Legal

Privacy Policy

Last updated: August 2026

Our Privacy Commitment

Persistent Flow is built for data sovereignty. Your memory is yours—encrypted, portable, and always under your control. This policy explains how we handle your data, in plain language.

What Data We Collect

Account Data

When you create an account, we collect:

  • Email address (for login and notifications)
  • Name (optional, for personalization)
  • Payment information (processed securely, never stored on our servers)

Memory Data

Everything you store in your Persistent Flow memory space. This is encrypted per personand we cannot read it. Only you and the services you explicitly authorize can access it.

Usage Data

We collect minimal technical logs:

  • API request counts (for billing and rate limiting)
  • Error logs (to improve service reliability)
  • Access timestamps (for security monitoring)

We do not log the content of your requests, only metadata necessary for operations.

Website Analytics

This marketing site uses privacy-respecting analytics (no cookies, no tracking). We see aggregate page views, nothing personally identifiable.

How We Use Your Data

  • To provide the service: Store your memory, process API requests, manage your account
  • To communicate: Service updates, security alerts, billing notifications
  • To improve: Anonymous usage patterns help us optimize performance
  • To comply: We may disclose data if legally required (e.g., court orders)

We never train AI models on your data. We never sell your data. Period.

Where We Store Data

All data is stored in Sweden, EU. No data crosses EU borders. Our infrastructure is hosted in Swedish data centers with full GDPR compliance.

Who We Share Data With

Very few third parties, all GDPR-compliant:

  • Email service: Transactional emails only (EU servers)

We sign data processing agreements (DPAs) with all vendors. No marketing partners, no data brokers, no third-party trackers.

Your Rights (GDPR)

As a European service, you have full GDPR rights:

  • Access: Download all your data anytime (Settings → Export)
  • Rectification: Update your account details in Settings
  • Erasure: Delete your account and all data (Settings → Delete Account)
  • Portability: Export in JSON/CSV formats for use elsewhere
  • Objection: Opt out of non-essential communications

Data Retention

  • Active accounts: Data retained as long as you use the service
  • Deleted accounts: Permanently erased within 30 days (including backups)
  • Logs: Technical logs retained for 90 days, then deleted
  • Billing records: Kept for 7 years (Swedish tax law requirement)

Security Measures

We take security seriously:

  • End-to-end encryption for all memory data
  • TLS 1.3 for data in transit
  • Regular security audits
  • SOC 2 Type II certification (in progress)
  • Multi-factor authentication available

Children's Privacy

Persistent Flow is not intended for users under 16. We don't knowingly collect data from children. If we discover such data, we delete it immediately.

Changes to This Policy

We may update this policy to reflect service changes or legal requirements. Material changes require 30 days notice via email. Your continued use means you accept the updated policy.

Contact & Data Protection Officer

Questions about privacy? Email our Data Protection Officer at [email protected].

You also have the right to lodge a complaint with the Swedish Data Protection Authority (IMY).

TL;DR: Your data stays in the EU, encrypted. We can't read it. You can export or delete it anytime. We don't train models on it. We don't sell it. Full GDPR compliance.