Legal

Policies governing use of the CATO platform

Privacy Policy

Effective July 21, 2026

CATO is a biomedical data analysis platform that provides AI-assisted data exploration, statistical analysis, code execution, and literature review capabilities.

This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use the CATO platform and related services ("Services"). It applies to all users of CATO's standard platform.

Standard CATO accounts are currently offered only to users in the United States. They are not intended for Protected Health Information or other identifiable consumer health, genetic, biometric, or patient-level data.

This Privacy Policy does not apply where CATO acts as a data processor on behalf of enterprise customers using CATO's commercial deployments - for example, where your organization has provisioned a self-hosted or VPC-deployed instance of CATO. In those cases, the enterprise customer is the data controller, and you should review their policies for information about how they handle your personal data.

This Privacy Policy also describes your privacy rights. More information about your rights, and how to exercise them, is set out in Section 4 ("Rights and Choices").

1

Collection of Personal Data

We collect the following categories of personal data:

Personal data you provide to us directly

  • Identity and Contact Data: We collect your name and email address when you create a CATO account. We may also collect or generate indirect identifiers (e.g., internal user IDs).
  • Payment Information: If you purchase access to paid features, we collect payment information through our payment processor. CATO does not store full payment credentials on its servers.
  • Inputs and Outputs:When you interact with CATO, your messages ("Inputs") generate AI responses and analysis results ("Outputs"). If you include personal data in your Inputs, that information will be processed as part of the conversation and may appear in Outputs.
  • Uploaded Datasets: Files you upload for analysis, including their contents, filenames, and structural metadata (column names, row counts, data types).
  • Literature Search Data: Search queries you submit through Literature Intelligence, which are transmitted to external academic databases (PubMed, PMC, Europe PMC, Unpaywall, CORE, Crossref, OpenAlex, DataCite, Semantic Scholar, arXiv, bioRxiv, medRxiv, ChemRxiv, SSRN, Research Square, OSF, Zenodo, HAL, ClinicalTrials.gov, and patent databases). Also includes literature collections you create, annotations you add to papers, saved watch alert queries, and papers you send to Chat via the literature-to-chat bridge.
  • Memories: A small, user-controlled index of durable context, such as preferences, standing instructions, project definitions, constraints, and decisions. Automatically created memories must be grounded in a user message. Generated scientific findings are not automatically promoted to memory. Each memory records its scope and source so you can review, edit, pin, or delete it. When automatic memory is enabled, CATO reviews changed conversations in a daily batch. The batch contains human-readable conversation excerpts and existing memory text, but excludes uploaded files, figures, binary artifacts, recognized credentials, and sandbox storage access.
  • Feedback and Communications: If you submit feedback or communicate with us, we collect the contents of those messages.
  • Service and Agent Trajectories: We record prompts, responses, tool calls and results, generated code, citations, reviewer results, execution metadata, safety signals, provider-returned reasoning content where available, and User Content surfaced in those records during and after the beta. Uploading a file does not, by itself, place the full raw file in a trajectory. File excerpts, selected rows, summaries, tool results, generated outputs, and other content surfaced to the agent may be recorded.

Personal data we receive automatically

When you use the Services, we receive certain technical data automatically, including device type, browser information, IP address, and usage information such as dates and times of access.

2

How We Use Your Data

We use your personal data for the following purposes:

  • To provide, maintain, and improve the CATO platform and its features
  • To process your Inputs and generate Outputs using AI models
  • To execute analysis code in sandboxed environments on your behalf
  • To execute literature search queries against external academic databases and APIs on your behalf
  • To perform AI-powered evidence extraction, citation network analysis, and document generation from retrieved literature
  • To create and administer your account
  • To extract and store conversational memories to personalize your experience
  • To generate conversation titles and other organizational metadata
  • To communicate with you about the Services
  • To prevent fraud, abuse, and violations of our Usage Policy
  • To investigate and resolve disputes or security issues
  • To debug and repair errors
  • To enforce our Terms of Service and Usage Policy
  • To reproduce failures and evaluate the scientific accuracy, reliability, and safety of CATO
  • To curate evaluation and training data and improve or train CATO models and agent systems during and after the beta
  • To retrieve and process full-text content from open-access research papers for literature analysis
  • To process data through periodically updated AI models to improve service quality
3

Data Storage, Retention, and Security

Storage

Google Cloud provides CATO's authoritative object storage for user files, project artifacts, operational trajectories, and training-approved trajectories. Railway hosts the application, PostgreSQL account, conversation, and project metadata, Redis cache and stream-replay data, Temporal workflow state, service logs, and a transient local trajectory delivery spool. The Railway spool is not the authoritative trajectory store. Storage may also include encrypted backups and security or error-monitoring systems as described in this Policy.

Sandbox file handling

A trusted Google Cloud controller stages only the input files needed for an analysis into a temporary sandbox workspace and retrieves validated outputs afterward. Sandbox pods do not receive cloud-storage credentials, application secrets, or mounted object storage. Staged copies are removed when the sandbox pod or session is cleaned up. Uploading a file does not automatically duplicate its full raw contents into an agent trajectory, although content surfaced through file inspection, tools, analysis, or generated outputs may be recorded there.

Trajectory storage boundaries

Operational trajectories and training-approved trajectories are stored separately. The production writer can create operational records but cannot list, read, overwrite, or delete them. A restricted cleaning and approval pipeline may read operational records and create approved copies in the training-approved store. Training systems can read only the training-approved store and cannot access the operational store directly. This separation prevents an operational record from becoming training-readable without the intervening cleaning and approval step.

Retention

Primary account and project data is retained while your account is active or as needed to provide the Services. You can delete conversations, memories, datasets, or projects in the application. Those controls remove the primary application copy but may not immediately remove security, diagnostic, trajectory, or backup copies.

Identifiable trajectories are retained as reasonably necessary to operate and restore workflows, debug and evaluate CATO, prevent misuse, investigate security events, resolve disputes, enforce our policies, and improve our offerings. Records connected to abuse, security, fraud, disputes, or legal obligations may be retained longer when reasonably necessary for those purposes.

Contact contact@nyrus.ai to request deletion of identifiable trajectory records or to request that identifiable records no longer be selected for future model-improvement datasets. A request applies prospectively once processed and does not undo completed processing. We may retain deidentified or aggregated evaluation and training data where permitted by law. Data already included in a training run that is underway, and improvements already incorporated into trained model weights, cannot generally be traced back and selectively reversed.

Memory feature

CATO can save durable context that you state in a conversation and recall only a relevant subset in later conversations. Global memories can apply across projects; project memories remain within their project. Memory is not a replacement for conversation history and is not treated as scientific evidence. Current instructions override older memories. Automatically saving new memories, recalling saved memories, and cross-project recall have separate controls. Memories are stored in CATO's application database and can be viewed, added, edited, pinned, or permanently deleted from Settings > Memory.

Infrastructure Updates

AI model infrastructure is upgraded periodically; your data may be processed by updated model versions.

Literature full-text content is retrieved on demand. A paper may be cached for an active workflow and is stored with the project when you or CATO fetches or saves it to the workspace. Project copies remain until you delete the paper or project, subject to backup and trajectory retention described above.

Third-Party Processing

The hosted Service uses the providers below. We limit each provider to the data needed for its function. We do not authorize AI providers to train their models on your User Content. Retention exceptions may apply for security, abuse prevention, legal obligations, and data that you explicitly ask a provider-backed feature to store.

ProviderFunctionData disclosedHandling
Fireworks AIStandard AI inference, daily memory maintenance, and selected scientific helper operationsPrompts, relevant conversation and tool context, human-readable conversation excerpts used for memory maintenance, and model outputsCATO uses reviewed Chat Completions paths that Fireworks documents as zero data retention by default. Daily memory maintenance uses transient Batch API datasets that CATO deletes after ingestion or terminal job handling.
AnthropicResearch model and selected literature planning, writing, and code-repair operationsPrompts, relevant conversation and tool evidence, generated code, and bounded error contextAnthropic states that commercial API data is not used for model training by default. Its standard API retention is up to 30 days unless a separate zero-data-retention agreement applies, with stated safety and legal exceptions.
RailwayApplication hosting, PostgreSQL metadata, Redis cache and stream replay, Temporal workflow state, service logs, and transient trajectory delivery spoolingAccount, conversation and project metadata, workflow and stream state, transient trajectory events, and technical service dataRetained to operate CATO and removed under CATO deletion, ephemeral-storage, backup, and Railway service processes. Railway is not the authoritative object store for user files or trajectories.
Google CloudAuthoritative user-file, project-artifact, operational-trajectory, and training-approved-trajectory object storage; isolated sandbox execution; and container infrastructureUploaded files, project artifacts, operational and approved trajectory records, analysis inputs, generated code, execution results, and technical metadataStored or processed under separate Nyrus-controlled identities, access boundaries, lifecycle rules, encryption, and deletion processes. Temporary sandbox copies are credential-free and removed during sandbox cleanup.
SentryError and performance monitoringStack traces, performance data, technical request route, subscription tier, and an opaque account IDCATO disables request bodies, session replay, contact details, project IDs, application logs, and default PII collection. Events follow the configured Sentry retention period.
StripeSubscriptions, payments, fraud prevention, and metered billingContact and billing data, Stripe customer ID, subscription state, and numeric usage quantitiesStripe retains transaction and compliance records under its legal, fraud, and financial obligations. CATO does not send prompts, datasets, or model outputs to Stripe.
ResendTransactional email and support notificationsRecipient email address, subject, message content, and delivery metadataEmail content is processed and stored under Resend's service and data processing terms. Do not include confidential research data in a support ticket.
Research data servicesLiterature, trial, patent, protein, pathway, chemical, and biomedical database lookupSearch terms, identifiers, filters, and ordinary network metadataQueries are subject to each public service's terms and logging practices. CATO does not send full conversations unless required for an explicitly selected provider-backed operation.

Security

We implement appropriate technical and organizational measures to protect your data, including encrypted credential storage, sandboxed code execution, controls that block sandbox access to internal cloud networks and metadata services, credential-free temporary sandbox file staging, separate user-file, operational-trajectory, and training-approved storage identities, and authentication-gated API access. Sandboxes may access public HTTP and HTTPS destinations when an analysis, package installation, or tool requires it. Data sent by code to a public destination is subject to that destination's terms. No security system is impenetrable, and we cannot guarantee absolute security.

4

Rights and Choices

Depending on where you live and the laws that apply, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Deletion: Request deletion of your personal data. You can also delete conversations, datasets, memories, and projects directly from the platform.
  • Correction: Request correction of inaccurate personal data.
  • Data portability: Request your data in a portable format.
  • Objection: Object to processing of your personal data on grounds of legitimate interest.
  • Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time.
  • Memory controls: View, edit, delete, or disable automatic memory extraction from the Memory page.

To exercise your rights, contact us at contact@nyrus.ai. We will respond to verified requests within the timeframes required by applicable law. CATO does not sell your personal data or use it for targeted advertising.

See our Data Processing notice for details about trajectory use, deletion, model-improvement datasets, and trained model weights.

5

Protected Health Information

Standard CATO accounts are not intended for processing Protected Health Information (PHI) as defined under HIPAA or other identifiable consumer health, genetic, biometric, or patient-level data. Users must not upload that data or enter it into conversations unless operating under an approved enterprise deployment with appropriate agreements and safeguards in place. See our Usage Policy for details.

If your data originates from health records, you are responsible for ensuring it has been de-identified in accordance with HIPAA Safe Harbor or Expert Determination methods before uploading it to CATO.

6

Enterprise Deployments

Enterprise deployments may include additional data processing agreements, Business Associate Agreements (BAAs) with CATO and relevant third-party providers, and custom infrastructure configurations including self-hosted and VPC deployments where data does not leave the customer's infrastructure.

7

Children

CATO is not directed towards, and we do not knowingly collect information from, children under the age of 18. If you become aware that a child has provided personal data to us, please contact us and we will investigate and, if appropriate, delete the data.

8

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the platform and update the effective date at the top of this page. Continued use of the Services after changes constitutes acceptance.

9

Contact

If you have questions about this Privacy Policy, or wish to exercise your privacy rights, contact us at contact@nyrus.ai.

10

Legal Bases for Processing

The following table describes the legal bases we rely on for processing your personal data under applicable data protection laws:

PurposeData typesLegal basis
Provide and maintain the ServicesIdentity, Inputs & Outputs, datasets, technical dataContract
Process Inputs and generate Outputs via AI modelsInputs & Outputs, dataset metadataContract
Execute analysis code in sandboxed environmentsGenerated code, dataset contentsContract
Extract and store conversational memoriesConversation excerptsLegitimate interest; consent controls via Memory page
Create and administer your accountIdentity, payment informationContract
Communicate with you about the ServicesIdentity, communication dataContract; legitimate interest
Prevent fraud, abuse, and policy violationsIdentity, Inputs & Outputs, technical dataLegitimate interest; legal obligation
Debug and repair errorsTechnical data, Inputs & OutputsLegitimate interest
Evaluate, secure, and improve CATO during and after the betaAgent trajectories, Inputs & Outputs, tool results, execution metadata, feedbackContract; legitimate interests in safety, reliability, misuse prevention, and service improvement; consent where required
Execute literature searches against external databasesSearch queries, literature metadata, collectionsContract
Enforce Terms of Service and Usage PolicyIdentity, Inputs & Outputs, technical dataContract; legitimate interest