Legal
Privacy Policy
Last updated: August 2026
Our Privacy Commitment
Persistent Flow is built for data sovereignty. Your memory is yours—encrypted, portable, and always under your control. This policy explains how we handle your data, in plain language.
What Data We Collect
Account Data
When you create an account, we collect:
- Email address (for login and notifications)
- Name (optional, for personalization)
- Payment information (processed securely, never stored on our servers)
Memory Data
Everything you store in your Persistent Flow memory space. This is encrypted per personand we cannot read it. Only you and the services you explicitly authorize can access it.
Usage Data
We collect minimal technical logs:
- API request counts (for billing and rate limiting)
- Error logs (to improve service reliability)
- Access timestamps (for security monitoring)
We do not log the content of your requests, only metadata necessary for operations.
Website Analytics
This marketing site uses privacy-respecting analytics (no cookies, no tracking). We see aggregate page views, nothing personally identifiable.
How We Use Your Data
- To provide the service: Store your memory, process API requests, manage your account
- To communicate: Service updates, security alerts, billing notifications
- To improve: Anonymous usage patterns help us optimize performance
- To comply: We may disclose data if legally required (e.g., court orders)
We never train AI models on your data. We never sell your data. Period.
Where We Store Data
All data is stored in Sweden, EU. No data crosses EU borders. Our infrastructure is hosted in Swedish data centers with full GDPR compliance.
Who We Share Data With
Very few third parties, all GDPR-compliant:
- Email service: Transactional emails only (EU servers)
We sign data processing agreements (DPAs) with all vendors. No marketing partners, no data brokers, no third-party trackers.
Your Rights (GDPR)
As a European service, you have full GDPR rights:
- Access: Download all your data anytime (Settings → Export)
- Rectification: Update your account details in Settings
- Erasure: Delete your account and all data (Settings → Delete Account)
- Portability: Export in JSON/CSV formats for use elsewhere
- Objection: Opt out of non-essential communications
Data Retention
- Active accounts: Data retained as long as you use the service
- Deleted accounts: Permanently erased within 30 days (including backups)
- Logs: Technical logs retained for 90 days, then deleted
- Billing records: Kept for 7 years (Swedish tax law requirement)
Security Measures
We take security seriously:
- End-to-end encryption for all memory data
- TLS 1.3 for data in transit
- Regular security audits
- SOC 2 Type II certification (in progress)
- Multi-factor authentication available
Children's Privacy
Persistent Flow is not intended for users under 16. We don't knowingly collect data from children. If we discover such data, we delete it immediately.
Changes to This Policy
We may update this policy to reflect service changes or legal requirements. Material changes require 30 days notice via email. Your continued use means you accept the updated policy.
Contact & Data Protection Officer
Questions about privacy? Email our Data Protection Officer at [email protected].
You also have the right to lodge a complaint with the Swedish Data Protection Authority (IMY).
TL;DR: Your data stays in the EU, encrypted. We can't read it. You can export or delete it anytime. We don't train models on it. We don't sell it. Full GDPR compliance.
