ErudAite, Inc. (“we”, “our”, or “us”) collects, uses, and discloses personal information (the “Personal Information”) in the course of providing our translation diagnostic service “CATER v2” (the “Service(s)”). This Privacy Policy (this “Policy”) explains how we process the Personal Information and protects the privacy of data subjects residing outside Japan in accordance with the laws and regulations applicable to such processing (the “Applicable Laws”, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) where applicable).

For data subjects residing in Japan, the CATER Privacy Policy (Japanese) applies.

The Service is provided as part of the ErudAite product family. When you sign in, authentication is handled by the ErudAite account that is shared with ErudAite Stand By Me (“SBM”). The SBM Privacy Policy applies in conjunction with this Policy.

1. Processing of Personal Information

(1) Categories of Personal Information We Collect

We collect the following categories of Personal Information, lawfully and transparently, to the extent necessary to provide the Service:

  • ErudAite (SBM) account information: name, email address, user ID, authentication tokens, and plan information. These are obtained through the ErudAite Account Service (id.erudaite.ai) shared with SBM.
  • Input data: the source text, translation candidate, optional Translation Brief, and Reference materials you submit for diagnostic evaluation, including text extracted from uploaded files (PDF, DOCX, plain text, etc.).
  • Service-usage data: IP address, browser type, OS, access logs, sampling mode used, input character counts, and number of evaluations per month.
  • Billing data: when you make an on-demand purchase of an Advanced or Ultimate evaluation, payment-method and billing-address information are processed by Stripe, Inc. through the ErudAite Account Service. The Service itself does not store your card number.
  • Strictly necessary cookies required to maintain authenticated sessions and protect billing round-trips.

Even when you use the Basic (quick) mode as a guest without signing in, we still process the input data and a minimal set of service-usage data described above.

(2) Purposes of Processing

Personal Information is processed within the scope of our legitimate business purposes and only to the extent necessary to achieve the following purposes:

  • To provide the translation diagnostic service, including its web interface, API endpoints, and reports;
  • To transmit your input text (which may contain Personal Information about yourself or third parties) to large language model (“LLM”) providers we contract with, solely for the purpose of generating diagnostic output, improving service quality, and addressing technical issues;
  • To preserve reproducibility by storing stage-level outputs in a deterministic cache keyed by a hash of the input (see “5. Deterministic Cache and Data Retention” below);
  • To enforce plan-based monthly quotas and to record on-demand purchases;
  • To handle inquiries, complaints and other support requests;
  • To compile non-personally identifiable usage statistics (e.g. inference time, error rate per model) for the purpose of improving the Service;
  • To respond to obligations under Applicable Laws;
  • To respond to lawful requests from governmental authorities or investigative agencies.

(3) Disclosure to Third Parties and Cross-border Transfer

Because the Service is a translation diagnostic, the input text you submit is necessarily transmitted to third-party LLM providers via the Vercel AI Gateway operated by Vercel Inc. These providers may operate servers located outside Japan (primarily in the United States), and include without limitation:

  • OpenAI, L.L.C. (United States)
  • Anthropic PBC (United States)
  • Google LLC (United States)
  • Other providers we may select from time to time.

We use commercially reasonable contractual and configuration measures to ensure that LLM providers do not use your input data as training data for their underlying models.

Card-payment data for on-demand purchases is transmitted to Stripe, Inc. (United States) through the ErudAite Account Service. Stripe’s privacy policy applies to such data.

We use Vercel Inc. for hosting, Google LLC (Firebase) for authentication, and Upstash, Inc. for the Redis-based deterministic cache. These processors handle Personal Information only within the scope set out in this Policy and under our supervision.

Where the data protection laws of the recipient’s jurisdiction do not provide the same standard of protection as those of your jurisdiction, we will examine the eligibility of the recipient and confirm that appropriate security measures are in place.

(4) Procedures for Disclosure, Correction, etc.

Where permitted under the Applicable Laws, you may request disclosure, correction, addition, deletion, restriction of processing, suspension of use, suspension of provision to third parties, or data portability, of your Personal Information by contacting us via the channels in “4. To Contact Us” below. Where you signed up via SBM, account closure must be performed via SBM; closing your SBM account will simultaneously sign you out of CATER.

You may withdraw your consent for us to collect, use or disclose your Personal Information at any time, without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent may, however, prevent us from providing some or all of the Service.

(5) Filing a Complaint

You may have the right to lodge a complaint with your local data protection authority or with a court of law under the Applicable Laws if your data protection rights are violated.

(6) Cookies

We use only strictly necessary cookies for session management, authentication, and protection of billing round-trips. We do not use tracking, analytics, or advertising cookies.

(7) Automated Decision-Making

We do not use your Personal Information for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. Diagnostic scores produced by the Service are intended as decision support and not as a substitute for human judgement.

(8) Children

The Service is intended for individuals aged 13 or older. Account creation and age verification are handled by SBM (https://sbm.erudaite.ai/signup?from=cater), and the SBM Terms and Privacy Policy govern those procedures. Under the GDPR, where a user is below the age threshold defined by the applicable EU Member State, processing based on consent shall be lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility.

If we learn that we have collected Personal Information from a child below the relevant threshold without the necessary parental consent, we will take steps to delete that information promptly. Parents or guardians may contact us using the channels in “4. To Contact Us” below.

2. Security Measures

We have established a management system and implemented appropriate organisational, human, physical, and technical security measures to protect Personal Information from unauthorized access, loss, destruction, falsification, leakage, etc.

3. Reports, Deterministic Cache, and Data Retention

For academic reproducibility and to reduce the cost of processing identical inputs, the Service caches the output of each pipeline stage in a deterministic cache, keyed by a hash of the input text and configuration parameters.

  • Cache keys are computed from input text, model identifier, and orchestrator version. The cache key and cache value contain no authentication-derived identifiers (no user ID, no email address, no plan).
  • As a consequence, two users submitting identical input share the same cache entry. This is both the reproducibility guarantee (“the same input always yields the same output”) and a structural safeguard against leaking user identity into evaluations.
  • Cache entries are retained on managed Upstash Redis for up to 30 days and then automatically expire.
  • The diagnostic report itself is not stored on the Service’s servers. Reports are persisted only in your browser (localStorage) and can be cleared from your browser settings.
  • Account information and usage statistics are retained according to the SBM-shared retention policy described in the SBM Privacy Policy.

4. To Contact Us

Inquiries regarding our processing of Personal Information are welcomed at the following channels:

ErudAite, Inc., Privacy Team

5. Changes to this Policy

We may update this Policy from time to time as part of our ongoing review of how Personal Information is managed, protected, and processed. Material changes will be announced on the Service or our corporate website. The updated Policy becomes effective when published on the Service.

Last updated: May 12, 2026