Privacy Policy
Last updated: July 3, 2026 · Effective date: July 2, 2026
1. Who we are
ANSA mind AB, a Swedish company, operates Quelo — an AI-powered LinkedIn content tool that automatically generates post drafts from your work activity (GitHub commits, Stripe milestones, and other connected sources) and presents them for your review and approval.
For privacy questions, contact us at hello@quelo.ai.
Data controller: ANSA mind AB, Sweden.
2. What data we collect
- Account data — your name and email address, collected at registration to authenticate you and identify your workspace.
- Tone profile data — your answers to the tone calibration wizard (7 questions on writing style, formality, humor, and preferred language), plus any writing samples or example posts you upload. Injected into every generation prompt.
- Knowledge base data — company name, industry, product name and description, target customer, team members and roles, brand values, and any phrases you want Quelo to never use. Also vector embeddings of brand voice documents, product docs, and previously published posts you upload.
- GitHub activity — when you connect GitHub via OAuth, we store push events, pull request merges, release tags, and closed issues from authorized repositories: commit hash, branch name, repository name, commit message, and timestamp. The commit hash is used as a deduplication key.
- Stripe webhook data — when you connect Stripe, we store webhook events signaling new paying customers and MRR milestones: the Stripe event ID, event type, and numeric milestone values. We never store full payment card information — that's handled entirely by Stripe.
- Other connector event data — Shopify, Notion, Linear, Product Hunt, Supabase, Forge, or custom webhooks. We store the event payload sufficient to generate a post; specific fields depend on the integration.
- Generated post data — every post draft, its source event, your full edit history, the editing mode used (save / AI Polish / re-generate), image recommendations, and final status. Published posts are also stored as vector embeddings for duplicate detection.
- API keys (BYOK) — your own AI provider keys (e.g. OpenAI, Anthropic, Mistral), stored encrypted at rest and used only to fulfill your generation requests.
- Usage data — feature usage patterns, page views, and error logs, used to improve Quelo. Not linked to individual posts or content.
- Technical data — IP address, browser type, and session data, stored in server logs and discarded after 90 days.
3. How we use your data
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account authentication and service communications | Contract (Art. 6(1)(b)) |
| Tone profile | Generate LinkedIn post drafts that sound like you | Contract (Art. 6(1)(b)) |
| Knowledge base | Ground AI generation in your real context | Contract (Art. 6(1)(b)) |
| GitHub activity | Generate post drafts from your shipped work | Contract (Art. 6(1)(b)) |
| Stripe webhook events | Generate post drafts from growth milestones | Contract (Art. 6(1)(b)) |
| Other connector events | Generate post drafts from your results | Contract (Art. 6(1)(b)) |
| Generated posts + embeddings | Duplicate detection (semantic similarity check) | Contract (Art. 6(1)(b)) |
| Lead trigger data | Capture buying-intent signals for your Forge campaigns | Contract (Art. 6(1)(b)) |
| BYOK API keys | Fulfill AI generation requests using your own model | Contract (Art. 6(1)(b)) |
| Payment data (via Stripe) | Process your subscription | Contract (Art. 6(1)(b)) |
| Usage patterns | Improve the Quelo product | Legitimate interest (Art. 6(1)(f)) |
| Server logs | Security, fraud prevention, debugging | Legitimate interest (Art. 6(1)(f)) |
| Financial transaction records | Swedish bookkeeping compliance | Legal obligation (Art. 6(1)(c)) |
4. Data we share — third-party services
We share data with the following third-party services in order to provide Quelo:
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase Inc. (US vendor; database hosted in EU — eu-west-1, Ireland) | Database, authentication, vector storage | supabase.com/privacy |
| Google LLC (USA) | AI post generation (Gemini 2.5 Flash) | policies.google.com/privacy |
| Stripe Inc. (USA) | Payment processing and subscription management | stripe.com/privacy |
| Vercel Inc. (USA) | Frontend hosting | vercel.com/legal/privacy-policy |
| Railway Corp. (USA) | Backend API hosting | railway.app/legal/privacy |
| Resend Inc. (USA) | Transactional email delivery (account emails) | resend.com/privacy |
BYOK — your own API keys: when you enable Bring Your Own Key, you connect your own credentials from AI providers (e.g. OpenAI, Anthropic, Mistral, Groq). We store these keys encrypted but do not control how those third parties process data — their privacy policies apply to your use of their services.
GitHub, Stripe, Shopify, Notion, Linear, Product Hunt, Supabase, Forge: when you connect these integrations, data flows between their systems and Quelo under your authorization via OAuth. Each provider's own privacy policy governs how they handle data on their end.
We do not sell personal data. We do not share data with advertising networks.
5. Data retention
| Data type | Retention period |
|---|---|
| Account data (email, name) | Until account deletion + 30 days |
| Tone profile | Until account deletion + 30 days |
| Knowledge base data | Until account deletion + 30 days |
| Connector event store | 24 months, then aggregated or deleted |
| Generated post drafts | Until account deletion + 30 days |
| Published post history (for duplicate detection) | Until account deletion + 30 days |
| Lead trigger data | Until account deletion + 30 days |
| BYOK API keys | Until you remove them from settings + 7 days |
| Payment records | 7 years (Swedish bookkeeping law, Bokföringslagen) |
| Support emails | 2 years |
| Server logs | 90 days |
You can delete your account and all associated data at any time from Settings → Account.
6. Your rights (GDPR)
Under GDPR, you have the right to:
- Access your personal data (Art. 15) — request a copy of all data we hold about you
- Rectification of inaccurate data (Art. 16) — correct errors in your account or knowledge base
- Erasure (“right to be forgotten”) (Art. 17) — request deletion of your data
- Restriction of processing (Art. 18) — limit how we use your data
- Data portability (Art. 20) — receive your data in a machine-readable format (JSON/CSV)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email hello@quelo.ai. Response time: within 30 days.
You also have the right to lodge a complaint with the Swedish Data Protection Authority: Integritetsskyddsmyndigheten (IMY) — imy.se | imy@imy.se
8. Security
We protect your data using:
- Row-Level Security (RLS) at the database level — your workspace data is strictly isolated from all other workspaces. No Quelo user can access another workspace's data.
- Encryption at rest — all data is stored encrypted via Supabase/PostgreSQL (AES-256)
- Encrypted API key storage — BYOK keys and OAuth tokens are encrypted before storing
- HTTPS / TLS 1.2+ for all data in transit between your browser, the Quelo backend, and third-party services
- JWT-based authentication with short-lived tokens managed by Supabase Auth
- Content hash deduplication —
social_postsstores a SHA-256 content hash to prevent duplicate storage
9. Children
Quelo is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us at hello@quelo.ai and we will delete the account.
10. Changes to this policy
If we make material changes to this Privacy Policy, we will notify you via email and/or an in-app notification at least 30 days before the changes take effect. The updated date at the top of this document reflects the most recent revision.
11. Contact
Privacy questions: hello@quelo.ai
Data controller: ANSA mind AB, Sweden
Supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
imy.se | imy@imy.se | +46 8 657 61 00