Privacy policy
Last updated: 21 October 2025
This privacy policy explains how Citium Tech ("we", "us", or "our") collects, uses, and protects information when you use our business software service (the "Service").
This policy applies to business customers and their users. We comply with applicable privacy laws including GDPR and CCPA where required.
1. Information we collect
Account information
- Name, email address, and job title
- Company name and business details
- Payment information (processed by secure third-party providers)
- Login credentials and account settings
Usage information
- How you use our Service (features accessed, time spent)
- Device and browser information
- IP address and general location
- Cookies for signin and basic functionality
Your business data
Any data you upload or create in our Service belongs to you. We only access it to provide the Service or if you ask for support.
2. Analytics and product improvement
PostHog analytics (required for authenticated users)
When you create an account and use our Service, we use PostHog, a product analytics platform, to understand how you interact with our features. This helps us identify bugs, improve performance, and build features you'll find valuable.
What PostHog collects when you're logged in:
- Pages you visit within the application
- Features and buttons you interact with
- Time spent on different parts of the Service
- Technical information (browser type, screen size, device type)
- Your account ID (to link usage patterns to your account for support purposes)
What PostHog does NOT collect:
- The specific content you create or upload
- Your business data or documents
- Passwords or payment information
- Keystrokes or form inputs
PostHog analytics is a required part of using our Service when you're logged in. By creating an account, you consent to this analytics collection as a condition of service. PostHog stores this data on secure servers and is bound by their own privacy policy. We retain PostHog analytics data for up to 12 months.
Google Analytics (optional for public pages)
On our public website pages (before you log in), we use Google Analytics to understand visitor traffic and improve our marketing. You can control Google Analytics through our cookie consent banner when you first visit our site. Google Analytics is not used when you're logged into your account.
3. How we use information
We use your information to:
- Provide and improve our Service
- Create and manage your account
- Process payments and send bills
- Provide customer support
- Send important service updates and product announcements
- Communicate with you about your account, billing, and the Service
- Keep our Service secure
- Comply with legal requirements
- Analyze product usage to improve features and user experience
We do not sell your information or use it for advertising.
4. Communications from us
We use your contact information to send you communications related to the Service, including:
- Transactional emails: Account notifications, password resets, billing receipts, and other essential service communications
- Service announcements: Security alerts, maintenance notifications, and critical updates
- Product updates: Information about new features, improvements, and changes to the Service
- Support communications: Responses to your inquiries and support requests
These communications are essential to providing the Service. You may manage certain email preferences in your account settings, but you will continue to receive transactional and critical service communications as outlined in our Terms of Service.
5. Information sharing
We only share your information with:
- Service providers who help us operate our Service, including:
- Hosting and infrastructure providers
- Payment processors
- Email service providers
- PostHog for product analytics (when you're logged in)
- Google Analytics for website analytics (on public pages only, with your consent)
- Legal authorities if required by law
- Business successors if we're acquired (we'll notify you first)
We never sell your personal information.
6. Your rights
You can:
- Access and update your account information anytime
- Request a copy of your data
- Ask us to delete your data (subject to legal requirements)
- Object to certain uses of your data
- Cancel your account and have your data deleted
- Control Google Analytics on public pages through our cookie consent banner
- Manage certain email preferences in your account settings
Note on PostHog analytics: Because PostHog analytics is required for authenticated users as a condition of service, you cannot opt out of it while maintaining an active account. However, if you delete your account, all associated PostHog analytics data linked to your account will be removed from our active systems.
Note on essential communications: While you can manage preferences for certain types of emails, you will continue to receive transactional and critical service communications as they are necessary to provide the Service.
Contact us at support@app.citiumtech.com to exercise these rights.
7. Data security
We protect your data with:
- Encryption of data in storage and transmission
- Secure signin with password protection
- Limited employee access to your data
- Regular security updates and monitoring
- Secure third-party service providers (including PostHog) with strong security practices
If a data breach occurs, we'll notify affected users and authorities as required by law.
8. Data retention and account deletion
Active accounts
While your account is active, we retain:
- Account data: For the duration of your active account
- Usage logs and analytics: Up to 12 months for service improvement and security
Account deletion
When you delete your account, your personal data is removed from our active systems and you will no longer be able to access your account. This action is permanent and cannot be undone.
However, we may retain certain anonymized billing and transaction records as required by law for:
- Billing and tax records: Up to 7 years as required by tax authorities
- Payment dispute records: As required by payment processors and applicable law
- Fraud prevention: Anonymized records to protect against abuse
These retained records are anonymized and cannot be used to identify you personally. They are kept solely for legal compliance, financial record-keeping, and fraud prevention purposes.
9. International data
Your data is stored and processed in the United States. PostHog analytics data is also stored on servers in the United States. By using our Service, you consent to this transfer and processing.
10. Cookies
We use cookies to keep you logged in and understand how you use our Service. On public pages, we also use cookies for Google Analytics (with your consent via our cookie banner). You can disable cookies in your browser, but some features may not work properly.
11. Policy updates
We may update this policy occasionally. We'll email you about significant changes at least 30 days in advance. Continued use of our Service means you accept the updated policy.
12. Contact us
Questions about this privacy policy? Contact us at support@app.citiumtech.com