Privacy Policy
1. Scope
This Privacy Policy explains how Coasterly AI handles information when organizations and their users access the service, contact us or use AI-assisted RFQ, drawing, estimation and production workflows.
Coasterly AI is operated by Kirill Ginzburg (קיריל גינזבורג), Israeli identification number 346904519 (the "Operator").
2. Information we handle
- Account and contact information, such as names, business email addresses, organization details and user roles.
- Billing and subscription information. Payment card details may be handled directly by a payment provider.
- Customer Content, including drawings, RFQs, BOMs, specifications, prices, estimates and related files.
- Technical information, including IP address, browser and device information, authentication events and security logs.
- Usage and activity information, including screens, actions, processing events, feature use, errors and performance measurements.
- Support communications and information provided in requests or feedback.
3. How information is used
Information is used to provide and operate the service, authenticate users, maintain organization access, process Customer Content, generate requested output, provide support, administer plans and billing, protect security, prevent misuse, monitor reliability, understand product usage and comply with legal obligations.
4. Customer roles
For account, business contact, security and service-usage information, Coasterly AI generally determines why and how information is handled. Where Customer Content contains personal data controlled by a customer, the customer generally determines the purpose of that processing and Coasterly AI handles it to provide the service. A separate Data Processing Agreement may apply where required.
5. AI and service providers
Information may be shared with providers that support hosting, databases, authentication, payments, monitoring, communications and AI processing. Depending on the functionality used, these providers may include OpenAI, Anthropic, Google and Supabase. Providers receive only information reasonably needed for their services and are subject to applicable contractual and technical controls.
Coasterly AI does not use Customer Content to train its own general-purpose AI models. AI providers used by the service must not use Customer Content for general model training where the applicable service terms and configuration provide that protection.
6. Cookies and similar technologies
The service uses essential browser storage and similar technologies for authentication, session continuity, security and core operation. It also records product usage and performance events needed to monitor and improve the service. Coasterly AI does not currently use Customer Content or account information for third-party behavioral advertising. Material new advertising or marketing tracking would be assessed separately before use.
7. International processing
Coasterly AI and its providers may process information in countries other than the user's location. Where required, appropriate contractual or legal safeguards will be used for international transfers.
8. Retention and deletion
Account, security and legal records are kept for as long as reasonably needed for the service, compliance, dispute resolution and protection of legal rights. Customer Content may remain stored after a project or account is removed. A customer may request permanent deletion through the contact below. Deletion may take a reasonable period and limited backup copies may remain temporarily for security, continuity or legal obligations.
9. Security
Coasterly AI uses reasonable administrative, organizational and technical measures designed to protect information. No system can guarantee absolute security, and users are responsible for protecting their credentials and promptly reporting suspected unauthorized access.
10. Rights and requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to certain processing, or to receive a portable copy of information. Requests may require identity and authority verification. When Coasterly AI processes personal data only for a customer, the request may be referred to that customer.
11. Changes
This policy may be updated as the service, providers and legal requirements change. The current version and effective date will remain available here. A Privacy Policy update does not by itself require a new Terms acceptance.
12. Contact
The data controller for the account and service information described above is Kirill Ginzburg (קיריל גינזבורג), Israeli identification number 346904519, operating under the Coasterly AI name. Privacy questions and requests may be sent to hello@costerly.ai.