KRITIA

Privacy notice

Who we are. Kritia (“we”) is a compliance record-keeping tool for businesses using AI, operated from Cork, Ireland. Contact: info@kritia.ai.

Using the free tools. The scope checker and the policy generator run in your browser, and your answers are not stored unless you save them to an account.

The website scanner is different. It does not run in your browser: we fetch one page of the address you give us from our own servers, the way a browser would, and run fixed checks over it. The preview stores nothing. Opening the full report needs an account, and at that point we record the address you scanned, the finding counts, the engine version and a SHA-256 hash of the report text — never the content of your page — and we email the report to your account address.

If you create an account. We store your email address, your organisation’s name and country, any assessments you save, and the AI systems you record in your inventory. We use it to provide the service you signed up for (Art. 6(1)(b) GDPR, performance of a contract). You can sign in with a password, with a single-use link emailed to you, or with Google or GitHub where we have enabled them. Kritia keeps no password of its own: authentication is handled by Supabase Auth, which stores only a salted hash, and no Kritia table holds your password.

Cookies. Signing in sets authentication cookies, managed by Supabase, which hold your session and let it be refreshed without asking you to sign in repeatedly. They persist between visits until you sign out. They are strictly necessary to operate the service and need no consent. We set no advertising or cross-site tracking cookies.

Analytics. We use Vercel Analytics to count page views and see which pages people arrive on. It sets no cookies and builds no cross-site profile of you. Legitimate interest (Art. 6(1)(f)) in knowing whether the product is useful.

The evidence trail: read this one. When we issue a document we append a row to a log: a reference to your organisation, what was issued, when, and a SHA-256 hash of the document text. The log is append-only. Update and delete are revoked at the database level, not merely avoided, because a compliance record you can quietly rewrite is worth nothing. It stores no document content: the hash proves a document is unchanged, it does not reveal it.

Two things we would rather state than gloss. First, where you use the free policy generator without an account, the row references a hash of the email address you gave: not the address itself, but still data that relates to you. Second, that log is the one place we cannot simply delete on request: erasing rows would destroy the integrity the log exists to provide. If you ask us to erase your data we delete your account, your assessments and your inventory, and we will tell you honestly what remains in the log and why. We are a small team and that step is manual today.

Who processes your data. Supabase (database and authentication, hosted in Ireland), Vercel (hosting and analytics), Resend (sending the emails you ask us to send), OpenAI (only when you use Ask Kritia — see below), and, if you take a paid subscription, Stripe, which handles payment. Card details go directly to Stripe; we never see or store them. We do not sell or share your data with anyone else.

Ask Kritia and your data. When you ask a question, we send that question, the conversation you are having, and a short summary of your organisation’s own records (company name, country, size band, plan, how many AI systems you have recorded, and your latest scope-check verdict) to OpenAI, which generates the answer. Your data is not used to train their models. The assistant explains; it never writes the policies or obligation text we issue — those come from fixed templates, which is why a document we generate can be reviewed and signed off, and a chat answer cannot. If you would rather nothing left our own infrastructure, do not use Ask Kritia; every other part of Kritia works without it.

Where data lives. Your account data is stored in the EU (Supabase, Ireland, eu-west-1). That is a product decision, not a default: a tool selling EU data governance should not host EU customer data elsewhere. Requests are served by Vercel, whose network is global, so a request may be processed outside the EU even though the data at rest is not. Ask Kritia questions are processed by OpenAI, which may process them outside the EU under standard transfer safeguards. We would rather say that plainly than imply an end-to-end EU guarantee we do not currently have.

Product updates. Requesting a scan report also adds your account email address to our product-update list. We send from one address, we do not pass it to anyone, and we will take you off it the moment you ask.

Retention. Product-update records are kept until you ask us to remove them. Account data is kept while your account is open and for 30 days after you close it. Evidence-log entries are kept for six years, which is roughly how long you may need to prove what you did. These periods are our policy and are applied by hand. We have not yet automated deletion, and we would rather say so than imply a scheduler exists.

Your rights. Access, rectification, erasure, restriction, portability, objection: email us. You can lodge a complaint with the Data Protection Commission (dataprotection.ie).

Last updated: 28 August 2026.