Privacy policy

Last updated:

1. Introduction

Pyroplane ("the Service") is operated by Arya Pooladi AB, a company registered in Sweden (organisation number: 559444-0561), with registered address at Marmorvägen 5B, 752 44 Uppsala, Sweden ("we", "us", "our").

We are committed to protecting your personal data and processing it in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Swedish data protection law.

This Privacy Policy describes what data we collect, why we collect it, how we use and store it, and what rights you have.

2. Data Controller

Arya Pooladi AB is the data controller for personal data processed through Pyroplane.

Contact: support@pyroplane.com Address: Marmorvägen 5B, 752 44 Uppsala, Sweden

3. What Data We Collect

3.1 Data You Provide Directly

  • Account information: name, email address, profile picture

  • Team data: team name, brand settings, therapeutic area, website

  • Content: posts, comments, calendar events, uploaded files and assets

  • Communications: support requests and messages sent to us

3.2 Data Collected Automatically

  • Usage data: pages visited, features used, actions taken in the Service

  • Device and technical data: browser type, device type, operating system, IP address, session identifiers

  • Authentication tokens and session cookies

3.3 Data from Third-Party Authentication When you sign in using Google OAuth, we receive your name, email address, and profile picture from Google. This data is used solely to create and manage your account.

3.4 Payment Data Payment transactions are processed by Stripe. We do not store full card details. We may receive and store billing metadata such as subscription status, plan type, and transaction identifiers.

3.5 Analytics Data (with consent) If you consent via our cookie banner, Microsoft Clarity may collect behavioural analytics data including mouse movements, clicks, and session recordings to help us improve the Service. This data is only collected upon explicit consent.

4. Legal Basis for Processing

Purpose

Legal Basis

Providing and operating the Service

Performance of contract (Art. 6(1)(b) GDPR)

Account management and authentication

Performance of contract (Art. 6(1)(b) GDPR)

Billing and subscription management

Performance of contract (Art. 6(1)(b) GDPR)

Security, fraud prevention

Legitimate interests (Art. 6(1)(f) GDPR)

Legal compliance

Legal obligation (Art. 6(1)(c) GDPR)

Analytics and service improvement

Consent (Art. 6(1)(a) GDPR)

Marketing communications

Consent (Art. 6(1)(a) GDPR)

5. How We Use Your Data

We use your personal data to:

  • Create and manage your account

  • Provide and operate all features of the Service

  • Process subscription payments and manage billing

  • Send transactional emails (invitations, notifications, password resets)

  • Respond to support requests

  • Detect and prevent fraud or abuse

  • Comply with legal obligations

  • Analyse usage patterns to improve the Service (with consent)

6. AI Features and Data Processing

Pyroplane uses artificial intelligence features including AI-generated post ideas and AI First Drafts. To deliver these features, content you submit (such as post text and writing samples) may be processed by the following AI providers:

  • OpenAI (openai.com) — used for AI content generation

  • Google Gemini (deepmind.google) — used for AI content generation

Both providers operate under Data Processing Agreements with us and have confirmed that your data is not used to train their models. Content submitted to AI features is processed solely to generate the requested output and is not retained by these providers for training purposes.

7. Data Storage and Sub-processors

Your data is stored and processed within the European Union and European Economic Area. We use the following sub-processors:

Provider

Purpose

Location

Supabase

Database and authentication

Stockholm, Sweden (EU)

Cloudflare R2

File and asset storage

Eastern Europe (EU)

Upstash (QStash)

Background job processing

EU Central

Stripe

Payment processing

EU/US (SCCs in place)

Resend

Transactional email delivery

EU

OpenAI

AI content generation

US (SCCs in place)

Google (Gemini)

AI content generation

EU/US (SCCs in place)

Microsoft Clarity

Behavioural analytics (consent-gated)

EU/US (SCCs in place)

Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Data Sharing

We do not sell, rent, or trade your personal data. We share data only:

  • With sub-processors listed above, strictly to operate the Service

  • Within your team workspace, where team members can see shared content and organisational data

  • When required by Swedish or EU law, court order, or regulatory authority

  • To protect our legal rights or prevent harm

9. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide the Service. Upon account deletion, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. accounting records under Swedish bookkeeping law, which must be retained for 7 years).

10. Your Rights Under GDPR

As a data subject under GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you

  • Rectification — request correction of inaccurate or incomplete data

  • Erasure — request deletion of your data ("right to be forgotten")

  • Restriction — request that we limit how we process your data

  • Data portability — receive your data in a structured, machine-readable format

  • Object — object to processing based on legitimate interests

  • Withdraw consent — withdraw consent at any time where processing is consent-based

To exercise any of these rights, contact us at support@pyroplane.com. We will respond within 30 days. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

11. Cookies

We use the following types of cookies:

  • Strictly necessary cookies — required for authentication and session management. These cannot be disabled.

  • Analytics cookies — used by Microsoft Clarity to analyse user behaviour. Only set with your explicit consent via our cookie banner.

You can manage your cookie preferences through our cookie consent tool at any time.

12. Age Restriction

The Service is intended for business use by individuals aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us immediately at support@pyroplane.com and we will delete the account.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or prominent notice within the Service at least 14 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

Arya Pooladi AB Margorvägen 5B, 752 44 Uppsala, Sweden Organisation number: 559444-0561 Email: support@pyroplane.com