Legal
Privacy Policy
What personal data Pinevon collects, why, who receives it, how long we keep it and the choices you have.
Version 0.2-draft · No effective date set yet · All legal documents
Draft — pending legal review. This document is a complete working draft prepared by the Pinevon team. It has not yet been reviewed by a lawyer and no effective date has been set. It describes how the service is actually built and operated today; bracket-free wording is deliberate, but jurisdiction-specific terms must be confirmed by qualified counsel before it is relied on.
1. Who is responsible for your data
Pinevon (“we”, “us”) is the controller of personal data described in this policy for pinevon.com and the Pinevon account. For data a business customer puts into a Pinevon product such as Anchor (for example its customers and orders), the business is the controller and Pinevon is its processor under the Data Processing Addendum.
Privacy contact: privacy@pinevon.com.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email address, sign-in method, verification status, security events (sign-ins, password changes, enrolled factors). Passwords are handled by our authentication provider and are never visible to us. | You / provider |
| Profile | Display name, avatar, language and region preferences you choose to set. | You |
| Support and contact | Name, email, phone, company, message, topic and any attachment you send; a ticket reference and status. | You |
| Assistant conversations | The messages you send to the Pinevon Assistant and its replies during the conversation. | You |
| Usage and diagnostics | Page visited, referrer, coarse device and country signal, app version, service-worker and connectivity state, error reports. No cross-site identifier and no advertising profile. | Your device |
| Payments (paid products) | Plan, status, invoice history and the provider’s customer reference. Card details go to the payment provider, not to us. | You / provider |
| Technical and security | IP address, user agent, timestamps and request identifiers in server logs and audit records, used to secure the Services and investigate abuse. | Your device |
3. Why we use it (purposes and legal bases)
- Provide the Services you asked for — create and secure your account, deliver features, answer support requests (performance of a contract).
- Keep the Services secure and prevent fraud and abuse — rate-limiting, audit trails, incident response (legitimate interests, and legal obligation where applicable).
- Understand and improve the Services using cookieless aggregate usage data (legitimate interests).
- Send service messages such as verification, security alerts, billing notices and replies to your requests (contract / legitimate interests). Marketing email, if we ever send it, is only with your consent and always has an unsubscribe link.
- Comply with law, enforce our Terms and establish or defend legal claims (legal obligation / legitimate interests).
- Where the law requires consent for a purpose, we ask for it and you can withdraw it at any time.
We do not sell personal data, we do not share it for third-party advertising, and we do not use it for automated decisions that have legal or similarly significant effects on you.
4. AI processing
When you message the Pinevon Assistant, the conversation is sent to an AI provider we have configured to generate the reply. We send only what is needed for the conversation, not unrelated account data. Providers may include Google (Gemini), Groq, OpenAI and Anthropic depending on availability; each processes the request under its API terms and, under those terms, does not use API inputs to train its general models. See the AI Use Policy.
6. International transfers
Our providers may process data in countries other than yours, including the United States and the European Union. Where required we rely on appropriate safeguards such as standard contractual clauses or the provider’s certified transfer mechanisms.
7. How long we keep data
| Data | Retention target |
|---|---|
| Account and profile | While your account is active; deleted when you delete your account, subject to the exceptions below. |
| Support tickets and attachments | 24 months after the ticket is resolved or closed, then deleted automatically (including any attachment). |
| Read notifications | Deleted automatically 12 months after being read. |
| Assistant conversations | Kept only while needed to answer the conversation; not used for training. |
| Cookieless usage records | Up to 14 months; deleted automatically every day. |
| Security and audit logs | Kept while needed for security, integrity and legal purposes. These logs are append-only and are not currently deleted automatically. |
| Invoices and tax records | As long as tax and accounting law requires. |
These are the periods we work to. Deletion of cookieless usage records, support tickets (with their attachments) and read notifications is automated and runs daily; other categories are reviewed periodically. We may keep data longer where needed to comply with law, resolve disputes or enforce agreements. Backups age out on their normal cycle.
8. Your rights and choices
Depending on where you live you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, to withdraw consent, and to complain to a data-protection authority. You can view and edit your profile in Settings, and delete your account and its data yourself — see how to delete your data. For anything else email privacy@pinevon.com. We may need to verify your identity first and will respond within 30 days (or the period the law sets).
We do not discriminate against you for exercising these rights.
9. Security
We protect personal data with encryption in transit, access controls enforced in the database as well as the application, least-privilege staff access, audit logging of sensitive actions and separation between products. No system is perfectly secure. If a breach affects your data we will notify you and the relevant authorities as the law requires. Report vulnerabilities via our Security Disclosure Policy.
11. Children
The Services are not directed to children and are not intended for anyone under 18. We do not knowingly collect personal data from children; if you believe we have, contact us and we will delete it.
12. Changes
We will post updates here with a new version number and, for material changes, notify you before they apply.