Privacy Policy
This Privacy Policy explains how Calera Computing, Inc. ("Calera Labs", "we", "us", "our") collects, processes, protects, and handles data across our hosted APIs, software development kits (SDKs), Model Context Protocol (MCP) servers, and user consoles — including FinanceSec, Infinite Context (ICX), and the Universal Dashboard (dashboard.caleralabs.com).
Zero Foundation Model Training Guarantee: Calera Labs does not use customer queries, ingested documents, memory spaces, custom ontologies, or API payloads to train public foundation models, distill third-party statistical weights, or share data across tenant boundaries. Your proprietary data remains strictly isolated to your organization.
1. Information We Process
- Account & Identity Data: Name, email address, organization membership, and authentication tokens managed via Firebase Authentication and enterprise Single Sign-On (SSO).
- API & License Credentials: Cryptographic API keys and license tokens used to authenticate requests to
/api/query, MCP endpoints, and integrations. API keys are hashed and treated as sensitive secrets. - Query Inputs & Ingested Content: Text queries, natural-language prompts, documents, financial filing identifiers, and document streams submitted to our APIs or indexed into Infinite Context memory spaces.
- Cryptographic Provenance & Verification Hashes: For factual recall and verification (e.g., SEC EDGAR queries), we process and output deterministic provenance records, including filing accession numbers, XBRL taxonomy concepts, and SHA-256 evidence hashes.
- Bring-Your-Own-Key (BYOK) Credentials: When you optionally configure third-party LLM providers (e.g., Anthropic, OpenAI, Google Gemini) in your account settings, your keys are encrypted at rest using Google Cloud KMS envelope encryption and utilized strictly to route your own requested completions.
- Operational & Health Telemetry: Aggregated, anonymized service metrics (HTTP status codes, latency percentiles, error rates, request counts) necessary to maintain uptime, prevent denial-of-service, and enforce subscription rate limits.
2. Data Sovereignty & Memory Isolation
Infinite Context (ICX) and FinanceSec operate with strict tenant isolation. Ingested documents and crystallized memory nodes are partitioned by tenant organization identifier (X-CaleraLabs-OrgId). No tenant's memory space or query history is accessible by or merged into another tenant's workspace or any shared statistical model.
3. AI Agents, Swarms & Model Context Protocol (MCP)
Calera Labs provides deterministic factual computation, memory topology, and verified data grounding. When you connect autonomous agents, IDE assistants (e.g., Cursor, VS Code, Claude Desktop), or multi-agent swarms via our MCP servers (e.g., financesec-mcp, icx-mcp):
- The MCP server acts solely as a secure transport to our deterministic query engine; it does not dispatch your private facts to third-party generative networks without your explicit instruction.
- Third-party agent clients that consume our tool outputs operate under their own independent terms and privacy policies. We encourage you to review their respective privacy practices.
- OAuth consents established for MCP client directories bind your specific license to temporary access tokens and can be revoked at any time by rotating your API keys in the Universal Dashboard.
4. User-Controlled Telemetry & Privacy Preferences
We respect client data sovereignty and provide granular privacy controls directly within your account:
- Telemetry Opt-Out: You can opt out of client-side product telemetry at any time via the Privacy & Compliance settings in your Universal Dashboard. Toggling opt-out persists
calera_ignore_telemetrylocally and suppresses analytics pings. - Configurable Audit Retention: Subscribers can configure their audit log retention window (from 14 days up to enterprise-grade indefinite retention) based on their compliance and data governance requirements.
5. Data Retention & Self-Service Deletion
- Operational Logs: Transient operational logs used for infrastructure debugging and DDoS mitigation are automatically purged within 90 days.
- Memory Spaces & Ingested Files: You have continuous control over your memory spaces. You may delete or flush individual memory spaces or full document collections at any time via the ICX REST API (
DELETE /v1/memory/spaces/{space_id}) or the Universal Dashboard. Deleted data is immediately purged from active memory structures. - Account Records: Basic billing and transactional history are retained for the duration of your account plus standard statutory periods required for financial accounting and tax compliance.
6. Subprocessors & Infrastructure
We partner exclusively with enterprise-grade infrastructure providers that adhere to stringent security standards (SOC 2, ISO 27001):
- Google Cloud Platform (GCP): Container hosting (Cloud Run), secure document storage, Cloud KMS encryption, and Firestore metadata storage.
- Firebase: Authentication, session verification, and static asset distribution.
- Stripe: Payment card processing and recurring subscription billing. Stripe processes financial transactions directly; Calera never stores raw payment card numbers.
7. Security & Cryptographic Integrity
All data in transit is encrypted using modern Transport Layer Security (TLS 1.3). Sensitive secrets and BYOK credentials are protected with Cloud KMS envelope encryption. Our container runtimes use minimal distroless base images with non-root execution profiles, eliminating legacy shell vectors. Factual responses include cryptographic SHA-256 verification hashes for end-to-end tamper detection.
8. Global Privacy Rights (GDPR & CCPA/CPRA)
Regardless of your geographic location, you enjoy full sovereignty over your personal data:
- Access & Portability: You may export your complete account profile, preferences, and usage records directly from your account settings.
- Rectification & Erasure: You may update your profile data or execute a permanent account deletion request with 1 click in the Universal Dashboard or by emailing support@caleralabs.com.
- Non-Discrimination: We do not discriminate against any user for exercising their statutory privacy rights.
9. Changes & Contact
We may update this Privacy Policy to reflect evolving technical capabilities or statutory requirements. When changes occur, the effective date at the top of this page will be updated. For questions, compliance reviews, or Data Processing Agreements (DPAs), contact our privacy team at support@caleralabs.com.