Privacy Policy
Circulr is software that magazine publishers use to run a local edition: who they cover, who advertises, who attends the events. Most of the personal information in Circulr is not about the publisher — it is about the people they write about and do business with. This page says what we do with all of it.
Two different roles
For a publisher's own account — the name and email of the people who sign in, and their billing details — we are the controller. We decide what to collect and why, and this policy is that decision.
For everything a publisher puts into Circulr — their contacts, their photographs, their event attendance, their interview notes — we are a processor. The publisher decides what goes in and what it is for; we hold it and act on their instructions. If you are a real estate agent, a partner business or an event guest whose details are in a publisher's Circulr workspace, the publisher is the one who answers for it, and the Data Processing Addendum is the agreement that governs it.
What we collect
From people who sign in
- Name, email address and profile picture, from the sign-in method used.
- Which workspace and publication an account belongs to, and its role.
- Sign-in events, and whether two-factor authentication was used.
- Billing contact details. Card numbers go directly to Stripe and never reach us.
From publishers putting their work into Circulr
- Contact records: names, email addresses, phone numbers, employers, licence identifiers, notes.
- Photographs, including of identifiable people, and automatically derived crops of faces.
- Events and who attended them, articles and who was featured, interviews and transcripts.
- Anything imported from a connected integration the publisher chose to set up.
Automatically
- Application logs, browser error reports and page-timing events, used to find and fix faults.
- IP address and user agent on requests, used for rate limiting and abuse prevention.
We do not use advertising trackers, we do not sell personal information, and we do not share it for cross-context behavioural advertising.
Why we use it
- To provide the product: showing a publisher their own data and acting on it.
- To keep it working and secure: diagnosing faults, preventing abuse, taking backups.
- To bill for it.
- To contact account holders about the service. We do not send marketing to the contacts in a publisher's workspace.
Artificial intelligence
Some features send data to AI vendors. They are off unless a publisher turns them on, and each one is listed on the subprocessors page.
- Research reads publicly available web pages about the people a publisher tracks, and sends that page text to Anthropic to be summarised.
- Semantic search sends article text and interview transcripts to OpenAI to be turned into embeddings.
- Assistant access lets a publisher connect an AI assistant that can read and change their workspace through our API, under a key they create and can revoke.
We do not permit these vendors to train models on customer data under the terms we use. A publisher can leave these features off, and turning them off stops any further data being sent.
Who else sees it
Only the service providers we need to run the product, each listed with the data it receives on the subprocessors page. We may also disclose information if the law requires it, and we will tell the affected customer unless we are prohibited from doing so.
Our staff can open a workspace to provide support. That access is recorded with a reason, is time-limited, and can be revoked. It is not silent.
Where it is kept
In the United States. The database and stored files are hosted in AWS's us-west-1 region through Supabase; the application runs on Railway; encrypted backups go to Cloudflare R2.
How long we keep it
- Workspace data — for as long as the workspace exists.
- After a deletion request — a 30-day hold, so an accidental deletion can be undone, then the data is purged.
- Backups — 90 days. Deleted data persists in encrypted backups until they age out.
- Logs and telemetry — 90 days.
- Unused trial workspaces — removed after 30 days of inactivity.
- Billing records — kept as long as tax and accounting law requires.
Your rights
Depending on where you live, you may have the right to see the personal information held about you, correct it, delete it, obtain a copy, or object to certain uses. California residents have these rights under the CCPA, including the right not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined there.
If your details are in a publisher's workspace, ask that publisher — they decide what is held and we act on their instruction. If you do not know who that is, write to us at privacy@circulr.io and we will identify them or pass the request on. For your own Circulr account, write to us directly.
Children
Circulr is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16.
Security
The specific measures in place are listed in the Data Processing Addendum, because they are commitments rather than description. To report a vulnerability, write to security@circulr.io.
Changes
If we change this policy in a way that materially affects how we handle personal information, we will tell account holders by email before it takes effect.