1. Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use the platform. It is written for users in the European Economic Area, United Kingdom, United States, Canada, and Switzerland.
2. Controller and Contact
The data controller or business is the company publishing this site. Company name, registered address, and registration number are shown on the Legal Notice page. Privacy requests can be sent through the contact page.
3. Categories of Data We Collect
We collect account identifiers such as name, email, authentication identifiers, optional profile details, billing and subscription records, workspace memberships, AI prompts and outputs you submit, usage logs, consent records, support messages, device/browser data, and security logs. Payment card details are processed by Stripe and are not stored by the application.
4. Purposes and Legal Bases
We process data to create and secure accounts, provide paid and free services, manage workspaces, deliver AI features, process payments, send transactional messages, provide support, prevent abuse, maintain audit logs, and comply with legal obligations. Depending on context, the legal basis is contract performance, consent, legitimate interests, or legal obligation.
5. Cookies, Analytics, and Advertising
Necessary cookies are used for authentication, security, checkout, locale, and consent storage. Analytics, advertising, remarketing, and live-chat scripts are disabled by default and load only after the matching analytics or marketing consent is granted. You can withdraw or change consent using Cookie settings in the footer.
6. Email Marketing and Electronic Messages
Newsletter and promotional messages are sent only after a clear opt-in or another lawful basis permitted by applicable law. Messages identify the sender and include an unsubscribe mechanism. Unsubscribe requests are honored through the connected email provider.
7. Service Providers and Transfers
We use service providers such as Supabase for hosting/database/authentication, Stripe for payments, Vercel for hosting, email providers for transactional and marketing email, analytics providers when consented, and AI providers for requested AI features. Data may be processed outside your country, including the United States, Canada, and Switzerland, with appropriate contractual and technical safeguards. We also use Cloudflare Turnstile for bot protection on public forms; the data handled by this protection is described in the Cloudflare Turnstile Privacy Addendum available at https://www.cloudflare.com/application-services/products/turnstile-privacy-policy/.
8. Retention
Account data is kept while the account is active and then handled through the deletion queue. Billing and tax records are retained as required by law. Security and access logs are retained for a limited period. Consent records are retained to prove current and historical choices.
9. Your Privacy Rights
Depending on your location, you may request access, portability, correction, deletion, restriction, objection, withdrawal of consent, opt-out of sale/sharing or targeted advertising, and limitation of sensitive personal information use. Swiss users may also request information about processing, correction, deletion, or objection where applicable law allows. The application provides self-service data export and deletion flows where possible; other requests can be submitted through the contact page.
10. California and US State Privacy Notice
We do not sell personal information for money. If advertising or analytics integrations are configured in a way that constitutes sharing, targeted advertising, or cross-context behavioral advertising, users must be offered the required opt-out controls and Global Privacy Control handling before launch.
11. Canada Privacy Notice
For Canadian users, we collect, use, and disclose personal information for stated and reasonable purposes, use meaningful consent where required, allow withdrawal of non-essential consent, safeguard personal information according to sensitivity, and maintain breach-response procedures.
13. Security and Breach Response
We use access controls, row-level security, CSRF protection, rate limits, logging redaction, and secret-management controls. If a breach creates a legal notification obligation, affected users and regulators will be notified according to applicable law.
14. Changes
We may update this policy when the service, providers, markets, or legal requirements change. Material changes will be communicated through the product, email, or the website.
15. Contact
For privacy questions or requests, use the contact page and include the email address associated with your account.
12. Switzerland Privacy Notice
For Swiss users, we process personal data according to the FADP/nFADP principles of lawfulness, proportionality, transparency, purpose limitation, security, and accuracy. We inform users about the main processing purposes, recipient categories, relevant international transfers, and how to exercise their rights. If a breach is likely to create a high risk to personality or fundamental rights, required notices to the FDPIC and affected individuals will be handled under applicable law.
