Ceptile
Ceptile AI Search Privacy Policy

Ceptile Privacy Policy

Effective Date: September 2026 • Version 2.4. This privacy policy describes how Ceptile (accessible at ceptile.com) handles user data, processes search inquiries, and approaches data practices across our AI search engine.

Privacy-Oriented

Designed with user privacy as a guiding principle in how we build our product.

Data Minimization

We aim to collect and retain only what is necessary to operate the service.

AI-Powered Search

Answers are synthesized from live web sources in real time using AI inference.

Encrypted At Rest

All credentials and sessions secured with AES-256 & bcrypt.

1. Core Privacy Philosophy

At Ceptile, we believe search should be a private, useful experience. Traditional commercial search engines may construct profiles of your interests and search habits to serve targeted advertising.

Ceptile is an AI-native search engine focused on answering questions and providing useful, cited information. Our goal is to operate with minimal data collection and to be transparent about how we handle information you provide.

2. Data Practices & Our Approach

Our Approach to Data Collection:
  • Limited Tracking: We aim to avoid cross-site tracking pixels, persistent profiling beacons, or third-party behavioral trackers. Our practices may evolve as the service develops.
  • Search Data: We do not currently package or sell user search logs to advertisers as a business practice. This policy may be updated if our business model changes.
  • Location Data: We do not persistently log precise GPS coordinates. City-level routing may be used ephemerally when you search for local results (e.g., "restaurants near me").
  • Device Identifiers: We aim to avoid intrusive device fingerprinting techniques such as canvas inspection or battery API probing.

3. Information We Process

Ceptile can be used 100% anonymously without creating an account. If you voluntarily register a Ceptile Account to synchronize research history across devices, we process only the minimum required data:

Data ElementPurposeStorage & Encryption
Account EmailAccount identification, password resets, security notifications.Encrypted in secure Ceptile Cloud DB. Not shared with third parties for advertising purposes.
PasswordAuthentication validation.Cryptographically hashed with Bcrypt (cost factor 10). Ceptile cannot view plaintext passwords.
User Conversation ThreadsAllows users to review past research and branch chats.Linked to user ID. Can be permanently deleted by user at any time with 1 click.
Telemetry & Operational LogsSystem uptime, error rate diagnostics, rate-limiting enforcement.Ephemeral rotating server logs stripped of personal identifiers, purged every 14 days.

4. AI Inference & RAG Privacy Engine

Ceptile utilizes advanced Retrieval-Augmented Generation (RAG). When you submit an AI search query:

  • Your query is stripped of user session tokens before being dispatched to our inference engines.
  • Queries are evaluated exclusively to plan searches, score evidence, and synthesize the immediate answer.
  • AI Inference: Our AI providers operate under service agreements and strict enterprise data protection standards. Queries are processed exclusively to generate search answers and are not used to train or fine-tune public foundation models.
  • Context memory is stored within your private session thread only and is purged upon session or thread deletion.

5. Live Web Crawling & Ephemeral Retrieval

To provide verified citations, Ceptile crawls public web pages matching your search keywords. We process only publicly accessible HTML documents according to standard web crawler conventions (honoring `robots.txt` disallows). Web page contents are parsed in ephemeral memory to extract factual evidence and discarded immediately after answer synthesis.

6. Security & Encryption Standards

We implement defense-in-depth security engineering to safeguard all data:

  • Transport Security: Strict HTTPS encryption across all web traffic utilizing TLS 1.3 with HSTS (HTTP Strict Transport Security) preloaded.
  • Data at Rest: Database records and cloud backups are encrypted with AES-256.
  • SQL Injection & XSS Defense: Strict parameterized PDO queries in our backend architecture and sanitized React DOM rendering to prevent arbitrary script execution.
  • Session Protection: HTTP-only, SameSite=Lax authentication cookies preventing client-side script interception.

7. Secure Edge & AI Infrastructure

To deliver world-class latency and comprehensive search indexing, Ceptile operates robust global edge and search infrastructure:

  • Ceptile Global Edge Network: High-speed global edge network for fast static asset delivery and low-latency route execution.
  • Live Web Retrieval: Directly queries authoritative public web indexes to fetch relevant search documents in real time without profiling users.
  • High-Speed Neural Inference Clusters: Dedicated high-performance neural hardware executing open-weights neural inference under enterprise privacy standards.

8. User Rights (GDPR & CCPA/CPRA)

Regardless of where you reside globally, Ceptile extends universal data privacy rights:

Right to Erasure ("Right to be Forgotten")

You can permanently delete any conversation thread or your entire account with immediate cascade deletion in our database.

Right to Data Portability

Request a full export of your saved conversations and bookmarks in structured JSON format.

Right to Rectification

Modify your email address, preferences, or account credentials at any time in Settings.

Right to Opt-Out

You may contact us at any time to request information about how your data is used or to ask that it not be used for certain purposes.

9. Cookies & Local Storage Audit

Ceptile uses minimal functional local storage items required solely for application operation:

  • theme: Remembers your display choice (light or dark mode).
  • ceptile_conversations: Stores anonymous offline conversation history in your browser if not logged in.
  • ceptile_auth_token: Authenticates your active session if you have logged into Ceptile Account.

We currently do not use third-party cross-site marketing cookies or behavioral tracking beacons. Our cookie usage may be updated as the service evolves.

10. Data Retention & Account Deletion

Anonymous queries are not associated with user records and exist solely in volatile memory during generation. For registered users, conversation records are retained until you choose to delete them. You can delete individual chats from the sidebar or initiate complete account erasure in Account Settings.

11. Contact Our Data Protection Officer

If you have questions, feedback, or formal inquiries regarding Ceptile's privacy practices, or if you wish to exercise your statutory privacy rights, please reach out to our team:

Official Support Email: support@ceptile.com
Direct Contact Form: ceptile.com/contact