This Privacy Policy describes how CIAG Global, LLC, a Minnesota limited liability company ("Company," "we," "us"), collects, uses, and shares information in connection with the CIAG Quantum LENS document-extraction service (the "Service"). It supplements, and should be read together with, our Terms of Service. By using the Service, you agree to the collection and use of information as described here.
When you create an account, we collect your email address, a password (which we store only as a one-way bcrypt hash — we never store or transmit your actual password), an optional company name, and the IP address you signed up from. We also record the fact and timestamp that you accepted our Terms of Service, tied to your account, so that acceptance is a verifiable record rather than just a client-side assumption.
When you submit a document for extraction, it is read into memory, converted into the images our AI provider needs, and sent to that provider to perform the extraction you requested. We do not write your document to disk and we do not store it, or the extraction result, in our own database. Once the result is returned to your browser, our copy of it is discarded. (Our AI provider's own, separate retention of what it processes is described in Section 3.)
If you purchase additional Quanta, your payment is handled entirely by Stripe through its own hosted checkout — we never see or store your card number or other payment credentials. We retain only Stripe's checkout session identifier, the purchase amount, the Quanta credited, and the purchase status, so we can reconcile your balance.
For every extraction you run, we record the number of pages processed, the AI tokens consumed, and the resulting Quanta cost, tied to your account. This is our billing ledger — it reflects what you were charged, not the content of what you processed.
We log basic request metadata (such as IP address and timestamps) for security and anti-abuse purposes — for example, limiting how many accounts can be created from one IP address per day, and blocking known disposable-email signups. These operational logs do not contain the content of your documents or extraction results.
We do not use the content of documents you upload, or data we extract from them, for any purpose other than returning the result to you.
We do not sell your personal information. We share information only with the service providers below, each acting on our behalf to help operate the Service, or as required by law.
| Provider | Purpose | What it receives |
|---|---|---|
| OpenAI | AI-based document extraction | The document images you submit for extraction, and the resulting output. Processed under OpenAI's API terms: not used to train OpenAI's models, but retained by OpenAI for up to 30 days for abuse-monitoring purposes under its own data usage policy. We do not currently have a zero- or reduced-retention agreement in place with OpenAI. |
| Stripe | Payment processing | Whatever Stripe's own hosted checkout collects directly from you (card details, billing contact). Governed by Stripe's own privacy policy and terms. |
| Our email delivery provider | Sending account-verification and password-reset emails | Your email address and the content of those transactional emails only — we do not send marketing email through this channel. |
| Cloudflare (Turnstile) | Distinguishing real signups from automated/bot signups | Limited technical/browser signals needed to perform that check, under Cloudflare's own privacy policy. |
| Microsoft Azure & Neon | Application hosting and database hosting | All data described in Section 1, as our infrastructure providers. Both are located in the United States. |
We may also disclose information if required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.
Passwords are stored only as bcrypt hashes with a unique salt per password — never in plain text, and never logged. Email-verification and password-reset links are single-use and are stored server-side only as a one-way hash of the token, so the raw link cannot be reconstructed from our database. All traffic to the Service is encrypted in transit. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
The Service does not use advertising or analytics trackers. Your sign-in session is kept in your browser's local storage, solely to keep you logged in between visits — clearing it will sign you out. Cloudflare's Turnstile widget, used on signup, may set its own cookies as part of performing its bot-check, under Cloudflare's own policy.
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old, consistent with the eligibility requirement in our Terms of Service. If you believe a minor has provided us with personal information, contact us at will@ciag-global.com and we will take appropriate steps to delete it.
The Service and the infrastructure it runs on are located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice — such as by posting an updated effective date on this page, or emailing the address on your account. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
CIAG Global, LLC, a Minnesota limited liability company
Contact: will@ciag-global.com
Address: 330 S Second Ave, Suite 200 1900, Minneapolis, MN 55401