Draft v0.1 · pending counsel review Legal

Privacy policy.

What we collect, why we need it, how long we keep it, and how to ask us to delete it. Cult Shield is operated from the EU and follows GDPR by default.

1. Controller

The data controller is Cult Shield s.r.o., registered in Bratislava, Slovak Republic. Reach us at privacy@cultshield.com.

2. What we collect

Account data

Uploaded work

Detection & case data

Usage data

3. Why we collect it (lawful bases under GDPR)

4. Who sees it

We do not sell or rent personal data. We do not run third-party advertising trackers.

5. Where it lives

Primary storage is in the EU (Supabase Frankfurt and Hetzner Falkenstein). AI providers process content in the US under EU-US Data Privacy Framework adequacy. Cryptographic timestamps go to FreeTSA and DigiCert (US/EU) and the Bitcoin chain (global).

6. How long we keep it

7. Your rights

Under GDPR you have the right to access, rectify, delete, restrict, port, and object to processing of your personal data. To exercise any of these, email privacy@cultshield.com. We respond within 30 days. You may also lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) or your local supervisory authority.

8. Cookies

Cult Shield uses a single first-party session cookie required for authentication. No third-party cookies, no marketing cookies, no consent banner required (because we only set strictly necessary cookies).

9. Children

Cult Shield is not intended for use by people under 18. We do not knowingly collect data from minors.

10. Changes

We will email you about material changes to this policy and post the new version here with the effective date.

Effective date pending counsel review · Last drafted 2026-05-26