Draft. To be reviewed by a lawyer before launch.
Privacy Policy
Last updated September 24, 2026
1. Data controller
Planting Software, organization number 938 374 422, Skjønefjellveien 8C, 4517 Mandal, Norway, is the data controller for personal data processed in Zavelle AI. Privacy questions can be sent to contact@zavelle.app.
2. What we process and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address and account ID | Login and running your account | Contract, Art. 6(1)(b) |
| Subscription, invoices and payment status | Providing your subscription and meeting accounting obligations | Contract and legal obligation (Norwegian Bookkeeping Act), Art. 6(1)(b) and (c) |
| An anonymized fingerprint of your payment card (from Stripe, not the card number) | Preventing the same card from getting multiple trials, and fraud prevention | Legitimate interest, Art. 6(1)(f) |
| Usage: time, model, amount and cost per request | Quotas, billing, abuse prevention and cost control | Contract and legitimate interest, Art. 6(1)(b) and (f) |
| Content you submit (text, images and audio) and generated output | Producing the response you ask for | Contract, Art. 6(1)(b) |
| Chat history | Letting you continue and revisit earlier conversations | Contract, Art. 6(1)(b) |
| Code tasks: your instructions, the agent’s steps and the files it creates | Running the task and letting you download the result | Contract, Art. 6(1)(b) |
| Generated images and videos | Stored so you can view and download them | Contract, Art. 6(1)(b) |
| Referral code (affiliate) and commissions | Calculating and paying out commissions | Contract with the affiliate and legitimate interest, Art. 6(1)(b) and (f) |
We do not store your card number; payments are handled entirely by Stripe. We do not use your content to train AI models, and we do not sell personal data.
3. Who we share data with
We use the following providers (data processors) to run the Service. Each receives only the data needed for its task.
| Provider | Role | Location |
|---|---|---|
| Supabase | Database, login and storage of generated files | EU (Ireland) |
| Vercel | Website hosting | USA/EU |
| Stripe | Payments and billing | EU/USA |
| Anthropic | Text generation (Claude) and Zavelle Code sandboxes, including files created by Code tasks | USA |
| OpenAI | Image generation and real-time voice | USA |
| Video generation (Veo) | USA |
AI providers process the content you submit in order to generate a response. Under their API terms they do not use it to train their models, but they may retain it for a limited period to detect abuse.
4. Transfers outside the EEA
Some providers process data in the USA. Such transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses (SCCs).
5. How long we keep data
- Account data: for as long as you have an account; deleted within 30 days of your request.
- Chat history: until you delete the conversation or your account.
- Code tasks and their files: until you delete your account.
- Generated images and videos: until you delete them or your account.
- Usage data: up to 24 months, for billing and abuse prevention.
- Invoices and accounting records: 5 years, as required by Norwegian bookkeeping law.
- Card fingerprints for trials: up to 24 months.
6. Cookies
- Essential: login cookies from Supabase that keep you signed in. These do not require consent.
- Referral: if you arrive through an affiliate link, the referral code is stored in a cookie for 60 days so the affiliate can earn a commission.
- We do not use cookies for advertising or cross-site tracking.
7. Your rights
Under the GDPR you have the right to:
- access the data we hold about you;
- have inaccurate data corrected;
- have your data deleted, except what we must keep by law;
- receive your data in a machine-readable format (data portability);
- object to processing based on legitimate interest;
- lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local authority.
Email contact@zavelle.app and we will respond within 30 days.
8. Security
All traffic is encrypted (HTTPS). Database access is restricted with row-level security so you can only see your own data. Secret keys are only used on the server.
9. Changes
We will notify you by email of material changes to this policy. See also our Terms of Service.
See also the Terms and Privacy Policy.