Privacy Policy
Effective date: May 22, 2026
Climateshed Intelligence ("we," "us," or "our") operates the Climateshed Intelligence web app and iOS app (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, how long we keep it, and your rights under applicable law including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
1. Information We Collect
We collect the following categories of personal data when you use the Service:
- Email address — used to create your account and send login codes (OTP).
- Conversation history — the messages you send and the AI-generated responses, stored to provide conversational context and to allow you to review past sessions.
- Usage data — counts of queries sent per billing period, used to enforce plan quotas.
- Device tokens (iOS only) — APNs push notification tokens, used solely to deliver in-app notifications when a response is ready.
- Billing information — Stripe customer and subscription IDs. We do not store full card numbers; payment details are handled entirely by Stripe.
- Anonymous analytics — when you visit our website, we collect anonymized data including page views, referrer URL, browser type, operating system, and approximate country. This data is not linked to your account or any personally identifiable information, and no cookies are used.
- Location (optional) — if you grant permission, approximate GPS coordinates are sent with your query to retrieve nearby climate data (e.g., wildfire zone, flood zone, sea level rise). Coordinates are not stored.
2. How We Use Your Data
- To authenticate you and provide access to the Service.
- To answer your questions using our AI-powered research pipeline.
- To enforce monthly query quotas and process subscription billing.
- To send push notifications (iOS) when a response is ready.
- To improve the Service (aggregate, anonymized usage patterns only — never individual conversations).
We do not sell your personal data. We do not use your conversation history to train AI models.
3. Data Retention
We retain your data for the following periods after your last account activity, then delete it automatically:
| Account type |
Retention period |
| Free |
90 days from last activity |
| Paid (Starter or Pro) |
3 years from last activity |
"Last activity" means the last time you sent a message using the Service. Deletion is automatic and cascades to all associated data (conversation history, usage records, device tokens).
You may delete individual conversations at any time using the delete button in the interface. To request immediate deletion of your full account and all associated data, email us at feedback@climateshed.app and we will process your request within 30 days.
4. Your Rights (CCPA / CPRA)
As a California resident, you have the following rights:
- Right to know — you may request a summary of the personal data we hold about you.
- Right to delete — you may request deletion of your personal data (see Section 3 above).
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise these rights, contact us at feedback@climateshed.app.
5. Third-Party Services
We share data with the following third-party services to operate the Service:
- Anthropic — AI model provider. Your message and retrieved document excerpts are sent to Anthropic's API to generate a response. See Anthropic's Privacy Policy.
- Pinecone — vector database used to retrieve relevant document excerpts. Query embeddings (numerical vectors, not raw text) are sent to Pinecone.
- Supabase — database and authentication infrastructure. Your account data and conversation history are stored in Supabase.
- Stripe — payment processing. Billing information is handled by Stripe and subject to Stripe's Privacy Policy.
- Fly.io — cloud hosting for the API. Data is processed on Fly.io servers in the United States.
- Voyage AI — embedding model provider. Your message text is sent to Voyage AI to generate a search vector. No data is retained by Voyage AI beyond the API call.
- Umami — privacy-friendly, cookieless web analytics. Umami collects anonymous page view data (page URL, referrer, browser, OS, country) with no cookies and no personal identifiers. Data is hosted by Umami Cloud. See Umami's Privacy Policy.
6. Data Security
We use industry-standard security practices including HTTPS encryption in transit, row-level security in the database, and JWT-based authentication. No system is completely secure, and we cannot guarantee the absolute security of your data.
7. Children
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy at this URL with a revised effective date. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
9. Contact
For privacy questions or data requests, contact us at feedback@climateshed.app.