This privacy policy describes how Cassandra by Lonia AI collects, uses, and protects your information when you use the marketing site at cassandra.lonia.ai and the application at app.cassandra.lonia.ai (in development).
Cassandra is operated by Lonia AI, the legal entity referred to in this policy as "we", "us", or "our".
Data minimization is the design
The public tier requires no account. You can read the overview dashboard, weekly synthesis, and basic alerts without giving us any personal information. Account-based data collection only applies to paid tiers and to anyone who chooses to join the waitlist or contact us.
What data we collect
Waitlist email addresses
If you submit your email through the waitlist form, we store that email address along with the source tag of the form, so we can notify you when Cassandra launches and route you to the correct tier when paid signups open.
Account information (paid tiers, post-launch)
When paid signups open, you will sign in via OAuth Single Sign-On with Google or Microsoft. We will receive your name, email address, and profile photo from the provider. We will not receive or store your provider password.
Usage data
We collect anonymized usage data such as pages visited and features used to improve the product. This data is aggregated and not linked to individual identifiable accounts.
What we do not collect
- We do not store passwords. Authentication is OAuth-only
- We do not collect data from public-tier readers beyond aggregate analytics
- We do not sell, rent, or share user data with advertisers
- We do not use your data for profiling or behavioral targeting
How we use your data
- To deliver the platform and its synthesized briefings to subscribers
- To notify waitlist members when Cassandra launches
- To communicate with paid subscribers about their accounts and service updates
- To generate audit logs for security and compliance
- To improve the product based on aggregate usage patterns
Third-party services
Cassandra uses the following third-party services:
- Cloudflare: Hosting, CDN, and the email signup worker that receives waitlist submissions
- Supabase: Database hosting and authentication for the application (post-launch). Stores account information and application data
- Stripe: Payment processing for paid tiers (post-launch). Receives billing information. We do not store credit card numbers
- Google and Microsoft OAuth: Authentication providers for the application (post-launch)
- Resend: Transactional email delivery
Each third-party service operates under its own privacy policy and data handling practices.
Marketing communications
If you join the waitlist or subscribe to product updates, we send you launch notifications and product updates. Every email includes an unsubscribe link, and you can also unsubscribe at any time by emailing support@lonia.ai. Newsletter email addresses are retained until you unsubscribe, after which they are removed from active marketing lists.
We do not sell, rent, or share newsletter email addresses with any other third party.
Data retention
Waitlist email addresses are retained until launch and then transferred to active product communications, or until you unsubscribe. Account data is retained for the lifetime of the account plus 30 days for backup purposes after deletion. Usage analytics are retained in aggregate form only.
Encryption and security
- All data transmitted between your browser and our services is encrypted in transit using TLS 1.3
- Stored data is encrypted at rest using AES-256
- Authentication is OAuth-only. We do not store passwords for any account
- Application database tables enforce row-level security to isolate tenant data
- Audit logs are kept for security-relevant events
Your rights
- Access: You can request a copy of your data at any time
- Deletion: You can request deletion of your account and associated data
- Portability: You can request your data in a standard, machine-readable format
- Correction: You can request correction of inaccurate data
To exercise any of these rights, contact support@lonia.ai.
Children's privacy
Cassandra is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information to us, contact support@lonia.ai and we will remove it.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date. Material changes will be communicated via email to account holders.
Contact
For privacy inquiries, data requests, or concerns, contact:
Email: support@lonia.ai
Lonia AI