Privacy Policy
Effective September 21, 2026
CATO is a biomedical data analysis platform that provides AI-assisted data exploration, statistical analysis, code execution, and literature review capabilities.
This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use the CATO platform and related services ("Services"). It applies to all users of CATO's standard platform. The data controller is Nyrus Corp., a Delaware corporation.
CATO is operated from the United States. We do not currently offer the Services to individuals located in the European Economic Area, the United Kingdom, or Switzerland, and this Policy is not written to meet the requirements of those jurisdictions. If you are located there, please do not create an account.
Standard CATO accounts are not intended for Protected Health Information or other identifiable consumer health, genetic, biometric, or patient-level data.
This Privacy Policy does not apply where Nyrus acts as a data processor on behalf of enterprise customers under a separate written agreement, for example where your organization has contracted with Nyrus for an institutional deployment of CATO. In those cases, the enterprise customer is the data controller, and you should review their policies for information about how they handle your personal data.
This Privacy Policy also describes your privacy rights. More information about your rights, and how to exercise them, is set out in Section 5 ("Rights and Choices").
Collection of Personal Data
We collect the following categories of personal data:
Personal data you provide to us directly
- Identity and Contact Data: We collect your name and email address when you create a CATO account. We may also collect or generate indirect identifiers (e.g., internal user IDs).
- Payment Information: If you purchase access to paid features, we collect payment information through our payment processor. Nyrus does not store full payment credentials on its servers.
- Inputs and Outputs: Your messages and the responses and analysis results they generate. Input, Output, and User Content have the meanings given in Section 6 of the Terms of Service. If you include personal data in your Input, it will be processed as part of the conversation and may appear in Output.
- Uploaded Datasets: Files you upload for analysis, including their contents, filenames, and structural metadata (column names, row counts, data types).
- Literature Search Data: Search queries you submit through Literature Intelligence, which are transmitted to external academic databases. This category also includes literature collections you create, annotations you add to papers, saved watch alert queries, and papers you send to Chat via the literature-to-chat bridge.
- Memories: A small, user-controlled index of durable context, such as preferences, standing instructions, project definitions, constraints, and decisions. Automatically created memories must be grounded in a user message. Generated scientific findings are not automatically promoted to memory. Each memory records its scope and source so you can review, edit, pin, or delete it. When automatic memory is enabled, CATO reviews changed conversations in a daily batch. The batch contains human-readable conversation excerpts and existing memory text, but excludes uploaded files, figures, binary artifacts, recognized credentials, and sandbox storage access.
- Feedback and Communications: If you submit feedback or communicate with us, we collect the contents of those messages.
- Service and Agent Trajectories: We record prompts, responses, tool calls and results, generated code, citations, reviewer results, execution metadata, safety signals, provider-returned reasoning content where available, and User Content surfaced in those records. Uploading a file does not, by itself, place the full raw file in a trajectory. File excerpts, selected rows, summaries, tool results, generated outputs, and other content surfaced to the agent may be recorded.
Personal data we receive automatically
When you use the Services, we receive certain technical data automatically, including device type, browser information, IP address, and usage information such as dates and times of access.
Cookies and similar technologies
CATO uses a small number of cookies and browser storage entries, all of them to run the Services rather than to track you. A session cookie keeps you signed in. If you choose to trust a device during two-factor authentication, a cookie remembers that choice; this option is not available to members of an enterprise organization. Nyrus administrators may carry a cookie that lets them test the Services as a different plan. Browser storage holds interface preferences such as column widths, panel state, and the tab you last used. We do not use advertising cookies, and we do not currently run third-party analytics on the Services. If that changes, we will update this Policy and, where the law requires it, ask for your consent first. You can clear cookies and browser storage in your browser settings; doing so signs you out and resets your preferences.
How We Use Your Data
We use your personal data for the following purposes:
- To provide, maintain, and improve the CATO platform and its features
- To process your Inputs and generate Outputs using AI models
- To execute analysis code in sandboxed environments on your behalf
- To execute literature search queries against external academic databases and APIs on your behalf
- To perform AI-powered evidence extraction, citation network analysis, and document generation from retrieved literature
- To create and administer your account
- To extract and store conversational memories to personalize your experience
- To generate conversation titles and other organizational metadata
- To communicate with you about the Services
- To prevent fraud, abuse, and violations of our Usage Policy
- To investigate and resolve disputes or security issues
- To debug and repair errors
- To enforce our Terms of Service and Usage Policy
- To reproduce failures and evaluate the scientific accuracy, reliability, and safety of CATO
- To curate evaluation and training data and improve or train CATO models and agent systems
- To retrieve and process full-text content from open-access research papers for literature analysis
- To process data through periodically updated AI models to improve service quality
Sharing you control
If you join a lab, the conversations, files, and outputs in projects assigned to that lab are visible to the other members of the lab and to its owner and admins. If you create a share link for a conversation or figure, anyone with the link can view that content until you revoke the link. Projects you keep outside a lab, and content you do not share, are visible only to you and to Nyrus for the purposes described in this Policy.
Lab and organization administrators
A lab's owner and admins can see the conversations, files, and outputs in projects assigned to the lab, manage its membership and seats, and delete lab projects. They cannot see projects you keep outside the lab. Where your organization has an enterprise agreement with Nyrus, it may also receive account, usage, and billing information about its members and may ask us to suspend or remove a member's access. If you joined through your organization, its administrators may be told that you hold an account. Nyrus personnel access your data only to operate the Services, resolve a support request you raise, investigate abuse or a security incident, or as required by law.
Other disclosures
We may disclose personal data to a buyer or successor in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, including during due diligence for such a transaction. The successor will be bound by this Policy for the data it receives, or will tell you otherwise.
We may also disclose personal data to courts, law enforcement, regulators, or other third parties when we believe in good faith that the law or legal process requires it. We may do the same to enforce our Terms of Service or Usage Policy, to detect or prevent fraud, abuse, or a security threat, or to protect the rights, property, or safety of Nyrus, our users, or the public. Where the law allows, we will tell you before disclosing your data in response to a legal request.
Legal Bases for Processing
Where applicable law requires a legal basis for processing personal data, the following table describes the basis we rely on for each purpose:
| Purpose | Data types | Legal basis |
|---|---|---|
| Provide and maintain the Services | Identity, Inputs & Outputs, datasets, technical data | Contract |
| Process Inputs and generate Outputs via AI models | Inputs & Outputs, dataset metadata | Contract |
| Execute analysis code in sandboxed environments | Generated code, dataset contents | Contract |
| Extract and store conversational memories | Conversation excerpts | Legitimate interest; consent controls via Memory page |
| Create and administer your account | Identity, payment information | Contract |
| Communicate with you about the Services | Identity, communication data | Contract; legitimate interest |
| Prevent fraud, abuse, and policy violations | Identity, Inputs & Outputs, technical data | Legitimate interest; legal obligation |
| Debug and repair errors | Technical data, Inputs & Outputs | Legitimate interest |
| Evaluate, secure, and improve CATO | Agent trajectories, Inputs & Outputs, tool results, execution metadata, feedback | Legitimate interests in safety, reliability, misuse prevention, and service improvement; consent where required |
| Execute literature searches against external databases | Search queries, literature metadata, collections | Contract |
| Enforce Terms of Service and Usage Policy | Identity, Inputs & Outputs, technical data | Contract; legitimate interest |
Data Storage, Retention, and Security
Where your data lives
Uploaded files, project artifacts, and each project's durable working filesystem are stored with our cloud storage provider. Account, conversation, project, memory, and literature records live in CATO's application database, hosted with our application hosting provider alongside caches, workflow state, and service logs. Encrypted backups and the error-monitoring and payment systems described below also hold copies of some data.
Your project's sandbox
When the agent works on a project, its filesystem is attached to an isolated sandbox. The sandbox receives no cloud-storage credentials or application secrets, cannot reach other projects' filesystems, and is blocked from internal cloud networks and metadata services. Files stay in the project filesystem until you delete them or the project. Sandboxes may reach an approved list of public destinations over HTTPS, such as package repositories and scientific databases, when an analysis, package installation, or tool needs it; data your code sends to one of them is subject to that destination's terms.
Agent trajectories
Trajectories are recorded as described in Section 1. Uploading a file does not copy its full contents into a trajectory, although excerpts, tool results, and outputs surfaced to the agent may be recorded. Operational trajectories and training-approved trajectories are kept in separate stores: production systems can create operational records but cannot read them back, and training systems can read only records that a separate cleaning and approval step has copied into the training-approved store. Accounts on plans that are exempt from model-improvement capture do not produce full-content trajectories at all.
Retention
You can delete conversations, memories, datasets, files, and projects in the application, and you can delete your account from Settings. Deletion removes the primary application copy; security, diagnostic, trajectory, and backup copies may persist for the periods below.
- Account and billing records: for the life of the account, then removed on account deletion except where payment-processor or tax rules require longer retention.
- Conversations, memories, datasets, project files, outputs, literature collections, annotations, and watch queries: until you delete them or delete your account.
- Literature full text: retrieved on demand; a paper is stored with the project only when you or CATO saves it to the workspace, and stays until you delete it or the project.
- Agent trajectories: an event-level record of each turn's tool calls is stored with the conversation and deleted with it. Full-content trajectories, where created, are retained as reasonably necessary to operate and restore workflows, debug and evaluate CATO, prevent misuse, investigate security events, resolve disputes, enforce our policies, and improve our offerings.
- Error-monitoring events: for the retention period configured with our error-monitoring provider, then discarded.
- Technical logs and backups: on a rolling basis for operational recovery, after which they are overwritten or expire.
When you delete content or your account, the primary copy is removed at once, and copies held in caches, diagnostic systems, and security systems are removed within 30 days. Backups expire on their rolling schedule, and we do not restore deleted content from a backup except to recover the Services after an outage. Deleting your account removes your projects, conversations, memories, files, and literature records on the same timeline. We keep a record of the deletion request itself so that we can show it was honored.
Records connected to abuse, security, fraud, disputes, or legal obligations may be retained longer when reasonably necessary for those purposes. Operational trajectory records are written to a store that cannot be edited or deleted record by record, so a trajectory that has already been recorded is not removed on request. You can email contact@nyrus.ai to ask that identifiable records no longer be selected for future model-improvement datasets. A request applies once processed and does not undo completed processing; de-identified or aggregated data may be retained where the law permits, and changes already incorporated into trained model weights cannot generally be reversed.
Memory
CATO can save durable context you state in a conversation and recall a relevant subset later. Global memories can apply across projects; project memories stay within their project. Automatic saving, recall, and cross-project recall each have their own control, and every memory can be viewed, edited, pinned, or permanently deleted from Settings > Memory. Memory is not treated as scientific evidence, and current instructions override older memories.
Service providers
The hosted Services rely on contracted providers for AI inference and memory maintenance, application hosting and databases, file storage and sandbox infrastructure, error monitoring, payment processing, and email delivery. We limit each provider to the data its function needs, and we do not authorize AI inference or retrieval providers to train their models on your User Content. The function, data categories, retention posture, and contract for each provider are kept current on our Subprocessors and Service Providers page, which we update before a new provider receives production user data.
Literature, clinical trial, patent, protein, pathway, chemical, and other public research databases are external data sources rather than contracted providers. CATO sends them only the search terms, identifiers, and filters a lookup needs, and their own terms and logging practices apply. AI models and infrastructure are upgraded periodically, so your data may be processed by updated model versions.
Security
We protect your data with encryption in transit and at rest, sandboxed code execution that receives no storage credentials and cannot reach internal cloud networks, separate identities for user files and for each trajectory store, signed access to the API, and two-factor authentication, which you can enable on your account and which is required for members of an organization with an enterprise agreement. Section 7 of the Data Processing notice lists the measures in place. No security system is impenetrable, and we cannot guarantee absolute security.
Rights and Choices
Depending on where you live and the laws that apply, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Deletion: Request deletion of your personal data. You can also delete conversations, datasets, memories, and projects directly from the platform.
- Correction: Request correction of inaccurate personal data.
- Data portability: Request your data in a portable format.
- Objection: Object to processing of your personal data on grounds of legitimate interest.
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time.
- Memory controls: View, edit, delete, or disable automatic memory extraction from the Memory page.
To exercise your rights, contact us at contact@nyrus.ai. We will confirm receipt and respond to verified requests within 45 days, or sooner where applicable law requires it. We do not discriminate against you for exercising these rights. Nyrus does not sell your personal data, share it for cross-context behavioral advertising, or use it for targeted advertising.
Accuracy of AI output about people. AI Output is generated by a model, not retrieved from a record, and it can be inaccurate about a real person, including an author, a study participant, or you. If AI Output about you is wrong, you can ask us to correct or remove it; we will consider the request based on applicable law and what the models can technically do, and we may address it by deleting the conversation rather than by changing the model.
United States state privacy laws. The categories of personal data we collect are listed in Section 1, our purposes in Section 2, and the people we share with in Sections 2 and 4. We do not sell personal data, do not share it for targeted advertising, and do not process sensitive personal data to infer characteristics about you. Because we do not sell or share personal data, there is nothing for a browser opt-out signal to opt you out of. Residents of California and other states with privacy laws may exercise their rights to know, delete, correct, and not be discriminated against by contacting contact@nyrus.ai. We verify requests against your account, and an authorized agent must show written permission from you. You may appeal a decision by replying to our response.
See our Data Processing notice for details about trajectory use, deletion, model-improvement datasets, and trained model weights.
Protected Health Information
If your data originates from health records, you are responsible for ensuring it has been de-identified in accordance with HIPAA Safe Harbor or Expert Determination methods before uploading it to CATO.
Enterprise Deployments
Enterprise deployments may include additional data processing agreements, Business Associate Agreements (BAAs) with CATO and relevant third-party providers, exemption from model-improvement data capture, and custom infrastructure configurations agreed in writing.
Children
CATO is not directed toward, and we do not knowingly collect information from, children under the age of 18. If you become aware that a child has provided personal data to us, please contact us and we will investigate and, if appropriate, delete the data.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the platform and update the effective date at the top of this page. Continued use of the Services after changes constitutes acceptance.
Contact
If you have questions about this Privacy Policy, or wish to exercise your privacy rights, contact us at contact@nyrus.ai.