDPR-style)
- Contract: provide the Service, authenticate users, bill subscriptions
- Legitimate interests: secure the platform, prevent abuse, improve reliability
- Legal obligation: tax, accounting, breach notification where applicable
- Consent: optional notifications or non-essential cookies if introduced
4. Zero-knowledge boundary
We design the Service so room message and file plaintext is encrypted on the client. We do not operate a plaintext escrow. Metadata necessary to route and authorize access remains visible to the service.
5. Sharing
We share data with sub-processors listed in the DPA (hosting, object storage, email, payments). We do not sell personal data.
6. International transfers
If data is transferred internationally, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) as documented with counsel in the DPA pack.
7. Retention
Account and audit data are retained while the tenant is active and for a limited period afterward for security and legal claims, unless a shorter period is required. Soft-deleted files follow the product retention/purge schedule. You may request erasure subject to legal holds — see in-app Privacy controls and the DPA.
8. Your rights
Depending on jurisdiction, you may have rights to access, rectification, erasure, restriction, portability, and objection. Use in-app export/erasure where available, or contact the privacy address designated at launch. Customers in Québec should review the French (Canada) version of this notice (fr-CA locale), which addresses Law 25 and French-language requirements.
9. Security
See /.well-known/security.txt, our cryptographic controls policy, and the public status page. No method of transmission or storage is perfectly secure.
10. Children
The Service is not directed to children under 16 (or higher age where required).
11. Changes
We will post updates to this notice and adjust the “Last updated” date.
12. Contact
Privacy / legal contact: designate before public launch. Security reports: /.well-known/security.txt.
Privacy Notice