Last updated: April 8, 2026 · Effective immediately
When you create an account via Firebase Authentication, we collect your email address, display name, and profile photo. If you use Google OAuth, we receive your Google profile information as authorized by you.
During mediation sessions, we process and store: transcripts (text only), conflict analysis primitives (actors, claims, interests, constraints, leverage, commitments, events, narratives), emotion timeline data, session metadata (title, type, duration, phase progression), and any agreements drafted within the platform.
Billing is processed exclusively by Stripe Inc. We store only your Stripe customer ID. We never store, process, or have access to credit card numbers, CVVs, or full card details. Stripe's privacy policy governs payment data processing.
We collect anonymized, aggregated usage metrics including session counts, feature usage frequency, performance data, and error logs. These metrics cannot be traced back to individual users or session content.
We collect browser type, operating system, IP address (for rate limiting and security only — not stored long-term), and WebSocket connection metadata necessary for real-time mediation functionality.
Live audio is streamed for real-time processing by default.
Audio streams from your browser microphone through our WebSocket server to the Google Gemini Live Audio API in real time. Optional recording features may store audio only when explicitly enabled with participant consent and are governed by configured retention controls. Transcripts and structured conflict primitives may be stored as case data for reports, exports, and user-controlled deletion.
We process your data under the following lawful bases (GDPR Article 6):
| Purpose | Legal Basis |
|---|---|
| Provide mediation service | Contract performance |
| Generate session reports and analysis | Contract performance |
| Process payments | Contract performance |
| Send service communications | Legitimate interest |
| Detect and prevent abuse | Legitimate interest |
| Improve service quality | Legitimate interest |
| Marketing communications | Consent (opt-in only) |
Your session transcripts are processed by Google Gemini (via Vertex AI) for real-time mediation assistance and conflict analysis.
We do not sell, rent, or share your personal data. We use the following sub-processors:
| Provider | Purpose | Data Processed |
|---|---|---|
| Google Cloud / Vertex AI | AI processing, hosting | Transcripts (real-time, not retained) |
| Firebase (Google) | Authentication, database | Account info, session data |
| Stripe Inc. | Payment processing | Billing details (Stripe-managed) |
| Google Cloud Run | Application hosting | Request/response data |
Data may also be disclosed if required by law, subpoena, or court order, or to protect the safety of our users when automated systems detect potential harm.
Our infrastructure is hosted in the United States (Google Cloud, us-east1 region). If you are located outside the United States, your data will be transferred to and processed in the US. We rely on Google's Standard Contractual Clauses (SCCs) and Stripe's Data Processing Agreement for lawful international transfers under GDPR Chapter V.
Under GDPR (EU/EEA), CCPA (California), LGPD (Brazil), and equivalent regulations, you have the following rights:
To exercise any right, email privacy@tacitus.me. We will respond within 30 days (GDPR) or 45 days (CCPA).
CONCORDIA uses minimal browser storage:
| Item | Type | Purpose | Duration |
|---|---|---|---|
| Firebase Auth token | Essential | Authentication | Session |
| Cookie consent preference | Essential | Remember your choice | 1 year |
| Session draft state | Functional | Resume interrupted sessions | 7 days |
| User preferences | Functional | UI settings, language | Persistent |
We do not use tracking cookies, advertising pixels, or analytics cookies from third parties.
CONCORDIA is not directed at children under 13. We do not knowingly collect data from children under 13. In educational settings (ages 13-18), the school administrator acts as the account holder and is responsible for obtaining appropriate parental/guardian consent in compliance with COPPA and applicable local laws. If we learn that we have collected data from a child under 13 without parental consent, we will delete it promptly.
For privacy concerns, data requests, or to file a complaint:
Data Protection Contact
Email: privacy@tacitus.me
Entity: TACITUS
You also have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France, or the relevant EU Member State DPA).
We will notify you of material changes via email and in-app notification at least 30 days before they take effect. Non-material changes (clarifications, formatting) may be made without notice. The “Last updated” date at the top reflects the most recent revision.
Same engine as voice and text mediation
Ask me about CONCORDIA
Platform & concepts
Sign in for personalized session insights
AI advisor — not legal counsel. For informational purposes only.