Privacy Policy
Last updated: September 2026 · Controller: Belna, Stockholm, Sweden · hej@belna.se
1. What we collect
- Account: email + authentication tokens (Supabase Auth — password, one-time code, or Google). Your user id is derived server-side from your verified JWT — never from client input.
- Usage: prompts, model token counts and costs (for metering your API credit), gift/upgrade records.
- Memories & vault: only what you explicitly save. Secrets are encrypted at rest and masked; the model only receives references.
- Technical: minimal logs (rate limiting, errors). Secrets, tokens and keys are redacted from logs.
2. What we never do
We never sell your data, never place secret values in model context, logs or traces, and never fake app connections — Apps stays empty unless a real integration exists.
3. Legal basis & retention
Contract (to run your agent and meter credit), consent (memories, secrets you save) and legitimate interest (abuse prevention). Delete memories, secrets and chats anytime in the app; deleting your claim removes local data. Server records needed for billing are kept as required by Swedish bookkeeping law.
4. Your GDPR rights
Access, rectification, erasure, restriction, portability and objection. To exercise them, write to hej@belna.se. You may also complain to Integritetsskyddsmyndigheten (IMY), Sweden's data protection authority.
5. Sub-processors
Supabase (auth + database), AI model providers (to answer prompts — they receive your prompt plus masked references, never vault values).
6. Contact
hej@belna.se · See Terms, Security, Cookies.