Short version: We collect only what we need to run the service. We never sell your data. You own your files, including the copies Culacc keeps from services you connect. You can delete everything at any time.
The data controller is Andrej, an individual operating Culacc, based in Slovakia, European Union.
Contact: andrej@culacc.com
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address | Account login, billing emails, service notifications | Contract performance |
| Files you upload | To provide the storage service | Contract performance |
| Content from services you connect | To keep the copies you asked for — for example Notion pages, Jira issues or GitHub repositories (see section 6) | Contract performance |
| Access tokens for connected services | To read those services, and to write to them when you ask. Stored encrypted. | Contract performance |
| App sign-ins | When you sign in from Culacc’s apps and plugins, so you can see and remove those sign-ins | Contract performance |
| Storage usage and traffic | To enforce quotas and calculate billing | Contract performance |
| Payment status | To know which plan you are on | Contract performance |
| Visits to your public links | When someone opens a file you shared publicly: their IP address, browser and the page they came from — for security and to count traffic | Legitimate interest |
| IP address / logs | Security, abuse prevention, debugging | Legitimate interest |
We do not collect: card numbers (handled by Stripe), crypto wallet details (handled by NOWPayments), browsing behavior, or any analytics beyond basic server logs.
We will never sell your data, share it with advertisers, use it to train AI, or use it for any purpose not listed above.
We use a small number of trusted third parties to operate Culacc:
| Service | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication (login/signup) | Email address |
| Stripe | Card payment processing | Email, billing status |
| NOWPayments | Cryptocurrency payment processing | Payment amount only |
| iDrive E2 | File storage infrastructure (EU regions) | Your files, including copies from services you connect |
| Resend | Transactional email delivery | Email address, email content |
| Hetzner | Server hosting (EU) | Culacc’s servers and database: account records, and data on its way to storage |
| Google (Drive) | Optional Drive sync, if you connect it | Files from folders you select |
All third parties are either EU-based or covered by appropriate data transfer mechanisms (Standard Contractual Clauses).
The services you connect yourself — such as Notion, GitHub or Jira — are not on this list: you use them under their own terms, and Culacc exchanges data with them only as you instruct. Section 6 explains how.
If you choose to connect a Google account, Culacc syncs files from Google Drive folders you explicitly select into your Culacc storage. We request the narrowest access possible: the Google Drive drive.file scope, which grants access only to the specific folders and files you choose through Google's own file picker — never your entire Drive.
Limited Use commitment: Culacc's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google data for advertising, do not sell it, do not allow humans to read it, and do not use it for any purpose other than providing and improving the sync features you have enabled.
You can disconnect your Google account at any time from Settings. You can also permanently delete all data Culacc obtained from your Google account — synced files, stored copies, and related records — using the "Delete synced data" button in Settings, or by emailing andrej@culacc.com. Disconnecting and deletion do not affect the original files in your Google account.
Culacc can connect to other services you use — for example Notion, GitHub, GitLab, Bitbucket, Jira, Confluence, WordPress and Shopify — to keep copies of your content in your Culacc account. You connect each one through that service’s own sign-in and permission screen, where you choose what Culacc may access.
Only to keep the copies in your account and, when you ask, to send a file back to a connected service. It is never sold, never used for advertising, never used to train AI, and never analysed for anything else.
These copies can contain personal data about other people — names of colleagues in a Jira issue or comment, the users of your WordPress site, the people in your documents. For that data, you decide what is copied, and Culacc processes it on your behalf, as your processor under GDPR. If your organisation needs a data processing agreement, email andrej@culacc.com.
You can disconnect a service at any time, in Culacc’s settings or in the service itself; Culacc then stops accessing it. Copies already made stay in your account until you delete them. Disconnecting doesn’t change your content in the connected service.
Your files are stored on iDrive E2 (S3-compatible) infrastructure. Files are encrypted in transit (HTTPS/TLS). We do not access, read, or analyze the contents of your files except when technically required to provide a feature you have enabled (for example, generating a download link, copying a file you selected from Google Drive, or keeping a copy from a service you connected).
As an EU resident you have the following rights regarding your personal data:
To exercise any of these rights, email andrej@culacc.com. We will respond within 30 days as required by GDPR. You also have the right to lodge a complaint with the Slovak data protection authority (dataprotection.gov.sk).
If you appear in content that a Culacc customer stored or backed up, please contact that customer first — they decide what is kept. We will help them respond.
Culacc uses only technically necessary cookies: for authentication (provided by Clerk), and — when you connect Notion from Notion’s marketplace — a short-lived cookie that lets the same browser finish the connection after you sign in, deleted within an hour. We do not use tracking cookies, advertising cookies, or analytics cookies. No cookie consent banner is required as we only use strictly necessary cookies.
We take reasonable technical and organisational measures to protect your data, including HTTPS encryption for all connections, encrypted file storage, access tokens for connected services encrypted with AES-256-GCM, access controls, and regular security reviews. No system is perfectly secure — if we become aware of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR.
Culacc is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it immediately.
We may update this privacy policy from time to time. We will notify you by email at least 14 days before significant changes take effect. The current version is always available at culacc.com/privacy.
For any privacy-related questions or to exercise your rights:
Email: andrej@culacc.com
Response time: Within 5 business days (GDPR requests within 30 days)
This policy was last reviewed in October 2026 and is compliant with GDPR Regulation (EU) 2016/679.