Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains how Levacells SRL (8 Avenue de la Renaissance, 1000 Brussels, Belgium), the operator of CFR21 and the data controller ("we", "us"), collects, uses, and protects your information when you use our website and Service. Contact: contact@levacells.com.
1. Information we collect
- Account information: your name, email address, and password (stored only as a secure hash).
- Usage data: the questions you ask and chat history, used to provide and improve the Service.
- Billing information: processed and stored by our payment processor, Stripe. We do not store your full card details.
- Technical data: standard log and device information for security and reliability.
2. How we use information
We use your information to operate the Service, authenticate you, process payments, respond to support requests, and improve our product. We do not sell your personal information.
3. Cookies
CFR21 uses only strictly necessary (essential) cookies. We do not use advertising, marketing, analytics, or cross-site tracking cookies, and we do not sell or share cookie data with third parties for advertising.
The cookies we set are:
-
cfr21_access— an encrypted, httpOnly session token that keeps you signed in. Scoped to.cfr21.comso a single login works across cfr21.com and app.cfr21.com. Not readable by JavaScript. -
cfr21_loggedin— a non-sensitive flag indicating that a session exists, so the interface can show the correct signed-in state. -
cfr21_csrf— a security token used to protect your account against cross-site request forgery (CSRF).
These cookies expire when your session ends or after a fixed period, and are removed when you sign out. Because they are essential to providing the Service, they cannot be disabled while using your account; you may block cookies in your browser, but the Service will not function. We display a notice about these cookies on your first visit.
4. Data sharing & sub-processors
We share data only with service providers ("sub-processors") that help us operate the Service, and only as necessary to provide it or comply with the law:
- Amazon Web Services (AWS) — cloud hosting and the Amazon Bedrock AI models that generate answers (EU/US regions).
- Stripe — payment processing and billing. Card details are handled entirely by Stripe and are never stored on our servers.
- Amazon SES — transactional email (verification, password reset, receipts).
We do not sell your personal information, and your questions and content are not used to train third-party or foundation AI models (Amazon Bedrock does not use customer prompts to train its models).
5. Data retention and security
We retain your information for as long as your account is active. We use industry-standard measures to protect your data, including encryption in transit (HTTPS), secure password hashing (Argon2), httpOnly session cookies, and CSRF protection.
6. Your rights
You may access, update, or delete your account information at any time from your account settings, or by contacting us. Deleting your account permanently removes your personal data and chat history. Depending on your jurisdiction (e.g. the EEA/UK under GDPR, or California under the CCPA), you may have additional rights to access, correct, port, or erase your data, and to lodge a complaint with a supervisory authority.
7. Children's privacy
CFR21 is a professional tool intended for business use and is not directed to individuals under 18. We do not knowingly collect personal information from children.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice within the Service.
9. Contact
Data controller: Levacells SRL, 8 Avenue de la Renaissance, 1000 Brussels, Belgium. Questions about your privacy or to exercise your rights, email contact@levacells.com or use our contact form. EEA/UK users may also lodge a complaint with their local data-protection authority (in Belgium, the Autorité de protection des données).