Privacy Policy

Last updated: 7 August 2026

This Privacy Policy explains how Rafael Luis Jacober Werlang (“Asserte”, “we”, “us”) collects, uses, and protects personal data when you use the Asserte service (the “Service”). We are the data controller. For any privacy question, contact hello@asserte.ai.

We sell confidence on high-stakes work, and privacy is core to that promise. This policy describes our actual practices.

1. What we collect

We do not sell your personal data, and we do not use your task, documents, or audit to train AI models.

3. Retention

4. AI subprocessors and how your input is processed

To generate your audit, your task (and any documents) are sent to a panel of frontier AI models through OpenRouter, an AI model routing provider. OpenRouter engages the model providers that serve each request and is bound to handle your data under the limits we set on every call. The panel is built from models by leading AI labs and changes as we track and run whichever frontier models are strongest at any time.

Those limits are enforced on every request: it may reach only zero-data-retention endpoints — endpoints that do not store your input or output and do not train on it — and never a provider that would collect your data for its own use. Which provider serves a given request is chosen by OpenRouter at request time within those limits, so we record that choice as routing metadata — the provider’s name and nothing of your content — and can tell you which providers processed a specific audit.

Other processors we use:

Authentication is our own passwordless email-code sign-in — no third-party auth provider receives your identity data.

A current list of our processors — including the model providers reached through OpenRouter — is available on request at hello@asserte.ai.

5. Where your data is processed

We host in the European Union (Hetzner). Some AI and service subprocessors may process data outside the EU; where they do, we rely on appropriate safeguards such as Standard Contractual Clauses.

6. Your rights

Subject to applicable law (including the GDPR), you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing. To exercise these rights, contact hello@asserte.ai. You may also lodge a complaint with your local data protection authority.

7. Cookies and local storage

We use two strictly necessary cookies: a session cookie to maintain your session, and — once you sign in — a persistent sign-in cookie so your devices stay signed in (revoked on sign-out). When you dismiss our cookie notice, a single flag in your browser’s local storage remembers only that choice — it never leaves your device. We do not use advertising or cross-site tracking cookies.

8. Security

We host in the EU on hardened infrastructure, encrypt data in transit, and minimise what we store. Your input and your report never enter long-term storage at all — they live only in memory for your session and are delivered, not retained. Where you set a password, your report PDF is sealed with AES-256 — a password we never store, cannot reset, and cannot recover.

9. Changes

We may update this policy; the “Last updated” date reflects the latest version. Material changes will be notified where appropriate.

10. Contact

Rafael Luis Jacober Werlang, Viale Leopoldo Muzii, 77 — Piano 3, 65123 Pescara (PE), Italy. Email: hello@asserte.ai.