Privacy Policy

Last updated: July 3, 2026 · Effective date: July 2, 2026

1. Who we are

ANSA mind AB, a Swedish company, operates Quelo — an AI-powered LinkedIn content tool that automatically generates post drafts from your work activity (GitHub commits, Stripe milestones, and other connected sources) and presents them for your review and approval.

For privacy questions, contact us at hello@quelo.ai.
Data controller: ANSA mind AB, Sweden.

2. What data we collect

  • Account data — your name and email address, collected at registration to authenticate you and identify your workspace.
  • Tone profile data — your answers to the tone calibration wizard (7 questions on writing style, formality, humor, and preferred language), plus any writing samples or example posts you upload. Injected into every generation prompt.
  • Knowledge base data — company name, industry, product name and description, target customer, team members and roles, brand values, and any phrases you want Quelo to never use. Also vector embeddings of brand voice documents, product docs, and previously published posts you upload.
  • GitHub activity — when you connect GitHub via OAuth, we store push events, pull request merges, release tags, and closed issues from authorized repositories: commit hash, branch name, repository name, commit message, and timestamp. The commit hash is used as a deduplication key.
  • Stripe webhook data — when you connect Stripe, we store webhook events signaling new paying customers and MRR milestones: the Stripe event ID, event type, and numeric milestone values. We never store full payment card information — that's handled entirely by Stripe.
  • Other connector event data — Shopify, Notion, Linear, Product Hunt, Supabase, Forge, or custom webhooks. We store the event payload sufficient to generate a post; specific fields depend on the integration.
  • Generated post data — every post draft, its source event, your full edit history, the editing mode used (save / AI Polish / re-generate), image recommendations, and final status. Published posts are also stored as vector embeddings for duplicate detection.
  • API keys (BYOK) — your own AI provider keys (e.g. OpenAI, Anthropic, Mistral), stored encrypted at rest and used only to fulfill your generation requests.
  • Usage data — feature usage patterns, page views, and error logs, used to improve Quelo. Not linked to individual posts or content.
  • Technical data — IP address, browser type, and session data, stored in server logs and discarded after 90 days.

3. How we use your data

DataPurposeLegal basis
Email addressAccount authentication and service communicationsContract (Art. 6(1)(b))
Tone profileGenerate LinkedIn post drafts that sound like youContract (Art. 6(1)(b))
Knowledge baseGround AI generation in your real contextContract (Art. 6(1)(b))
GitHub activityGenerate post drafts from your shipped workContract (Art. 6(1)(b))
Stripe webhook eventsGenerate post drafts from growth milestonesContract (Art. 6(1)(b))
Other connector eventsGenerate post drafts from your resultsContract (Art. 6(1)(b))
Generated posts + embeddingsDuplicate detection (semantic similarity check)Contract (Art. 6(1)(b))
Lead trigger dataCapture buying-intent signals for your Forge campaignsContract (Art. 6(1)(b))
BYOK API keysFulfill AI generation requests using your own modelContract (Art. 6(1)(b))
Payment data (via Stripe)Process your subscriptionContract (Art. 6(1)(b))
Usage patternsImprove the Quelo productLegitimate interest (Art. 6(1)(f))
Server logsSecurity, fraud prevention, debuggingLegitimate interest (Art. 6(1)(f))
Financial transaction recordsSwedish bookkeeping complianceLegal obligation (Art. 6(1)(c))

4. Data we share — third-party services

We share data with the following third-party services in order to provide Quelo:

ServicePurposePrivacy policy
Supabase Inc. (US vendor; database hosted in EU — eu-west-1, Ireland)Database, authentication, vector storagesupabase.com/privacy
Google LLC (USA)AI post generation (Gemini 2.5 Flash)policies.google.com/privacy
Stripe Inc. (USA)Payment processing and subscription managementstripe.com/privacy
Vercel Inc. (USA)Frontend hostingvercel.com/legal/privacy-policy
Railway Corp. (USA)Backend API hostingrailway.app/legal/privacy
Resend Inc. (USA)Transactional email delivery (account emails)resend.com/privacy

BYOK — your own API keys: when you enable Bring Your Own Key, you connect your own credentials from AI providers (e.g. OpenAI, Anthropic, Mistral, Groq). We store these keys encrypted but do not control how those third parties process data — their privacy policies apply to your use of their services.

GitHub, Stripe, Shopify, Notion, Linear, Product Hunt, Supabase, Forge: when you connect these integrations, data flows between their systems and Quelo under your authorization via OAuth. Each provider's own privacy policy governs how they handle data on their end.

We do not sell personal data. We do not share data with advertising networks.

5. Data retention

Data typeRetention period
Account data (email, name)Until account deletion + 30 days
Tone profileUntil account deletion + 30 days
Knowledge base dataUntil account deletion + 30 days
Connector event store24 months, then aggregated or deleted
Generated post draftsUntil account deletion + 30 days
Published post history (for duplicate detection)Until account deletion + 30 days
Lead trigger dataUntil account deletion + 30 days
BYOK API keysUntil you remove them from settings + 7 days
Payment records7 years (Swedish bookkeeping law, Bokföringslagen)
Support emails2 years
Server logs90 days

You can delete your account and all associated data at any time from Settings → Account.

6. Your rights (GDPR)

Under GDPR, you have the right to:

  • Access your personal data (Art. 15) — request a copy of all data we hold about you
  • Rectification of inaccurate data (Art. 16) — correct errors in your account or knowledge base
  • Erasure (“right to be forgotten”) (Art. 17) — request deletion of your data
  • Restriction of processing (Art. 18) — limit how we use your data
  • Data portability (Art. 20) — receive your data in a machine-readable format (JSON/CSV)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email hello@quelo.ai. Response time: within 30 days.

You also have the right to lodge a complaint with the Swedish Data Protection Authority: Integritetsskyddsmyndigheten (IMY) imy.se | imy@imy.se

7. Cookies

Quelo uses the following cookies:

  • Essential cookies (no consent required) — authentication session cookie, set by Supabase Auth. httpOnly, Secure. Required to keep you logged in. Cannot be disabled without breaking the service.
  • Analytics cookies (consent required) — if Quelo uses analytics tools in future, we will request your consent before setting analytics cookies. As of this writing, no analytics cookies are in use.

You can manage cookies in your browser settings.

8. Security

We protect your data using:

  • Row-Level Security (RLS) at the database level — your workspace data is strictly isolated from all other workspaces. No Quelo user can access another workspace's data.
  • Encryption at rest — all data is stored encrypted via Supabase/PostgreSQL (AES-256)
  • Encrypted API key storage — BYOK keys and OAuth tokens are encrypted before storing
  • HTTPS / TLS 1.2+ for all data in transit between your browser, the Quelo backend, and third-party services
  • JWT-based authentication with short-lived tokens managed by Supabase Auth
  • Content hash deduplicationsocial_posts stores a SHA-256 content hash to prevent duplicate storage

9. Children

Quelo is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us at hello@quelo.ai and we will delete the account.

10. Changes to this policy

If we make material changes to this Privacy Policy, we will notify you via email and/or an in-app notification at least 30 days before the changes take effect. The updated date at the top of this document reflects the most recent revision.

11. Contact

Privacy questions: hello@quelo.ai
Data controller: ANSA mind AB, Sweden

Supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
imy.se | imy@imy.se | +46 8 657 61 00