Privacy Policy
1. Scope
This Privacy Policy explains how Costerly AI handles information when organizations and their users access the service at costerly.ai, contact us or use AI-assisted RFQ, drawing, estimation and production workflows.
Costerly AI is the trade name under which the service is operated by Kirill Ginzburg (קיריל גינזבורג), an individual registered in Israel as an exempt dealer (osek patur), registration no. 346904519 (the "Operator"). Costerly AI is not a separate legal entity.
2. Information we handle
- Account and contact information, such as names, business email addresses, organization details and user roles.
- Billing and subscription information. Payment card details may be handled directly by a payment provider.
- Customer Content, including drawings, RFQs, BOMs, specifications, prices, estimates and related files.
- Technical information, including IP address, browser and device information, authentication events and security logs.
- Usage and activity information, including screens, actions, processing events, feature use, errors and performance measurements.
- Support communications and information provided in requests or feedback.
Providing account and contact information is not required by law, but it is necessary to create, administer and use an account and to provide the service. If this information is not provided, the Operator cannot create or maintain the requested account or provide the corresponding service functionality.
3. How information is used
Customer Content is used to provide, operate, support, secure and troubleshoot the service, process requested workflows, generate requested output, comply with the Customer's instructions and meet legal obligations. It is not used to develop unrelated products or to train general-purpose AI models.
Account, technical, usage and performance information may be used to authenticate Users, maintain organization access, administer plans and billing, prevent misuse, monitor reliability, understand feature use and improve the service. Where practical, product analysis and improvement use aggregated or de-identified information rather than identifiable Customer Content.
4. Customer roles
For account, business contact, security and service-usage information, the Operator generally determines why and how information is handled. Where Customer Content contains personal data controlled by a customer, the customer generally acts as controller and the Operator handles that data as processor to provide the service. A separate Data Processing Agreement may be made available for customers that require one. No separate DPA checkbox applies to ordinary users.
5. AI and service providers
Information may be shared with subprocessors that support hosting, databases, authentication, payments, monitoring, communications, support and AI processing. Depending on the functionality used, these providers may include OpenAI, Anthropic, Google and Supabase. Access is limited to Costerly AI personnel and providers with a need to know the information for authorized service functions, subject to applicable contractual, confidentiality and technical controls.
The Operator does not use Customer Content to train its own general-purpose AI models. The Operator uses AI providers only under service terms, account types and technical configurations that do not permit Customer Content to be used to train or improve general-purpose models. This applies to OpenAI, Anthropic, Google and any other AI provider engaged for the service. Customer Content is transmitted to AI providers only to perform requested service functions.
6. Cookies and similar technologies
The service uses essential first-party browser storage for authentication, session continuity, security and core operation. This currently includes a short-lived encrypted session-resume cookie and tab-scoped session storage. The service also records first-party browser and server usage, reliability and performance events and stores them through the Operator's service providers. It does not currently use third-party analytics or advertising cookies or SDKs, and it does not use Customer Content or account information for behavioral advertising. Material new analytics, advertising or marketing tracking would be assessed and disclosed before use.
7. International processing
Information may be transferred from Israel and other locations to foreign service providers and processed in countries other than the User's location. The Operator will use the contractual commitments and other safeguards required by applicable law for international transfers.
8. Retention and deletion
Account, security and legal records are kept for as long as reasonably needed for the service, compliance, dispute resolution and protection of legal rights. Subject to applicable law, Customer Content may be stored indefinitely after a project or Organization Account is removed.
A customer may request permanent deletion through the contact below. After verifying and completing the request, the Operator will permanently delete the requested Customer Content from active systems and notify the customer. Limited backup copies may remain temporarily until overwritten through normal backup cycles, or longer where retention is required by law, security or dispute preservation. Such copies remain protected and are not restored to active use except for continuity, security or legal necessity.
9. Security
Costerly AI uses reasonable administrative, organizational and technical measures designed to protect information. No system can guarantee absolute security, and users are responsible for protecting their credentials and promptly reporting suspected unauthorized access.
10. Rights and requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to certain processing, or to receive a portable copy of information. Requests may require identity and authority verification. When Costerly AI processes personal data only for a customer, the request may be referred to that customer.
11. Changes
This policy may be updated as the service, providers and legal requirements change. The current version and effective date will remain available here. A Privacy Policy update does not by itself require a new Terms acceptance.
12. Contact
The data controller for the account and service information described above is Kirill Ginzburg (קיריל גינזבורג), an individual registered in Israel as an exempt dealer (osek patur), registration no. 346904519, operating under the Costerly AI trade name. Costerly AI is not a separate legal entity. Privacy questions and requests may be sent to hello@costerly.ai.