Privacy Policy
Last updated: 19 December 2025
This Privacy Policy explains how WebSailors FZCO, incorporated in IFZA - Dubai Silicon Oasis, UAE ("Company", "we", "our", "us"), collects, uses, stores and protects personal data when you use CTOx AI, CTOx.pro, and all related services ("Service").
By using the Service, you agree to the practices described in this Policy.
1. Information We Collect
We collect the following categories of data:
1.1. Information you provide directly
- Name, email address, account details
- Subscription and billing information (processed by third-party payment providers; we do not store full payment data)
- Documents, text, or files uploaded for analysis
- Messages, prompts, and chat interactions with CTOx AI
- Support requests and communication logs
1.2. Automatically collected information
- IP address, device information, browser type
- Usage statistics, feature interactions
- Session identifiers and access logs
- Cookies and similar technologies (essential for authentication and security)
1.3. AI interaction data
To operate and personalise the Service, we temporarily process:
- prompts, messages and system instructions
- context history (session-based or long-term, depending on subscription)
- uploaded documents for analysis
We do not use your content to train external AI models.
2. How We Use Your Information
We use personal data to:
- Provide and operate CTOx AI
- Perform AI analysis of your requests
- Improve accuracy, reasoning, and personalization of the Service
- Manage subscriptions, billing, and user accounts
- Respond to support requests
- Ensure platform security and prevent abuse
- Comply with legal obligations in the UAE
We process data strictly for service functionality - not for advertising or resale.
3. How Your Documents & AI Inputs Are Handled
3.1. Ownership
You retain full ownership of all documents, text, and content you upload.
3.2. Processing
Uploaded files are processed solely for:
- generating AI responses
- providing personalised reasoning
- enabling memory features for subscribers
3.3. Storage
Document storage depends on your usage tier:
- Free tier: files stored temporarily for active session only, then automatically removed.
- Pro/Pro+ tier: longer retention strictly for providing long-term memory and personalised features.
You may request deletion at any time (email: denis@ctox.pro).
3.4. Training
Your content is never used to train external AI models (OpenAI, Anthropic, etc.).
We may use anonymised statistics only to improve our own product (performance, safety, UX).
4. Cookies and Tracking
We use essential cookies to:
- authenticate user sessions
- provide secure access
- detect abuse
- store preferences (theme, locale)
We do not use advertising cookies or third-party trackers.
5. Legal Basis (for international users)
Even though UAE law does not require GDPR classification, international best practices apply:
- Contract performance (providing the Service)
- Legitimate interest (security, product improvement)
- Consent (when uploading data or documents voluntarily)
6. Sharing of Information
We do not sell, rent, or trade your personal data.
We may share limited information with:
6.1. Service providers
Only trusted partners necessary to operate CTOx AI, including:
- cloud hosting providers
- AI API providers (processing only your inputs for response generation)
- payment processors (Stripe, Paddle, etc.)
- analytics providers (privacy-preserving only)
6.2. Legal compliance
We may disclose data if required by:
- UAE law
- IFZA regulators
- court orders
- fraud or abuse investigations
We never share user data unless legally required.
7. Data Retention
We retain personal data only as long as needed:
- Account information: until you delete your account
- Chat data: depends on subscription tier
- Uploaded documents: temporary (free tier) or persistent (Pro/Pro+)
- Billing records: as required by UAE law
You may request deletion by contacting: denis@ctox.pro
8. Data Security
We implement multiple layers of protection:
- encrypted data transmission (TLS)
- restricted internal access
- separation of user datasets
- secure cloud storage
- regular audits and monitoring
No system is 100% secure, but we apply industry-standard safeguards.
9. International Data Transfers
Your data may be processed on servers outside your home country.
We ensure that such transfers meet UAE regulatory requirements and international safety standards.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- access your personal data
- request corrections
- export your data
- request deletion
- withdraw consent (where applicable)
To exercise these rights: denis@ctox.pro
11. Children's Privacy
The Service is not intended for individuals under 18.
We do not knowingly collect data from minors.
12. Changes to This Policy
We may update this Privacy Policy periodically.
Updates will be posted with a new "Last updated" date.
Continued use of the Service after changes means you accept the revised Policy.