Skip to content
CIRCO

Privacy Policy

What we collect, why, where it lives, and what we never do with it. The short version: account data to run the platform, no ad-tech anywhere, and we do not sell your personal information.

Effective September 4, 2026 · v1.0

Who we are, and what this covers

This Privacy Policy describes how Catalyst Intelligence Research Corporation — operating under brand names including CIRCO, CIRCO Analytics, CIRCO Research, Prime CIR, Cluster, and CIR (“CIRCO,” “we,” “us”) — collects, uses, discloses, and protects personal information across our websites, the Cluster application, our APIs, and related services (the “Services”), whichever brand they carry. CIRCO is the organization responsible for personal information under this policy. It applies to account holders and visitors; it does not apply to third-party sites we link to.

One thing to understand about Cluster's design: almost everything in the product — market data, filings, transcripts, news, scores — is public-market information that is not about you and is not personal information. Your personal data is a thin layer on top: your account, and what you choose to track. The complete list of what is held against your record is also published inside the product, at Profile → Data & Privacy, and this policy mirrors it.

What we collect

ACCOUNT AND IDENTITY

Sign-up and sign-in run through Clerk, our identity provider, so we never store a password ourselves. From it we receive and hold your email address, name, profile photo, and account identifiers, along with session and device records (which you can review and revoke in Profile → Security) and an audit record of account events such as sign-up and plan changes. We also hold your subscription plan, status, and dates.

YOUR WORKSPACE

What you choose to track — companies, entities, narratives, and stories — plus your watchlist, which alerts you have read or dismissed, your answers from onboarding, research and agent queries you run and the outputs saved to your account, when you were last active, and anything you send to support.

COLLECTED AUTOMATICALLY

Standard operational records when you use the Services: IP address, browser and device information, timestamps, and server logs of requests. We use these for security, abuse prevention, debugging, and capacity — not for advertising. Some preferences (such as your theme) are stored only in your browser's local storage and never reach our servers.

WHAT WE DO NOT COLLECT

No advertising trackers, no cross-site tracking, no third-party analytics scripts, and no data purchased from brokers. We do not collect government identifiers, precise location, health, or biometric data. If we ever add payment processing, card details will be handled by a certified payment processor and will not touch our servers. Sample figures shown on the marketing site are deterministic, illustrative product vocabulary — not live customer data.

How we use personal information

  • To provide and operate the Services: authenticate you, run your watchlists and tracking, assemble your feed, and deliver the alerts you have set up.
  • To personalize: your usage (for example, what you search and track) can become inferred interests that shape what surfaces for you — visible to you and dismissible in the product.
  • To communicate: service and account emails (security, plan, and feature notices) and alert deliveries you have enabled. Optional update emails include a way to opt out.
  • To secure and improve: investigate abuse, debug, measure aggregate usage of surfaces, and improve models and features using de-identified or aggregated information that no longer identifies you.
  • To comply with law: keep required records, respond to lawful requests, and establish or defend legal claims.

Where the law of your jurisdiction requires a legal basis: we process to perform our contract with you, for legitimate interests (running and protecting the Services) balanced against your rights, to comply with legal obligations, and with your consent where required — which you may withdraw.

AI processing

Research queries, agent prompts, and content being summarized or translated are processed by third-party AI providers acting as our service providers. They process this data to return results to you, under terms that restrict them from using our API requests to train their models. Do not put sensitive personal information into research prompts — the product neither needs nor asks for it.

When we share — and when we never do

We do not sell, rent, or trade personal information, and we do not share it for cross-context behavioral advertising. We disclose it only:

  • to service providers who run parts of the Services for us — identity (Clerk), cloud infrastructure and hosting, email delivery, and AI processing — bound by agreements to use it only to provide the service;
  • within a corporate transaction (merger, acquisition, financing, or sale of assets), in which case this policy continues to apply to your data until you are told otherwise;
  • when required by law or legal process, or to protect the rights, safety, or property of CIRCO, our users, or others; and
  • with your direction or consent.

Cookies and local storage

We use strictly necessary cookies from our identity provider to keep you signed in, and browser local storage for device preferences such as theme. That is the full list today: no advertising cookies and no third-party analytics cookies. If we ever add product analytics, it will be privacy-respecting and aggregate, and this policy will be updated first. Blocking essential cookies will prevent sign-in from working.

Where data lives, and international transfers

Our primary infrastructure is hosted in Canada. Some service providers — including identity and AI processing — operate in the United States and elsewhere, so your information may be transferred to, stored, and processed in jurisdictions with different data-protection laws than your own. Wherever it is processed, it remains protected by this policy and our agreements with those providers, and we use recognized safeguards for cross-border transfers where required.

Retention and deletion

We keep personal information while your account is active and as long as needed for the purposes above. You can delete your account yourself at Profile → Data & Privacy → Delete account: it permanently closes the account, signs you out everywhere, and your tracking lists, alerts, and research history stop being accessible; we then delete or de-identify the associated personal information within a reasonable window, typically thirty days. Residual copies may persist for a limited time in backups and security logs, and we may retain what the law requires us to keep or what is needed to resolve disputes — no longer than necessary, and protected in the meantime.

Your rights and choices

Much of this is self-service in the product: edit your profile, review and revoke sessions and devices, manage what you track and which alerts you receive, dismiss inferred interests, and delete your account entirely. Beyond that, depending on where you live — including under Canada's PIPEDA, the EU/UK GDPR, and US state privacy laws such as the CCPA — you may have rights to access, correct, export, restrict, object to the processing of, or delete your personal information, and to complain to your data-protection authority (in Canada, the Office of the Privacy Commissioner).

To exercise any of these rights, write to desk@cir.co. We will verify the request against your account email, respond within the time your law requires, and never discriminate against you for exercising a privacy right. An authorized agent may act for you where your law provides for it.

Security

Data is encrypted in transit; authentication is delegated to a dedicated identity provider so we hold no passwords; access to production systems is limited to the people and systems that need it to operate the Services. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects your personal information in a way the law requires us to report, we will notify you and the relevant authorities as required. Security findings are welcome at the contact address.

Children

The Services are built for professional and adult use and are not directed to anyone under 18. We do not knowingly collect personal information from children; if we learn we have, we will delete it. If you believe a child has an account, contact us.

Changes to this policy

When our practices change, this policy changes in the same release: we update the version and effective date at the top, and for material changes we will notify you by email or in the product before they take effect. This version replaces the early-access notice dated May 1, 2026.

Contact

For any privacy request — access, export, correction, deletion, or a question this policy does not answer — write to desk@cir.co and we will respond promptly.

Free to explore the flagship terminal while it is in early access. Sign up and watch the next story form — or read the Terms.

QUESTIONSdesk@cir.co

Privacy — CIRCO