Privacy Policy
Effective 18 September 2026 · Version 1.0
1. Who controls your data
The controller is the operator of the pilvory service. Privacy and data-protection requests can be sent without an account through the privacy Support form available below.
2. Data we process
- Account data: email address, nickname, optional name, password hash, login provider, role, account ID, and authentication sessions.
- Profile and social data: avatar, background, status, presence, teams, contacts, comments, conversations, stickers, reactions, and voice messages. Audio/video calls use transient WebRTC signaling and are not recorded by pilvory.
- Workspace content: notes and preferences synchronized by your account, uploaded cloud files, personal website links, and AI connection settings.
- Support and security data: support requests, recovery records, IP and request metadata used for abuse prevention, CAPTCHA results, and technical server logs.
- Optional service data: city or coordinates submitted for weather, and prompts sent to OpenRouter only after you connect your own OpenRouter account.
pilvory does not request payment-card data, identity documents, or your account password in support tickets.
3. Why we use it and our legal bases
- Contract: creating and operating your account, synchronizing content, storing files, delivering messaging, support, and requested integrations.
- Legitimate interests: securing the service, preventing abuse, diagnosing failures, and maintaining reliable operation, balanced against your rights.
- Consent: optional profile information or integrations where consent is the appropriate basis; consent can be withdrawn without affecting earlier lawful processing.
- Legal obligation: when records must be kept or disclosed under applicable law.
4. What other people can see
Your nickname, account ID, avatar, presence, public status, team badge, and profile comments can be visible to signed-in users. Your name and system role are shown only according to your profile settings. Private files, notes, email address, password hash, and private conversations are not public. Messages are visible to the participants of the relevant conversation.
5. Service providers and transfers
Data is shared only as needed to provide features you choose: Google or GitHub for OAuth sign-in; Cloudflare Turnstile for anti-abuse checks; Resend for recovery email when enabled; OpenRouter for AI requests after connection; OpenWeather or Open-Meteo for weather searches; Google STUN for establishing optional peer-to-peer WebRTC calls; and Google Fonts or image/CDN providers for interface assets. Call participants receive each other's real-time media and may learn network information needed for a peer-to-peer connection. These providers may process IP addresses and request metadata and may operate outside the EEA under their own terms and lawful transfer safeguards.
pilvory does not sell personal data and does not create advertising profiles.
6. Cookies and security
pilvory uses essential secure cookies for authentication and local browser storage for preferences and synchronized workspace state. Passwords are stored as one-way hashes. Sensitive integration credentials are encrypted at rest. Access controls, request limits, CAPTCHA, HTTPS, and audit records are used to protect accounts. No online system can guarantee absolute security.
7. Retention
- Account and workspace data is kept while the account remains active and is removed when the account is deleted, subject to technical backups and legal obligations.
- Authentication sessions last up to 7 days unless you sign out earlier.
- Recovery links expire after 20 minutes; expired technical records are removed during routine cleanup.
- Closed support tickets are automatically deleted after 180 days; tickets can also be deleted earlier by a Developer.
- Files, messages, comments, and profile media are retained until you remove them, their container is deleted, or the account is deleted.
8. Your rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent where processing relies on consent. Requests are handled after reasonable identity verification. You may also complain to the Estonian Data Protection Inspectorate or another competent supervisory authority.
9. Children
pilvory is not intended for children under 16 unless use is authorized by a parent or guardian where required by applicable law.
10. Changes to this policy
Material changes will be announced in the service and the effective date and version above will be updated. Continued use after a change does not replace consent where fresh consent is legally required.
Comments
0