Privacy policy
This policy explains which personal data PaxHelm processes, why, on what legal basis, and what rights you have over it.
本文有葡萄牙语和英语版本。此处显示英语版本。
草稿。 本文尚待法律审核,目前不具有约束力。责任实体的身份信息、数据处理者以及保存期限将在最终版本发布前补充。
工作版本日期: .
本文内容
Data controller
For privacy questions, write to [email protected].
What data we process
- Account: name, email address and password, stored only as a hash. If you sign in with a Microsoft account, that account's identifier.
- Content you create in the service: tasks, projects and their documents, reminders, follow-ups, captures, ideas, notes and contacts.
- Accounts you choose to connect: synced mail messages and calendar events, and the credentials for those accounts, encrypted at rest.
- Obsidian notes, if you turn on sync: the vault's files and their revision history.
- Devices: notification subscriptions and the tokens of devices you pair.
- Technical data: access and error logs, needed for security and troubleshooting.
- Billing, once payment is available: the data needed to issue invoices.
Why we use the data and on what basis
- To provide the service you signed up for, including service emails (account verification, invitations, access recovery): performance of a contract, GDPR Article 6(1)(b).
- To keep the service secure, prevent abuse and troubleshoot faults: legitimate interest, Article 6(1)(f).
- To meet legal obligations such as tax and invoicing: legal obligation, Article 6(1)(c).
We do not sell personal data or use it for advertising.
Artificial intelligence
AI features are optional. By default they run on your own computer through the local agent: processing happens there and the text is not sent to any AI provider. Cloud AI works only if it is turned on; then the text each request needs, such as a capture to sort, is sent to the cloud AI provider, acting as a processor.
AI suggestions are never applied without your confirmation. We make no solely automated decisions that have legal effects on you.
Publishing to social networks
If you connect social network accounts to Publishing (for example a Facebook Page, an Instagram account or a Threads profile), we keep each account's id and name and an encrypted access token, only to publish what you write and schedule. For Meta accounts we also keep a fingerprint (hash) of the id of the person who connected them, to handle Meta's deletion requests.
The content you choose to publish, with its images and videos, is sent to each network you choose, which handles it under its own terms and privacy policy. Images and videos stay in the service's storage until you delete them.
- Disconnecting an account in Settings › Publishing deletes the account and its token at once.
- If you remove the PaxHelm app in your Facebook, Instagram or Threads settings, Meta tells us and we delete those accounts' tokens.
- If you ask Meta to delete your data, we delete the connected accounts and their tokens, and Meta shows you a confirmation code with the request's status at /privacy/data-deletion.
Processors
We use processors to host the service, deliver service emails and, once they are turned on, for cloud AI and payments, under contracts that bind them to process data only on our instructions.
Microsoft and Google accounts, IMAP and SMTP servers and Obsidian are services you choose to connect; their own terms and policies apply.
Transfers outside the European Economic Area
If a processor handles data outside the European Economic Area, the transfer relies on a European Commission adequacy decision or on standard contractual clauses, and the list of processors says so.
How long we keep data
- While your account is active, we keep the data needed to provide the service.
- Billing data is kept for as long as tax law requires.
Your rights
At any time you can ask to access, correct or erase your data, object to or restrict its processing, and receive it in a structured format. The full export is available in the settings.
To exercise these rights, write to [email protected]. We reply within one month.
You can also lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.
Security
Credentials for connected accounts are encrypted at rest, connections use HTTPS, and each workspace is isolated from the others. If a data breach affects you, we notify the CNPD and, where the law requires it, the people affected, within the GDPR deadlines.
Changes to this policy
If we change this policy in a meaningful way, we will tell you by email or in the app before the change takes effect.