Privacy policy
Privacy, by design.
Last updated 22 September 2026. This policy explains how Cercle handles personal data across cercle.house, the application and verification process, member emails and the Cercle mobile app.
Cercle has no public member directory. Your identity is not revealed to another member merely because we consider an introduction. Names, employers, profile links and photos are shared only in line with the approval choices explained below.
1. The information we collect
Application and verification information
- your name, work email, role, employer, home city and languages;
- your professional profile link and the application answers you provide;
- email-verification, application-review and membership status;
- where you choose LinkedIn verification, your LinkedIn member identifier, name and email address returned by LinkedIn;
- the limited application-decision and consent records needed to operate the private network; Cercle does not label a professional role or work affiliation as checked unless it has actually completed and recorded that specific check.
Optional identity-verified badge
If you choose the optional Identity verified check, we collect one fresh camera photo of you holding your photo ID for that check. We only collect this evidence after you give a separate, explicit consent to process it. Consent to process the evidence and consent to display the green Identity verified badge are separate choices.
Member and introduction information
- your professional profile, languages, interests, expertise, meeting preferences and optional profile photo;
- trip destination, dates, rough availability and your purpose for a particular meeting window;
- when you use Open Now, the precise location or venue you select, its coordinates, your chosen distance and the short availability window;
- if you use the optional voice-entry feature, the short recording and transcript needed to turn what you say into a trip and meeting-availability draft;
- proposed introductions, fit signals, mutual approval choices and meeting status;
- messages, venue preferences, calendar actions, blocks, reports and support requests;
- private feedback about a meeting or venue.
Technical information
We may process device, browser, IP address, authentication, security and service-log information when you use the website or app. If you enable notifications, we process a device push token and notification-delivery status so that service messages can reach that device. We do not ask for age or gender and do not use either to make introductions.
Membership purchase information
Apple or Google processes membership purchases made in the Cercle app. Stripe processes existing web subscriptions. Cercle receives and stores the subscription product, billing provider, customer or transaction identifier, verification status and expiry needed to activate and maintain your membership. Stripe also processes the billing contact, address, payment method, tax information and invoice details you submit in Checkout or its customer portal. Raw payment-card details are not provided to or stored by Cercle.
2. How and why we use information
We use personal data to:
- receive, verify and review applications;
- where you separately opt in, have an authorised Cercle reviewer compare the optional fresh camera photo of you holding a photo ID and record whether the optional Identity verified badge can be shown;
- create and protect member accounts;
- identify potentially useful introductions based on timing, location, role, experience, interests and the purpose selected for that meeting window;
- request mutual approval before identity details are revealed;
- coordinate meeting preferences, venues and service communications;
- verify purchases, restore membership access and respond to subscription renewals, cancellations, billing issues and refunds;
- calculate private proximity for an Open Now introduction without showing another member your precise location;
- prevent misuse, investigate reports and protect members and the service;
- improve reliability and understand how Cercle is used;
- meet legal, accounting and regulatory obligations.
3. Our legal bases
Under the GDPR, we rely on:
- steps before and performance of a contract, to review your application and provide membership services;
- legitimate interests, to operate a trusted professional network, consider relevant introductions, secure the service and improve it, balanced against your rights;
- consent, where we ask you to connect LinkedIn, share optional information or approve identity disclosure for an introduction. You may withdraw consent at any time;
- separate explicit consent, to process the optional fresh camera photo of you holding a photo ID, and a separate consent to display the green Identity verified badge. Neither choice affects whether we review, approve or maintain your Cercle membership;
- legal obligations, where records must be retained or disclosed by law.
4. How introductions and approval work
Cercle may use relevance scoring to help identify a potential introduction. The score considers information such as overlapping availability in the same city, complementary or comparable professional perspectives, shared context and the purpose selected for that meeting window.
A score is a recommendation signal, not a decision with legal or similarly significant effects. Applications are reviewed by a person, and members remain in control of whether to proceed. Your identity is revealed to a proposed member only after the required approval step. Cercle does not permit public browsing or unsolicited member messages.
4a. Optional Identity verified badge
The check is voluntary and is reviewed by a person. It compares the single fresh camera photo of you holding a photo ID that you choose to submit; it is not a background check. Cercle does not use AI, create or retain face templates, or make automated decisions from this evidence. The result cannot decide your application, membership, access or standing in Cercle.
If you separately opt in to display it, the badge may appear next to your member name as a green Identity verified indicator. It means only that this optional review was completed. It is not a safety, character, suitability or endorsement guarantee about any member.
5. When we share information
We disclose personal data only where needed:
- to another Cercle member, after the relevant mutual approval. Before approval, only limited, non-identifying professional context may be shown;
- to service providers that host the website and app, store data, authenticate users, send transactional emails, process subscription payments or support operations, including Supabase, Vercel, Resend and Stripe;
- to OpenAI, only when you choose the voice-entry feature: the short recording is sent for transcription, and the resulting transcript is sent to structure it as a trip draft for your review. OpenAI processes this content through its API services and may retain relevant API inputs or outputs in abuse-monitoring logs for up to 30 days by default, or longer where required by law or needed to protect its services or others;
- to LinkedIn, only when you choose to start LinkedIn verification. LinkedIn then processes information under its own privacy terms;
- to authorised Cercle reviewers, only to complete the optional Identity verified check you request. We do not show the raw identity-check photo to other members;
- to a venue or booking provider, only when you choose to open its website, telephone service or booking page. Cercle does not make the reservation for you;
- to professional advisers, authorities or other parties where required by law, needed to establish or defend legal claims, or necessary to protect people and the service;
- in a business reorganisation, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal data or use it for third-party advertising.
6. International transfers
Some service providers may process data outside Belgium or the European Economic Area. Where this happens, we use a lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards, and apply additional protections where appropriate.
7. How long we keep information
We retain personal data only for as long as it is needed for the purposes above:
- incomplete or declined applications are generally kept for up to 12 months;
- member profiles, trip information and account records are kept while membership is active and generally for up to 12 months afterwards;
- precise Open Now location labels and coordinates are erased when you remove the window or when it expires; only a limited operational record may remain;
- meeting feedback, safety reports and related communications may be kept for up to three years after the relevant matter closes, where needed to protect members and handle disputes;
- security logs are generally kept for up to 12 months;
- voice recordings and transcripts used to create a trip draft are not saved to your Cercle profile or database. They are processed by OpenAI as described above and may be retained by that provider under the conditions described there;
- a submitted optional raw identity-check photo remains in restricted access until a human reviewer completes the review, you withdraw consent, or you delete your account. We do not apply an automatic 24-hour deletion timer to an unreviewed submission;
- if a human reviewer approves the optional check, the raw identity-check photo remains restricted for exactly 24 hours after approval and is then permanently deleted. If a human reviewer rejects the photo, it is permanently deleted before we show a neutral result that lets you resubmit;
- after an optional identity-check decision, we retain only a minimum audit record for 12 months after the decision. This record supports the review trail and your consent or withdrawal choices; it does not include the raw identity-check photo;
- records required for legal, tax, accounting or claims purposes are kept for the applicable statutory period.
We may delete information sooner when it is no longer needed, or retain limited information for longer where a legal obligation or an active dispute requires it.
8. Cookies and local storage
Cercle uses essential browser storage for secure sign-in, application sessions, fraud prevention and basic service operation. These technologies are necessary for the service you request. We do not currently use advertising cookies or cross-site behavioural advertising. If optional analytics or marketing cookies are introduced, we will update this policy and request consent where required.
9. Device permissions, voice and calendars
If you use Open Now, you can type and select a location or choose to grant foreground location permission. Cercle uses the resulting coordinates only to calculate distance during that short window. The precise location is not shown to another member and is erased when the window is removed or expires. You can use the rest of Cercle without granting location permission.
If you choose voice entry, Cercle asks for microphone permission only while you record your availability. Your short recording is sent securely to OpenAI for transcription, and the resulting transcript is sent to OpenAI's Responses API to structure it into an editable draft. Cercle asks the Responses API not to store the structured response for later retrieval. This setting does not prevent the processing needed to provide the feature or OpenAI's abuse-monitoring retention described above. Cercle does not save the recording or transcript to your profile or database, and nothing is added as a trip until you review and approve the draft.
If you choose “Use dates from my calendar” or “Find it in my calendar”, Cercle asks for calendar permission and reads event titles, locations, notes and start and end times for the next four months to suggest possible trip cities and dates. This scan and parsing happen on your device. Only the city and dates from a suggestion that you select and then confirm as a trip are sent to Cercle and saved; unconfirmed calendar content is not sent.
If you choose “Add to calendar”, Cercle opens your selected phone, Google or Outlook calendar with meeting details for your review. Using that action alone does not make Cercle read your existing calendar. Other optional device permissions are requested only when the related feature needs them.
10. Security
We use access controls, private data-storage rules, encrypted connections, authentication safeguards and restricted staff access designed for a private membership service. No system can be guaranteed completely secure, but we review safeguards as Cercle develops and respond to suspected incidents.
11. Your rights
Depending on the circumstances, you may ask us to:
- provide access to your personal data;
- correct inaccurate or incomplete information;
- delete information;
- restrict or object to processing;
- provide certain information in a portable format;
- withdraw consent without affecting earlier lawful processing.
Contact info@cercle.house. Access and portability requests can be started from the app under Profile. To delete an account, use the app under Profile or the web account-deletion request form if you no longer have the app. We may need to verify your identity for a web request and will normally respond within one month, subject to the extensions and exceptions allowed by law. You also have the right to complain to the Belgian Data Protection Authority or the competent authority where you live or work.
You can withdraw either optional identity-check consent at any time in the app or by contacting us. Withdrawing consent to process evidence cancels a review that has not been decided; withdrawing display consent hides the badge. If you withdraw the review consent or delete your account, we permanently delete any raw identity-check photo that remains. Withdrawal does not affect processing that was lawful before withdrawal or the limited 12-month audit record described above.
12. Age requirement
Cercle is intended for professionals aged 18 and over. We do not knowingly accept applications from children.
13. Changes to this policy
We may update this policy as Cercle develops or legal requirements change. The latest version will remain available on this page. We will communicate material changes directly where appropriate.
Questions or privacy requests
Use the account-deletion form or email info@cercle.house.
Cercle