Privacy Policy

How DeepCell collects, uses, stores, shares, and protects information you create while using DeepCell.

Effective
Last updated

This Privacy Policy explains how DEEPCELL AI PTE. LTD. ("DeepCell", "we", "us") collects, uses, stores, shares, and protects information generated when you use DeepCell.

Place of incorporation: Singapore. For any question, complaint, or personal-data request, contact us at hello@deepcell.net.

Your use of DeepCell is also governed by our Terms of Service. Where this Policy and the Terms conflict on a matter of personal-data protection, this Policy controls.


1. Scope#

This Policy applies to DeepCell's website, command-line tool, MCP endpoint, web agent, Excel add-in, cloud collaboration, and related services.

DeepCell provides an open file format (.deepcell) for storing conclusions together with the assumptions, evidence, and calculations behind them, plus the features to create, view, analyze, sync, and collaborate on those files.

This Policy does not apply to services provided independently by third parties that determine their own processing. Examples: an AI model, agent platform, MCP client, Git host, or other external tool that you choose and connect. Those services are governed by their own privacy policies.


2. Core principles#

2.1 The format is open, and it is yours. .deepcell is a documented file format, not a container that only we can read. You can author, read, validate, and exchange .deepcell files with your own tooling or any third-party implementation, with no DeepCell account and no contact with our servers at any point. Nothing in this Policy applies to files you handle that way, because we never see them.

2.2 Collect as little as possible. We process information only as necessary to provide product features, administer accounts, support collaboration, secure the service, diagnose faults, or meet legal obligations.

2.3 Our tools, however, are clients for a service. The CLI, MCP endpoint, web agent, and Excel add-in are thin clients: parsing, calculation, querying, editing, and validation all run on DeepCell's servers, not on your device. So working on a file through our tools sends that file's contents to us — this is true of read-only-looking commands too, and there is no offline mode in which they run locally. Section 3.3 sets out exactly what is and is not sent.

2.4 Installing is not sending. Installing the CLI, or having .deepcell files on disk, uploads nothing on its own. The upload happens when you run a command that operates on a file.

When you use the web agent, remote MCP, online research, export, or another connected feature, the prompts, queries, file fragments, model inputs and outputs, and tool-call records required to complete that request are transmitted and processed — though not necessarily retained as a collaboration file. Section 7 names the specific recipients.


3. Information we may collect#

3.1 Information you provide#

When you register, sign in, join a team, contact us, request a demo, or submit a support request, we may process:

  • Email address
  • Name or display name
  • Avatar
  • Organization or team information
  • Emails, feedback, and other communications you send us
  • Any other information you choose to submit

If you sign in with a third-party account, we may receive from that identity provider the information needed to complete sign-in — typically email address, name, avatar, and the third-party account identifier.

3.2 Account, sign-in, and security information#

  • User ID, team ID, and permission records
  • Sign-in times, session state, and authentication records
  • IP address, browser type, operating system, and device information
  • OAuth grants and related security metadata
  • Failed access attempts, security events, and error logs

3.3 The CLI: what stays local, and what is sent#

Stays on your device. Your .deepcell files themselves, until a command acts on one. Your configuration and stored credentials (under ~/.deepcell/). Anything you do with the open format using your own or third-party tooling. And deepcell viewer, which builds a URL locally without calling us.

Is sent to DeepCell. Everything else. The CLI is a thin client for our API, so any command that inspects, queries, edits, validates, searches, exports, or versions a model runs on our servers and therefore transmits the file contents involved. This includes commands that sound purely local — cat, query, grep, describe, and describe --lint (validation) among them. Files sent this way are stored in the workspace the command targets and are covered by Section 3.4.

Running a command without signing in still uploads. If you have no stored credentials, the CLI creates an anonymous account and a temporary workspace on our servers and works there, printing a notice when it does. Section 3.6 describes that mode and its retention. Set DEEPCELL_NO_ANON=1 to disable the behavior; the affected commands then fail rather than upload.

If you point the CLI at your own deployment (DEEPCELL_API_URL), file contents go to that server instead, and our processing described here does not apply to it.

3.4 Workspace contents#

This covers every file that reaches a DeepCell workspace — whether you uploaded it explicitly, synced it, shared it, or simply ran a command from Section 3.3 against it:

  • The .deepcell files you upload or sync
  • File name, size, type, version, and modification time
  • The conclusions, assumptions, evidence, formulas, and calculation steps inside those files
  • Author, collaborator, and permission records
  • Edit history, version history, and conflict records
  • Share links, access permissions, and access records

Files may contain business information written by you or your agent. You are responsible for ensuring you have the right to process, upload, and share it.

3.5 AI and agent features#

When you use the web agent, online research, remote MCP, or other AI features:

  • Prompts and questions you submit
  • Files or file fragments needed to complete the request
  • Search terms and research tasks
  • Model inputs and outputs
  • Tool calls, run state, and error information
  • Technical traces generated for security, debugging, and run tracking

We process this only as necessary to provide the feature, keep the service running, and handle faults.

3.6 Anonymous and demo use#

You can try parts of DeepCell without registering. When you do, we create a server-side anonymous account and workspace so your work survives a page refresh. In that mode we process:

  • An anonymous user identifier and a browser cookie that links you to it
  • The workspace and files you create during the session
  • Activity records including IP address and user agent

On the website, we ask you to accept a notice before the anonymous session is created, and the referral and campaign information described in Section 3.7 is recorded only from that point. Opening a public share link does not create an anonymous session. The CLI does not ask: it prints a notice and proceeds, as described in Section 3.3, and DEEPCELL_NO_ANON=1 prevents it.

Anonymous data has its own retention rules, stated in Section 10. If you later register, you may claim the anonymous workspace; the anonymous record is then merged into your account and deleted.

3.7 Website and usage logs#

  • IP address
  • Access time
  • Browser and operating-system type
  • Pages visited and features used
  • Request status, response time, and error information
  • Security, audit, and troubleshooting logs

General usage telemetry does not include full file contents unless you upload, sync, or invoke an online feature that must read them.

Referral and campaign measurement. When you reach DeepCell through a link we placed — an advertisement, a campaign, a newsletter, or a partner site — the address you arrive at can carry campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) or an advertising click identifier (for example gclid or fbclid). We record those, along with the address of the site that referred you and the page you landed on, so that we can tell which of our own efforts bring people to DeepCell.

We record this only for the first visit in which it appears, and it stays with your visitor record if you later register. We drop the query string and fragment from the referring address before storing it, because those can carry information from the referring site that we neither need nor want.

We read these values from the address you arrive at. We do not track you across other websites and we do not sell this information.

Website and product analytics. With your consent, we also measure how people move through our website and product so we can see where it works and where it does not. This covers:

  • pages viewed on our marketing site, our blog, and our sign-up pages
  • which calls to action were clicked
  • the steps of getting started: beginning a demo, generating a model, sharing a link, creating an account
  • whether a share link you received led you to try DeepCell yourself
  • page-performance measurements, such as how long a page took to become usable

We collect this to our own servers, under a random visitor identifier that is created only after you consent and is not linked to any identifier from another website. We ask before any of it is recorded, and declining costs you nothing — the product behaves identically either way. See Section 6 for the consent mechanism and the storage keys involved.

Google Analytics. Where we enable Google Analytics and Google Tag Manager, they load only after you have consented, and until then Google Consent Mode is set to deny storage. When enabled, Google acts as a processor for this measurement, and we may report the completion of a sign-up, a generated model, or a shared link to Google Ads so we can tell which advertising works. We do not send Google your email address, your name, your file contents, or any DeepCell account identifier; the account reference we send is a one-way hash. If you decline, no Google tag is loaded at all.

We do not use advertising or cross-site tracking cookies of our own, and we do not sell any of this information.


PurposeLegal basis (GDPR Art. 6 where applicable)
Provide, maintain, and improve DeepCellPerformance of a contract
Create and administer accounts, teams, permissions, and workspacesPerformance of a contract
Store, sync, display, and share files you uploadPerformance of a contract
Execute the AI, search, research, or MCP requests you initiatePerformance of a contract
Handle sign-in, authentication, and account securityPerformance of a contract; legal obligation
Provide customer support, demos, and consultationPerformance of a contract; legitimate interests
Debug, monitor service health, and prevent abuseLegitimate interests
Measure which campaigns and referrals bring visitors to DeepCellLegitimate interests
Meet contractual and applicable legal obligationsLegal obligation
Establish, exercise, or defend legal claimsLegitimate interests
Send product updates or marketing communicationsConsent (opt-in; withdraw at any time)
Produce aggregated or anonymized statistics that no longer identify anyoneLegitimate interests

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We do not make decisions with a significant effect on you based solely on automated processing.

Marketing email is sent only to accounts that explicitly opted in; we record the opt-in timestamp, and every marketing message carries an unsubscribe link.


5. AI model training and content processing#

We do not use the contents of your .deepcell files, your prompts, or model outputs to train general-purpose AI models — ours or anyone else's.

When you use AI or agent features, the prompts, file fragments, search terms, model inputs and outputs, and tool-call records required to produce a result may be sent to the providers named in Section 7 for model inference, search, and run tracing. Those providers may process the data only as necessary to provide their service, and we do not authorize them to use your content to train general-purpose models.

Please note:

  • "Not used for training" does not mean the data is never processed. Model providers process it to answer the request, and may retain it briefly for abuse monitoring under their own terms.
  • Run traces are retained by a third party. Our agent-tracing provider stores prompts, file fragments, and model outputs so we can debug failed runs. See Section 10 for the retention window.
  • Third-party models and agent platforms you choose to connect are governed by their own data policies.
  • If you send files or content directly to a third-party platform, that platform's handling is outside DeepCell's control.

6. Cookies, browser storage, and similar technologies#

We use cookies and browser storage to keep you signed in, remember your language, protect against attacks, keep unregistered work from disappearing on a refresh, and — with your consent — measure how people find and use DeepCell. We do not use advertising or cross-site tracking cookies of our own.

Cookie or keyPurposeLifetime
refresh_tokenKeeps you signed in; HttpOnly and SecureUp to 90 days, rolling; the session ends 30 days after first sign-in regardless
NEXT_LOCALERemembers your language choice1 year
Demo session cookieLinks a browser to its anonymous workspace so unregistered work survives a refreshSession lifetime of the demo account
OAuth state cookieCSRF protection during third-party sign-inMinutes; deleted as soon as sign-in completes
demo_consent (local storage)Records that you accepted the demo notice, so we do not ask againUntil you clear it
deepcell.attribution (session storage)Holds the campaign or referral you arrived from until it is recorded, so moving around the site cannot erase itThe browser tab session
deepcell.analytics_consent (local storage)Records whether you accepted or declined analytics, so we do not ask againUntil you clear it
deepcell.visitor_id (local storage)A random identifier that lets us count one person's visit as one visit. Created only if you accept analytics, and deleted if you later declineUntil you clear it or decline
_ga, _ga_* (Google Analytics)Set only where Google Analytics is enabled and you have accepted analyticsUp to 2 years (Google's default)

Two separate consents, because they are for different things. The demo notice covers the demo session cookie, which the demo needs in order to work at all. The analytics notice covers measurement, which the product does not need. They are asked separately so that trying the demo never requires accepting analytics.

Consent on the demo surface. Before we set the demo session cookie we ask you to accept a notice. Public share links do not set the demo cookie.

Analytics consent. Nothing described under "Website and product analytics" in Section 3.7 is recorded, and no Google tag is loaded, until you accept the analytics notice. Before you decide, and if you decline, Google Consent Mode remains set to deny storage. While no decision has been made we hold the campaign parameters from your arrival address in memory only, so that clicking through to a second page does not lose them — nothing is written to your device unless you accept. If you decline, we discard them and delete the visitor identifier.

To change your mind later, clear deepcell.analytics_consent from your browser storage and we will ask again.

Disabling necessary cookies may break sign-in, language settings, or other functions. You can inspect, restrict, or delete cookies and clear browser storage in your browser settings.

If we introduce advertising or cross-site marketing technologies, we will disclose them here and obtain consent where the law requires it.


7. Sharing and service providers#

We share information only in the circumstances below.

7.1 At your direction#

For example: inviting team members, sharing a file or link, connecting DeepCell to a third-party agent or MCP client, or using a third-party AI, search, research, or integration feature.

7.2 Service providers (sub-processors)#

We engage service providers to operate DeepCell. We describe them here by function rather than by name: the specific providers we use change with our features, our architecture, the regions we serve, and the deployment a customer has chosen, and a list of names would be out of date faster than this document is revised.

FunctionData involved
Cloud infrastructure, hosting, databases, object storage, and backupsAll hosted data
AI model inference for the agent and related featuresPrompts, file fragments, model inputs and outputs
Web search and researchSearch queries derived from your request
Agent run tracing and error monitoringPrompts, file fragments, model inputs and outputs, run state
Transactional and opt-in marketing emailEmail address, display name
Third-party sign-inEmail address, name, avatar, account identifier
Website and product analytics, where enabled and consented toPages viewed, calls to action clicked, getting-started steps reached, campaign parameters, a random visitor identifier, and a one-way hash standing in for the account reference
Document conversion for /to-excel and /to-pptxThe contents of the file being exported

Exports leave the application. When you export to Excel or PowerPoint, the contents of the file being exported are sent to a document-conversion service for rendering and recalculation. That service processes the file to produce the export and does not retain it.

The current list, on request. We maintain an up-to-date register of our sub-processors, including their identities and processing regions. Write to hello@deepcell.net and we will provide it. Enterprise customers may receive it, and notice of changes to it, under their agreement.

We require providers to process information only on our instructions, only as necessary to provide the service, and with appropriate safeguards. We give notice where a change materially affects your rights.

We may disclose information where necessary to comply with applicable law, a court order, or a lawful government request; to investigate fraud, attacks, abuse, or security incidents; to protect the rights, property, and safety of DeepCell, our users, or the public; or to establish, exercise, or defend legal claims.

7.4 Business changes#

In a merger, acquisition, financing, reorganization, bankruptcy, or asset transfer, information may transfer as part of the transaction. We will require the recipient to continue honoring this Policy or provide equivalent protection.


8. Storage and cross-border processing#

DeepCell and its service providers may process data in different countries depending on the feature, deployment, and your region.

Collaboration files are stored in data centers operated by us or our cloud infrastructure provider. Data required for model inference, web search, and run tracing is currently processed in the United States; email delivery is processed in the United States and the European Union. The register described in Section 7.2 states the current processing region for each sub-processor.

Where processing crosses borders, we:

  • limit the scope of data transferred to what the request requires;
  • enter into appropriate data-protection terms with providers, including the EU Standard Contractual Clauses where they apply;
  • apply technical and organizational safeguards;
  • provide the specific disclosure and obtain the separate consent required by laws such as China's PIPL before transferring personal information abroad; and
  • give you a channel to exercise your rights.

For on-premises or private-cloud enterprise deployments, storage region and processing are governed by the written agreement between DeepCell and the enterprise customer.


9. File contents and sensitive information#

.deepcell files may contain business conclusions, financial data, evidence, personnel information, or other sensitive material.

Do not write, upload, or share in a file:

  • personal information you have no right to process;
  • sensitive personal information without the required authorization;
  • data that would breach law, contract, confidentiality, or intellectual property rights;
  • passwords, private keys, API keys, access tokens, or other credentials; or
  • content unsuitable for processing by the models or third-party services you have selected.

If you use DeepCell on behalf of an organization, you are responsible for having the authorization needed to upload, collaborate on, and process the data.


10. Retention#

We retain personal information only as long as needed for the purposes described here, based on data type, account status, contractual requirements, security risk, and legal obligations.

The periods below describe our standard practice. Where the law that applies to you prescribes a different period, that period governs: where it requires us to keep something longer — for a tax, accounting, regulatory, or litigation-hold obligation — we keep it for as long as required and no longer, and where it requires a shorter period, we apply the shorter one. Enterprise customers' agreements may set their own retention terms, which prevail for the data they cover.

DataRetention
Account informationFor the life of the account. On deletion, removed or anonymized within 30 days, except where law requires retention
Workspace filesWhile you keep the file, the workspace, or your account
Deleted filesRemoved through normal deletion; residual copies clear from backups within 30 days
Share links and version historyWhile needed to provide sharing, audit, and version-restore
Sign-in and security logsEvent records are kept for security and audit; IP address and user agent are erased 180 days after the event
Anonymous / demo visitorsWorkspaces and their file contents deleted after 30 days of inactivity; IP address and user agent erased 90 days after the event
Website and product analytics eventsEvent records kept for up to 26 months, then deleted; IP address and user agent erased 90 days after the event
Google Analytics data, where enabledRetained by Google for the period configured on our account, up to Google's 14-month maximum for event data
SessionsRefresh credentials expire after 90 days of inactivity, and every session ends 30 days after it began
AI run tracesRetained by our agent-tracing provider for the retention period configured on our account with them, and used only to debug failed runs. Write to us for the period currently in force.
Support and correspondenceWhile needed to resolve the request and keep reasonable business records
Financial and transaction recordsAs required by applicable law

Where law requires continued retention, or deletion is temporarily infeasible, we restrict further processing of that information and keep protecting it.


11. Security#

We apply reasonable technical and organizational measures, including:

  • encryption in transit (TLS), and encryption at rest for stored files, backups, and databases as provided by our cloud infrastructure provider;
  • authentication and permission controls;
  • OAuth 2.1 with PKCE for third-party client authorization;
  • access logging and security auditing;
  • restricted internal access to production data;
  • backups and disaster recovery; and
  • a security incident response process.

No internet transmission, software, or storage system can be guaranteed absolutely secure.

If a breach, alteration, or loss occurs that may affect your rights, we will take remedial action and notify affected users and regulators where the law requires it.

If you discover a security issue, please contact hello@deepcell.net immediately.


12. Your rights#

To the extent applicable law provides, you may:

  • ask whether we process your personal information;
  • access or obtain a copy of it;
  • correct or complete inaccurate or incomplete information;
  • request deletion of your account or specific personal information;
  • restrict or object to particular processing;
  • withdraw consent you previously gave;
  • request data portability where technically feasible and legally required;
  • close your account;
  • ask us to explain how we handle personal information; and
  • complain to a competent supervisory authority.

How to exercise them. Two rights are built into the product and take effect immediately:

  • Get a copy of your datadeepcell account export returns a machine-readable JSON file with your profile, workspaces, file index, share links, API key metadata, sessions, and activity records.
  • Delete your accountdeepcell account delete permanently removes your account, workspaces, files, and credentials, and erases the identifying fields from your activity records.

If you would rather not use the command line, email us and we will carry out either request for you.

For anything else, email hello@deepcell.net. To protect your account we may ask you to verify your identity, and we may decline a request we cannot reasonably verify as yours.

We respond within the period applicable law requires; where no period is prescribed, we aim to respond within 30 days. Where a request is complex, or where you have made several, we may extend that period so far as applicable law permits, and will tell you if we do. If we cannot fulfil a request in whole or in part — for example where it would reveal another person's information, prejudice an investigation, or conflict with a legal obligation — we will explain why.

Withdrawing consent does not affect processing carried out before the withdrawal.


13. Teams and enterprise customers#

When you use DeepCell through an organization, team, or enterprise account:

  • an administrator may manage your account, permissions, workspaces, and files;
  • the organization may set its own rules for data access, retention, and deletion;
  • the organization may be the controller of the relevant personal information, with DeepCell acting on its instructions under contract; and
  • after you leave the organization, you may lose access to files and data it controls.

Data handling for on-premises deployments, private cloud, industry templates, integration support, and other custom features is governed by the applicable contract and data processing agreement.


DeepCell may include or connect to third-party services, such as AI models and agent platforms, MCP clients, Microsoft Excel, Git hosts, search and data sources, and third-party sign-in. These parties handle information under their own privacy policies; review their terms before use.

When you authorize a connection, we transmit only what completing that connection requires. You can revoke authorization from DeepCell or from the third-party service.


15. Children#

DeepCell is built for workplace, business, and professional use and is not directed at children.

Minors should use the service with the guidance and consent of a parent or guardian. We do not knowingly process a minor's personal information where the law requires guardian consent and that consent has not been validly obtained.

If you believe a minor has provided us personal information without proper authorization, contact hello@deepcell.net and we will delete it, restrict processing, or obtain guardian consent as the law requires.


16. Changes to this Policy#

We may update this Policy as features, architecture, service providers, or legal requirements change.

Updated versions are published on this page with a new update and effective date. We keep every earlier version, and will provide the text in force on any given date on request. For material changes we will give more prominent notice through the website, product interface, an account notification, or email, at least 14 days before the change takes effect.

Where a change legally requires fresh consent, we will obtain it before the change takes effect. If you disagree with a change, you may stop using the affected feature and request deletion of your account or personal information.


17. Governing law#

This Policy is governed by the laws of Singapore. Where mandatory provisions of your local law apply, those provisions apply to the extent of their mandate.


18. Contact us#

For any question, complaint, or request regarding this Policy, our handling of personal information, security, or your rights:

  • Company: DEEPCELL AI PTE. LTD.
  • Data protection contact, who also acts as our Data Protection Officer where applicable law requires one to be designated: hello@deepcell.net
  • Email: hello@deepcell.net

Website: beta.deepcell.net