1. Who we are
Pyroplane is provided by Arya Pooladi AB, Swedish organization number 559444-0561, Marmorvägen 5B, 752 44 Uppsala, Sweden (“Pyroplane”, “we”, “us”, or “our”).
For privacy questions or requests, email support@pyroplane.com. Please do not send sensitive information in your first message. We may need to verify your identity or authority before acting on a request.
2. Scope
This policy applies to pyroplane.com, the Pyroplane web application, related product communications, support, and sales conversations. It does not govern third-party websites, services, or publication channels that you choose to use with or alongside Pyroplane. Those parties apply their own privacy notices.
Pyroplane is a business service intended for professional use. It is not directed to children or to personal household use.
3. Controller and processor roles
- When we are controller
- Arya Pooladi AB is the controller for personal data used to operate our business and relationship with you, including website visits, accounts, workspace administration, billing, sales, support, service security, and our own product analytics.
- When we are processor
- If a customer places personal data in its workspace content, the customer generally decides why and how that data is used. The customer is then the controller and Arya Pooladi AB processes the data on the customer’s instructions to provide the service. A separate data processing agreement may apply.
- Your organization’s responsibilities
- If you use Pyroplane through an employer or another organization, that organization may administer your workspace, access and manage work created in it, and submit requests concerning that data. Ask your organization about its own privacy practices.
4. Personal data we handle
- Account and profile data
- Name, business email address, profile image, job title or department, authentication and verification data, account status, sign-in timestamps, and preferences.
- Organization and workspace data
- Company and team names, website, size, industry, therapeutic focus areas, region, time zone, brand settings, membership, role, invitations, and workspace administration records.
- Workspace content
- Marketing plans, posts, drafts, ideas, events, schedules, sources, notes, tags, categories, comments, mentions, reactions, review and approval records, collaborators, version history, live publication links, files, images, and other material you upload or create.
- AI inputs and outputs
- Prompts, draft instructions, selected workspace context, sample posts and images used for style analysis, generated drafts, style profiles, and hashtag suggestions when you choose to use an AI feature.
- Billing and commercial data
- Plan, trial and subscription status, billing interval, transaction and invoice metadata, Stripe customer and subscription identifiers, business contact details, and commercial correspondence. Stripe handles payment-card details; we do not receive or store full card numbers.
- Support and communications
- Messages, meeting details, feedback, survey responses, attachments, and records needed to answer requests or manage our relationship.
- Usage and technical data
- IP address, browser and device information, operating system, timestamps, requested pages and routes, referring page, consent choice, diagnostic events, performance data, and security logs. Optional product analytics may also include session interaction and navigation data after consent.
- Public and third-party data
- Information from public company websites, public scientific and industry-event sources, publication URLs, and professional directory entries that you or your colleagues choose to save, such as a name and LinkedIn URL.
5. Where data comes from
We receive data directly from you; from your organization, workspace administrators, and colleagues; automatically from your browser and use of the service; from payment, authentication, hosting, analytics, and support providers; and from public sources when a feature is designed to collect public industry, event, company, or publication information.
Account, authentication, workspace-administration, and billing details requested during sign-up or purchase are needed to enter into or perform the service agreement. If they are not provided, we may be unable to create or administer the account, workspace, or subscription.
6. Why we use personal data
- Provide the service
- To create and authenticate accounts, operate workspaces, store content, support collaboration, generate requested AI output, manage subscriptions, and provide support. The legal basis is performance of a contract or steps requested before entering one.
- Administer customer relationships
- To communicate with business contacts, arrange demonstrations, manage orders, invoice, and keep commercial records. The legal basis is contract, legitimate interests in running our business, and legal obligations.
- Keep Pyroplane reliable and secure
- To prevent abuse, enforce access controls, diagnose failures, maintain audit and security logs, protect accounts and files, and investigate incidents. The legal basis is our legitimate interests in operating a secure service and, where applicable, legal obligations.
- Improve the product
- To understand aggregate website traffic, feature use, performance, and usability, and to develop Pyroplane. Essential operational measurement is based on our legitimate interests. Vercel Web Analytics measures aggregate website traffic without cookies; Google Analytics and Microsoft Clarity run only after consent.
- Communicate updates
- To send service notices, security messages, invitations, workflow notifications, trial and billing reminders, and requested marketing communications. The basis is contract, legitimate interests, or consent, depending on the message and local law.
- Meet legal requirements
- To keep accounting records, respond to lawful requests, establish or defend legal claims, and comply with applicable law. The basis is legal obligation or legitimate interests.
If we rely on legitimate interests, we consider the necessity of the processing and balance our interests against the rights and reasonable expectations of the people affected.
7. AI features
Pyroplane includes optional features that analyze writing samples and help create drafts or hashtag suggestions. When you use them, the inputs needed for your request, including text, instructions, selected context, or sample images, are sent to our AI provider, Anthropic, to produce the requested output. We store relevant outputs and style profiles in the workspace so workspace members can use the feature.
Do not submit patient records, protected health information, genetic or biometric data, clinical-trial subject data, or other special-category personal data to an AI feature unless your organization has first confirmed a lawful basis and Arya Pooladi AB has expressly agreed in writing that the service may process it.
AI output can be incomplete or incorrect. Pyroplane is not a medical device, clinical decision-support system, or substitute for scientific, medical, legal, regulatory, or pharmacovigilance review.
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about you.
9. International transfers
Arya Pooladi AB is established in Sweden, but some providers may process personal data in countries outside Sweden or the European Economic Area. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism and assess whether supplementary safeguards are needed.
11. Retention and deletion
We keep personal data only as long as needed for the purposes described here. The period depends on the account or customer relationship, the type of record, workspace instructions, security needs, limitation periods, and accounting or other legal requirements.
- Active accounts and workspaces
- Account, workspace, and content data is generally retained while the account or customer relationship remains active and as needed to provide the service.
- Deleted accounts and teams
- When an authorized user deletes an account or team through the product, it is placed in a 30-day recovery period. Access is revoked during that period. After the recovery window, the associated records and stored files are scheduled for permanent purge and the remaining profile record is de-identified, except where specific data must be retained by law or for legal claims.
- Billing and legal records
- Invoices, transaction records, contracts, and related correspondence may be retained for the period required by accounting, tax, and other applicable law.
- Technical records
- Security, queue, cache, monitoring, and diagnostic data is retained for shorter operational periods determined by the purpose, provider settings, and incident needs.
Deleting one item does not necessarily remove copies included in another user’s lawful records, an audit trail, or a backup that has not yet cycled out.
12. Security
We use organizational and technical measures designed to protect personal data, including authenticated accounts, role and membership checks, row-level database controls, private file storage, signed asset access, logging, secret redaction, recoverable deletion, and limits against abusive requests. No internet service is completely secure, and we cannot guarantee absolute security. See our Security page or contact us to discuss your organization’s requirements.
13. Your data protection rights
Depending on the circumstances and applicable law, you may have rights to:
- request access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive data you provided in a portable format;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent at any time, without affecting earlier processing; and
- complain to a data protection authority.
These rights are not absolute. We may need to keep or continue using certain information where law permits. If your request concerns data in an organization’s workspace and we act as processor, we may direct the request to that organization or assist it in responding.
Send requests to support@pyroplane.com. You may also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, Sweden, using IMY’s complaint service, or to the supervisory authority where you live or work.
14. Children and regulated data
Pyroplane is not intended for anyone under 18. We do not knowingly collect children’s personal data. The service is also not designed as a repository for patient or clinical-trial subject records. If you believe prohibited or inappropriate personal data has been submitted, contact us promptly.
15. Changes to this policy
We may update this policy as Pyroplane, our providers, or applicable law changes. We will post the revised version here and change the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where appropriate.
16. Contact
Arya Pooladi ABOrganization number 559444-0561
Marmorvägen 5B
752 44 Uppsala, Sweden
support@pyroplane.com