Legal
Privacy Policy
Camus is built local-first and consent-first. This policy describes what we collect, why, how long we keep it, and the rights you have. For a plain-language walkthrough of the data flow, see the Trust page.
1. Who we are
Camus (“we”, “us”) is operated by Nathan Van de Ridder. For any privacy question or request, contact nathan@hirecamus.com.
For account data and product telemetry, we act as the data controller. For buyer data processed inside your workspace (people who engage with your posts), you, our customer, are the controller and Camus acts as a processor following your configuration and instructions.
2. This website
hirecamus.com sets no cookies and runs no analytics or advertising trackers. Our hosting provider (Vercel) processes standard server logs, including IP addresses, for security and delivery. That is all.
3. Data we process in the product
On your Mac, staying on your Mac
- The raw work journal is created and stored locally, encrypted, and never leaves your Mac. It rolls off after 14 days.
- Recognized password managers, banking, health, payroll, HR and private-browsing windows are blocked. Mail, messaging, terminal and calls produce metadata only, never message text.
- Pause stops capture and sending immediately and discards in-flight processing.
What can reach our servers
- Account data: your Slack workspace and member identity, email, preferences, device pairing keys.
- Work digests: bounded, locally redacted summaries of authorized work signals, sent only after a separate, versioned cloud consent. Every attempted send is logged locally so you can audit it.
- Content data: drafts, your edits, published post URLs and your voice profile.
- Public engagement data: after a separate per-post opt-in, public reactions and comments on your tracked LinkedIn post, measured at day 1 and day 3, then stopped.
- Buyer data (as processor for you): public professional identity of engagers (name, title, company, public profile), qualification scores and evidence, enrichment results requested by your admin, and the conversations and opportunities your team records.
4. What we never do
- We never publish to LinkedIn on your behalf.
- We never contact, email or message buyers.
- We never bulk-enrich contacts. Email enrichment runs for one sales-ready person at a time, after an explicit admin action.
- We never sell personal data.
5. Legal bases
- Consent for Mac capture, cloud processing and per-post public measurement. Each consent is separate, versioned and revocable; withdrawal stops new processing immediately.
- Contract for account management and providing the service.
- Legitimate interest for security, abuse prevention and service improvement, and, on the customer’s side as controller, for B2B prospecting on public professional data.
6. Retention and deletion
- Raw local journal: 14 days, on your Mac only.
- Bounded digest evidence: 14 days on our servers; egress metadata: 90 days.
- Public engagements, derived buyer signals, scores and sales-ready records: 90 days, unless a human explicitly preserves a minimal commercial record.
- Published posts and voice profiles: until you delete them.
- “Delete my data” starts a deletion job with a 24-hour completion deadline.
- Deleting a buyer removes their signals, scores, activations, conversations and local opportunities, and leaves an irreversible, hashed tombstone that blocks re-ingestion.
7. Subprocessors
We use a small set of providers to run Camus. Model calls always go through Camus servers; your Mac never calls an AI provider directly.
| Provider | Purpose |
|---|---|
| Vercel | Website and application hosting |
| Supabase | Database (organization-scoped, row-level security) |
| Slack | Editorial workflow in your workspace |
| Anthropic / OpenAI | Language-model processing of redacted, bounded digests |
| Serper | Public web search from bounded search terms |
| Apify | Public LinkedIn post measurement, after your per-post opt-in |
| Airscale | Contact enrichment, one sales-ready person at a time, on admin action |
Some providers process data in the United States. Where personal data leaves the EEA, we rely on appropriate safeguards such as standard contractual clauses.
8. Security
- Device pairing uses hardware-backed P-256 keys; signed requests protect every product API call.
- All data is organization-scoped with row-level security and encrypted in transit.
- The Mac app keeps no product data cache on disk; secrets live in the Keychain and Secure Enclave.
9. Your rights
Under the GDPR and similar laws you can request access, rectification, deletion, restriction, portability, or object to processing. Write to nathan@hirecamus.com; we answer within 30 days. You can also lodge a complaint with your supervisory authority.
If you engaged with a customer’s post and want your data removed, contact us or the customer directly. Deletion is enforced with irreversible tombstones so you are not re-ingested later.
10. Children
Camus is a business tool and is not directed at anyone under 16.
11. Changes
We will post any change to this policy on this page with a new date. Material changes are announced to workspace admins.
Plain-language companion: the Trust page describes exactly what Camus observes, sends and keeps, screen by screen.