Short version: We collect only what we need to run the service. We never sell your data. You own your files, including the copies Culacc keeps from services you connect. You can delete everything at any time.

1. Who is responsible for your data

The data controller is Andrej, an individual operating Culacc, based in Slovakia, European Union.

Contact: andrej@culacc.com

2. What data we collect

Data Why we collect it Legal basis
Email address Account login, billing emails, service notifications Contract performance
Files you upload To provide the storage service Contract performance
Content from services you connect To keep the copies you asked for — for example Notion pages, Jira issues or GitHub repositories (see section 6) Contract performance
Access tokens for connected services To read those services, and to write to them when you ask. Stored encrypted. Contract performance
App sign-ins When you sign in from Culacc’s apps and plugins, so you can see and remove those sign-ins Contract performance
Storage usage and traffic To enforce quotas and calculate billing Contract performance
Payment status To know which plan you are on Contract performance
Visits to your public links When someone opens a file you shared publicly: their IP address, browser and the page they came from — for security and to count traffic Legitimate interest
IP address / logs Security, abuse prevention, debugging Legitimate interest

We do not collect: card numbers (handled by Stripe), crypto wallet details (handled by NOWPayments), browsing behavior, or any analytics beyond basic server logs.

3. How we use your data

We will never sell your data, share it with advertisers, use it to train AI, or use it for any purpose not listed above.

4. Third-party services

We use a small number of trusted third parties to operate Culacc:

Service Purpose Data shared
Clerk Authentication (login/signup) Email address
Stripe Card payment processing Email, billing status
NOWPayments Cryptocurrency payment processing Payment amount only
iDrive E2 File storage infrastructure (EU regions) Your files, including copies from services you connect
Resend Transactional email delivery Email address, email content
Hetzner Server hosting (EU) Culacc’s servers and database: account records, and data on its way to storage
Google (Drive) Optional Drive sync, if you connect it Files from folders you select

All third parties are either EU-based or covered by appropriate data transfer mechanisms (Standard Contractual Clauses).

The services you connect yourself — such as Notion, GitHub or Jira — are not on this list: you use them under their own terms, and Culacc exchanges data with them only as you instruct. Section 6 explains how.

5. Google account data (Drive sync)

If you choose to connect a Google account, Culacc syncs files from Google Drive folders you explicitly select into your Culacc storage. We request the narrowest access possible: the Google Drive drive.file scope, which grants access only to the specific folders and files you choose through Google's own file picker — never your entire Drive.

What we access

How we use it

Limited Use commitment: Culacc's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google data for advertising, do not sell it, do not allow humans to read it, and do not use it for any purpose other than providing and improving the sync features you have enabled.

Deleting your Google data

You can disconnect your Google account at any time from Settings. You can also permanently delete all data Culacc obtained from your Google account — synced files, stored copies, and related records — using the "Delete synced data" button in Settings, or by emailing andrej@culacc.com. Disconnecting and deletion do not affect the original files in your Google account.

6. Services you connect

Culacc can connect to other services you use — for example Notion, GitHub, GitLab, Bitbucket, Jira, Confluence, WordPress and Shopify — to keep copies of your content in your Culacc account. You connect each one through that service’s own sign-in and permission screen, where you choose what Culacc may access.

What Culacc receives

How it is used

Only to keep the copies in your account and, when you ask, to send a file back to a connected service. It is never sold, never used for advertising, never used to train AI, and never analysed for anything else.

Other people’s data in your copies

These copies can contain personal data about other people — names of colleagues in a Jira issue or comment, the users of your WordPress site, the people in your documents. For that data, you decide what is copied, and Culacc processes it on your behalf, as your processor under GDPR. If your organisation needs a data processing agreement, email andrej@culacc.com.

Disconnecting and deleting

You can disconnect a service at any time, in Culacc’s settings or in the service itself; Culacc then stops accessing it. Copies already made stay in your account until you delete them. Disconnecting doesn’t change your content in the connected service.

7. Your files

Your files are stored on iDrive E2 (S3-compatible) infrastructure. Files are encrypted in transit (HTTPS/TLS). We do not access, read, or analyze the contents of your files except when technically required to provide a feature you have enabled (for example, generating a download link, copying a file you selected from Google Drive, or keeping a copy from a service you connected).

8. Data retention

9. Your rights under GDPR

As an EU resident you have the following rights regarding your personal data:

Right of access
Request a copy of all data we hold about you
Right to erasure
Request deletion of your account and all associated data
Right to rectification
Correct any inaccurate personal data we hold
Right to portability
Export all your files and data at any time
Right to object
Object to processing based on legitimate interest
Right to restrict
Request we limit processing of your data

To exercise any of these rights, email andrej@culacc.com. We will respond within 30 days as required by GDPR. You also have the right to lodge a complaint with the Slovak data protection authority (dataprotection.gov.sk).

If you appear in content that a Culacc customer stored or backed up, please contact that customer first — they decide what is kept. We will help them respond.

10. Cookies

Culacc uses only technically necessary cookies: for authentication (provided by Clerk), and — when you connect Notion from Notion’s marketplace — a short-lived cookie that lets the same browser finish the connection after you sign in, deleted within an hour. We do not use tracking cookies, advertising cookies, or analytics cookies. No cookie consent banner is required as we only use strictly necessary cookies.

11. Security

We take reasonable technical and organisational measures to protect your data, including HTTPS encryption for all connections, encrypted file storage, access tokens for connected services encrypted with AES-256-GCM, access controls, and regular security reviews. No system is perfectly secure — if we become aware of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR.

12. Children

Culacc is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it immediately.

13. Changes to this policy

We may update this privacy policy from time to time. We will notify you by email at least 14 days before significant changes take effect. The current version is always available at culacc.com/privacy.

14. Contact

For any privacy-related questions or to exercise your rights:
Email: andrej@culacc.com
Response time: Within 5 business days (GDPR requests within 30 days)

This policy was last reviewed in October 2026 and is compliant with GDPR Regulation (EU) 2016/679.