Privacy
How Criton handles your data. No jargon, no tricks.
The essentials
- To talk to Crito you don't need to register. Only if you want to turn on Memory will we ask for an email to sign in.
- If you subscribe to the Leadership Score, we ask for your email, name, company and role in order to send you your result and the follow-up emails.
- By default, your conversations with Crito are not stored. If you turn on Memory (it's optional, you decide), they are stored end-to-end encrypted: the key is yours and yours alone. Neither Pablo Tovar nor anyone at Addventure can read them, with or without Memory.
- For the AI to answer, the content needed for that request is processed in plaintext by Criton's server and the AI model provider. End-to-end encryption protects persistent Memory storage; it cannot protect content while the model is actively generating a reply.
If you subscribe to the Leadership Score
When you enter your email:
- You receive your leadership profile on screen.
- You receive three automated emails over the following days (the «Score Sequence»).
- You are subscribed to CHIEF, Pablo Tovar's weekly email on leadership (in Spanish).
- You can unsubscribe at any time using the link at the foot of every email.
That data is stored in MailerLite, our email marketing provider (based in Lithuania, within the European Economic Area). We do not share it with third parties, apart from the technical processors described below.
Your conversations with Crito
Crito is a conversational assistant. Whatever you write in its chat:
- Without Memory turned on, Criton does not create a persistent conversation record in its database. The request is still processed transiently by Vercel and Anthropic in order to answer.
- With Memory turned on (see the next section), it is stored end-to-end encrypted. We have no panel where we can read users' conversations, nor could we decrypt them: we do not hold your key.
- To generate the reply, the content is sent to the AI model provider at the moment of the query. Encryption protects what is stored, not that one-off transmission needed to answer you.
- The current provider is Anthropic (Claude via its commercial API), under a data processing agreement (DPA). Anthropic does not use commercial API inputs or outputs to train its models by default. Under its standard API policy, it may retain inputs and outputs for up to 30 days, with longer exceptions for legal or misuse-prevention duties. Processing may occur outside the EU under standard contractual clauses (SCCs).
Neither Pablo Tovar nor anyone on the Addventure team has access to your conversations with Crito.
Crito's Memory (optional)
Crito can remember your conversations, your plan and your reflections between sessions, to give you continuity. It is optional and works like this:
- You turn it on yourself, from the lock in the menu. If you don't, Crito starts from scratch every time.
- End-to-end encrypted storage. When you turn Memory on, your device generates a key that never reaches our servers. Everything persisted in Memory (conversations, plan and summaries) is encrypted before storage; Supabase only receives ciphertext.
- You hold the only key. You receive a 12-word recovery code, the only thing that decrypts your memory. If you lose it, not even we can recover your data: that is precisely the guarantee.
- Using Memory in a reply. When continuity is needed, your device decrypts the relevant summary and sends it transiently with the current request. Criton and Anthropic must see that plaintext during inference; it is not persisted as readable Memory by Criton.
- You can turn it off whenever you want.
The encrypted content is stored in Supabase (servers in the European Union). Encryption and decryption for persistent storage happen on your device; transient plaintext processing for each AI reply is the separate process described above.
Technical processors
Criton relies on several technical services to work. All of them are processors in the terms of the General Data Protection Regulation (GDPR):
- Vercel — hosts the application and provides aggregated, cookie-free usage analytics.
- MailerLite — manages the emails.
- Anthropic (AI model provider) — processes each request to generate replies, under a DPA; commercial API data is not used for training by default and standard retention can be up to 30 days.
- Supabase — only if you turn on Memory, it stores your already encrypted data (servers in the EU). It cannot read its content.
Analytics, cookies and operational metadata
We measure Criton's usage in an aggregated way, without advertising or cross-site tracking cookies, to understand which sections are used and improve the product. We never record your email, your name or the content of your conversations in analytics. Vercel Analytics does not track individual users across sites.
crito_aidessential cookie. Purpose: stable anonymous usage and abuse limits. Data: a random UUID and HMAC signature, never email or conversation content. Legal basis: our legitimate interest in service security and cost control; it is strictly necessary to offer anonymous chat. Duration: one year. Recipients: Addventure, Vercel as host and Supabase for the pseudonymous counter.- Supabase session cookies (
sb-*). Used only after sign-in to keep the requested session. Legal basis: providing the Memory/account feature at your request. Duration: the session and refresh-token lifecycle configured in Supabase. Recipients: Addventure, Vercel and Supabase. - Operational metadata. Raw IP is processed transiently by hosting/security layers and converted by Criton into a non-reversible HMAC for abuse limits; those limiter rows expire after eight days. Daily pseudonymous usage counters expire after 90 days. Closed reminder metadata expires after 90 days. Active push subscriptions remain until account deletion or browser revocation. No coaching content is included.
- Product metrics. We keep daily aggregate event counts and a daily HMAC solely to deduplicate anonymous actors. The HMAC cannot be used to recover the IP or cookie identifier and is deleted after 90 days. Event names describe product actions only; no free text, profile attributes or coaching content are sent.
Your rights
Under the GDPR you can, at any time:
- Request access to the personal data we hold about you.
- Request its rectification or erasure.
- Delete your complete account from the Memory page. This removes active data from Supabase, usage and push records, requests MailerLite's GDPR forget process (up to 30 days), deletes any Stripe customer and downloads a signed receipt.
- Withdraw your consent to marketing at any time, without giving reasons.
- Lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe we are not complying.
Write to chief@pablotovar.com and we will reply.
Contact and data controller
Data controller: Pablo Tovar, El Campello (Alicante), Spain. For any privacy-related question: chief@pablotovar.com.
Criton is a product of Addventure (an executive-coaching firm), created and operated by Pablo Tovar. For data protection purposes, the data controller is Pablo Tovar as a natural person.
Addventure's institutional policy
This page specifically describes how Criton handles your data. For the institutional policy of the Addventure firm (professional coaching services), see addventure.es/politica-privacidad.
Last updated: 16 July 2026.