Legal
Privacy Policy
Effective 3 September 2026 · Last updated 3 September 2026
This Privacy Policy explains how [COMPANY LEGAL NAME] (“we”, “us”) collects, uses, and shares personal data when you use Qwythos (the “Service”).
1. Controller
Controller: [COMPANY LEGAL NAME], [REGISTERED ADDRESS, CITY, COUNTRY], [COMPANY REGISTRATION / CUI]. Privacy contact: privacy@qwythos.ai. Data Protection contact: dpo@qwythos.ai.
2. Data we collect
- Account data: email, password hashes / auth identifiers, profile fields you provide.
- Billing data: processed by Stripe (we receive limited billing status, customer IDs, invoices — not full card numbers).
- Usage data: token usage, request metadata, model selection, timestamps, approximate IP, device/browser info, error logs.
- Content data: prompts, messages, and related chat/API payloads you submit, and generated outputs stored where the product persists them.
- Support communications: emails and tickets you send us.
- Cookies / local storage: see Cookie Policy (session, preferences, local chat history on device where applicable).
3. Purposes and legal bases (GDPR)
- Provide the Service and accounts — contract performance.
- Billing, quotas, fraud prevention — contract and legitimate interests.
- Security, abuse detection, debugging — legitimate interests.
- Legal compliance — legal obligation.
- Product analytics and improvement (aggregated/de-identified where feasible) — legitimate interests; consent where required.
- Marketing emails (if any) — consent or soft opt-in where allowed; unsubscribe anytime.
4. AI processing notice
Inputs you send to chat/API are transmitted to our inference infrastructure (including third-party GPU hosts) to generate Outputs. Do not submit secrets, special-category data, or data you are not allowed to process unless you have a lawful basis and appropriate agreements. Operators with access to infrastructure may in rare cases see operational logs; we apply least-privilege controls.
5. Sharing
We share personal data with:
- Infrastructure providers (e.g. Vercel hosting, Supabase auth/DB).
- Payment processor (Stripe).
- GPU / inference hosts under contract.
- Professional advisers and authorities when legally required.
We do not sell personal data.
6. International transfers
Data may be processed in the EU/EEA and other countries where our providers operate. Where GDPR applies, we use appropriate safeguards (e.g. SCCs) for restricted transfers.
7. Retention
Account data: while the account is active and for a reasonable period afterward for legal/accounting claims. Usage/billing records: as required by tax and commercial law. Chat content: per product configuration (client-side local history and/or server retention if enabled). Logs: typically short operational windows unless needed for security investigations.
8. Security
We use industry-standard measures (encryption in transit, access controls, secret management). No method is 100% secure.
9. Your rights
Where GDPR/UK GDPR or similar laws apply, you may request access, rectification, erasure, restriction, portability, and objection, and withdraw consent. Contact privacy@qwythos.ai. You may lodge a complaint with your local supervisory authority.
10. Children
The Service is not directed to children under 18. We do not knowingly collect their data.
11. Changes
We may update this Policy by posting a new version with an updated date. Material changes may be notified by email or in-product notice.
12. Contact
privacy@qwythos.ai · [COMPANY LEGAL NAME] · [REGISTERED ADDRESS, CITY, COUNTRY]