Privacy Policy
Version 1.0 · Draft pending counsel review.
1. Controller
Done & Dusted AS, Norway. GDPR applies through the EEA. Contact: the support address in the footer.
2. What we process and why
Account data (email, name, language, timezone): contract performance. Voice Profile and samples: contract performance, user-provided. Threads and consented edited replies: consent, revocable by deletion. Usage metadata and analytics events (no message content): legitimate interest in operating and improving the service. Payment data: processed by Stripe; Chatwell never sees card numbers.
3. Screenshots and conversations
Screenshots are processed in server memory only and are deleted the moment the reply is generated. They are never written to disk, storage or logs. Extracted conversation text lives at most 15 minutes in an encrypted cache unless you explicitly save a thread. Screenshots contain information about other people; this ephemeral design is our data minimization measure, and you must only upload conversations you participate in.
4. AI processing
Conversations are processed by our model provider under a data processing agreement; the provider does not train on this data.
5. Processors
Supabase-compatible self-hosted database (EU), Anthropic (model), Stripe (payment), Resend (email), Cloudflare (network). All under DPAs.
6. Retention
Account data until deletion. Backups age out within 14 days after deletion. Stripe retains invoices per accounting law.
7. Your rights
Access and portability: self-serve export in Account. Erasure: self-serve deletion in Account, immediate. Rectification, restriction, objection and complaint to Datatilsynet: via support.
8. No sale of data, no advertising use, no tracking cookies on the product.
That is the whole section.