At Conclave AI we take data privacy seriously. This policy explains what data we collect, why we collect it, how long we keep it and how you can exercise your rights over it. We comply with the EU General Data Protection Regulation (GDPR) and the Spanish Data Protection Act (LOPDGDD).
1. Data controller
The data controller is Ivan Antonety (persona fisica), tax ID {NIF_PENDIENTE}, address {DIRECCION_PENDIENTE}, reachable at ivan@antonety.com. If you have any question about how we process your data, write to that address.
2. What data we collect
We collect only the minimum data needed for the service to work: your email address (to create your account and send you magic sign-in links), an automatically generated unique user identifier, the queries you submit to the platform and the reports we generate from them, and basic technical data such as approximate country and device type derived from your IP address at connection time.
If you sign in with Google via the OAuth flow, we receive your email address and your Google public name. We do not access any other data from your Google account.
If you set a password, it is stored encrypted (hashed) in our database. We never have access to your password in plain text.
If you purchase a subscription or a credit pack, we store an internal identifier issued by our payment provider (Stripe) that lets us link your account to your billing history. We never store your card data or payment method details.
3. What we use your data for
We use your data to authenticate you and keep your session active, run the queries you request and deliver the resulting reports, manage your credit balance and subscription if any, process payments and issue invoices through our payment provider, and send you essential service communications (security notices, terms changes, incidents, payment receipts). We do not use your data for advertising, we do not sell it to third parties and we do not perform automated profiling with legal effects on you.
4. Legal basis
The main legal basis is contract performance (GDPR article 6.1.b): we need to process your data to deliver the service you have signed up for. For essential service communications and billing, the basis is our legitimate interest and compliance with legal obligations (articles 6.1.f and 6.1.c). For any non-essential communication, we would request your prior explicit consent (article 6.1.a).
5. Who we share your data with
Your data is stored on infrastructure provided by technology vendors acting as data processors under our instructions:
- Supabase (database and authentication, hosted in the European Union).
- Vercel (application hosting).
- Anthropic (processing of your queries through their AI API). Your queries are sent to Anthropic so that their models can generate the reports; see their privacy policy at anthropic.com for details on how they handle API data in transit.
- Stripe Payments Europe Ltd (payment processor). When you purchase a subscription or a credit pack, your card and payment method data are entered and processed directly on Stripe's infrastructure; we never receive nor store them. Stripe returns to us only identifiers (customer_id, subscription_id) and non-sensitive payment metadata.
We do not sell your data to third parties under any circumstances.
6. How long we keep your data
We keep your account and queries while the account is active. If you request account deletion, we erase your personal data within a maximum of 30 days, except for data we are legally required to keep: in particular, billing records and transaction-related data are retained for the period required by Spanish tax law (currently 6 years for accounting records, article 30 of the Spanish Commercial Code).
7. Your rights
You have the right to access your data, rectify it if inaccurate, erase it, object to its processing, request restriction of processing and data portability in a structured format. You can exercise any of these rights by writing to ivan@antonety.com. We will respond within a maximum of 30 days.
If you believe the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es).
8. Cookies
We use exclusively technical cookies needed for the service to work: session cookies to keep you authenticated and a language preference cookie. We do not use advertising, tracking or third-party analytics cookies. For this reason, we do not need to request granular consent per cookie category; the notice we show is informational only.
9. Changes to this policy
We may update this policy to reflect changes in the service or applicable law. The last-updated date appears at the top of this document. If changes are substantial, we will notify you by email before they come into effect.