<- Back to CB1
Privacy Policy
Effective Date: April 12, 2026
1. Introduction
CB1 Intelligence ("CB1," "we," "us," or "our") operates the cb1.ai platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
We collect information you provide directly:
- Account Information: Name, email address, and password when you create an account.
- Organization Information: Company name, state, license number for business accounts.
- Experience Data: Effect ratings, consumption preferences, and product feedback you voluntarily log.
- Scan Data: Products you scan via QR codes, including timestamps and location (dispensary only, not GPS).
We collect information automatically:
- Usage Data: Pages visited, features used, and general interaction patterns.
- Device Data: Browser type, operating system, and IP address for security and rate limiting.
3. How We Use Your Information
- To provide personalized product recommendations based on your effect preferences.
- To compute your Personal Receptor Profile from voluntarily logged effect data.
- To operate loyalty and rewards programs you opt into.
- To generate anonymized, aggregated analytics for brands and retailers (no individual identification).
- To improve our services and compound intelligence models.
- To communicate service updates and, with your consent, new product alerts.
4. Data Sharing
We do not sell your personal information. We share data only as follows:
- Anonymized Analytics: Brands and retailers receive aggregated, anonymized insights (e.g., "60% of scanners prefer relaxation effects"). Individual users are never identified.
- Blockchain Anchoring: Product intelligence data (not personal data) is anchored on public blockchains for provenance verification.
- Service Providers: We use Anthropic (AI), Render (hosting), Stripe (payments), and Sentry (error monitoring). These providers process data under contract and cannot use it for their own purposes.
- Legal Requirements: We may disclose information if required by law or to protect safety.
5. Consumer Notifications
With your consent, you may receive notifications about new products, match alerts, and restock reminders. You can manage these preferences in your profile settings at any time. All notifications can be disabled individually.
6. Data Retention
We retain your personal data for as long as your account is active. Effect logs and scan history are retained to maintain your Receptor Profile. You may delete your account at any time (see Section 8).
7. Data Security
We protect your data using:
- Argon2id password hashing (OWASP-recommended configuration).
- JWT authentication with refresh token rotation and reuse detection.
- HTTPS encryption in transit via Cloudflare.
- PostgreSQL with connection pooling and query parameterization (no SQL injection).
- Rate limiting and CORS restrictions on all API endpoints.
8. Your Rights (CCPA/GDPR)
You have the right to:
- Access: Request a copy of your personal data via your profile page.
- Delete: Permanently delete your account and all associated data via the "Delete My Account" button in your profile. This removes your receptor profile, effect logs, scan history, loyalty points, and notification preferences.
- Opt Out: Disable any or all notification categories in your notification preferences.
- Portability: Export your data in standard formats (coming soon).
To exercise these rights, use the in-app controls or contact us at privacy@cb1.ai.
9. Children's Privacy
CB1 is not intended for use by individuals under the age of 21. We do not knowingly collect information from anyone under 21. If we become aware that we have collected data from someone under 21, we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date.
11. Contact
For questions about this Privacy Policy or our data practices, contact us at:
privacy@cb1.ai
CB1 INTELLIGENCE -- PRIVACY POLICY -- EFFECTIVE APRIL 12, 2026