This describes how Mattercite handles information when you use the hosted service at mattercite.com. It is written for a small early-access product, not as a substitute for a negotiated DPA.
To provide the workspace you signed up for: store your files, draft answers from those files, export questionnaires, and keep workspaces isolated from each other. We do not sell personal data. We do not use your documents or answers to train foundation models.
The application runs on Amazon Web Services in us-east-1. The public site and TLS termination in front of the app run on Cloudflare. Original uploads are stored in a private S3 bucket with encryption at rest. Extracted text and answers are stored in Postgres. Answer generation on the hosted service uses Amazon Bedrock (Nova Lite) over a knowledge base filtered to your workspace. See subprocessors.
A single HTTP-only session cookie (ddqa_session) keeps you signed in. It is marked Secure on HTTPS. We do not use advertising cookies.
We share data with the infrastructure providers listed as subprocessors, and if required by law. People you invite to a workspace can see that workspace’s content.
We keep account and workspace data while the workspace exists. Deleting a document removes the stored file, its extract, and its use in later answers. There is not yet a self-serve account-deletion control; email the operator if you need a workspace removed.
Questions about this policy: the operator of mattercite.com (account owner of this deployment).