Legal
Privacy notice
How Ansedd handles personal data when you visit the website, run an analysis or use the service.
Last updated:
1. Who is responsible
Flyingbox AB, organisation number 5593559213 is the controller for the processing described in this notice. Contact us at hello@flyingbox.app for privacy questions, incidents or requests.
2. Data we process
- Account and contact data, such as name, work email, authentication method and account identifiers.
- Workspace data, such as company name, domain, tracked buyer questions, competitors and the changes you choose to follow.
- Measurement evidence, such as AI answers, citations, provider status, models, usage, cost and derived findings linked to your workspace.
- Billing records, such as Stripe customer and subscription identifiers, plan, status and invoice-related records. Ansedd does not store full payment card details.
- Security and service data, such as pseudonymous rate-limit keys, session data, error diagnostics and coarse request context needed to operate and protect the service.
- Acquisition data, such as a first-party journey identifier, scan identifier and allowlisted campaign parameters. We do not place email, raw IP addresses, tokens or raw AI answers in analytics event properties.
3. Why we process data and our legal bases
- To provide the account, trial, measurements, recommendations, support and billing you request. The legal basis is performance of our contract or steps requested before entering it.
- To secure, troubleshoot and improve Ansedd, prevent abuse, measure the acquisition journey and keep reliable audit evidence. The legal basis is our legitimate interest in operating a safe and useful B2B service.
- To meet accounting, tax, sanctions, dispute and other legal obligations. The legal basis is compliance with a legal obligation or establishment, exercise or defence of legal claims.
- Where a future optional feature requires consent, we will ask separately and allow withdrawal without affecting earlier lawful processing.
4. AI measurements and customer instructions
Ansedd sends the buyer questions and limited measurement context needed to obtain answers from the selected AI and search providers. Do not add sensitive personal data, secrets or confidential third-party data to prompts or change notes. We do not use one customer's raw prompts, domains, answers or citations as raw evidence for another customer.
Global product learning may use structured, de-identified outcomes only when they do not contain customer identifiers, domains, URLs, raw prompts or raw answer text and can be recomputed without a deleted source.
5. Service providers
We use subprocessors only where needed for the relevant feature. The current set is:
- Vercel for hosting, deployment and platform operation.
- Neon for PostgreSQL data storage and Managed Auth.
- Vercel AI Gateway and the selected model providers for routed AI requests.
- DataForSEO for Swedish ChatGPT and Gemini interface collection and Google AI Overview measurement.
- Stripe for subscriptions, payments and billing records.
- Resend for transactional email.
- Trigger.dev for scheduled and background work.
- Cloudflare for security and abuse-prevention services used by the public analysis.
- Sentry for production error monitoring once the approved production integration is enabled.
6. International transfers
Some providers process data outside Sweden or the EEA. Where GDPR requires a transfer safeguard, we use an adequacy decision, the EU Standard Contractual Clauses or another lawful mechanism together with appropriate supplementary measures. Contact us for information about the safeguard relevant to a specific provider.
7. Retention
- Anonymous public-analysis data is retained for no more than 7 days unless it becomes part of an account you create.
- Security and rate-limit data is retained for no more than 90 days, unless longer retention is necessary to investigate an active incident or legal claim.
- Acquisition analytics is retained for no more than 13 months.
- Private product and measurement data is retained while the account is active and then deleted through the account-deletion process.
- A verified deletion request is completed within 30 days. Encrypted backups expire through the backup cycle within 90 days.
- Billing and accounting records that Swedish law requires are retained for seven years after the end of the relevant calendar year. Unrelated product content is not kept with those records.
8. Your rights
Depending on the processing, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. You may also complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten. Contact hello@flyingbox.app to exercise a right. We may need to verify your identity and may retain information where law requires it.
9. Account deletion
The authenticated Settings page provides an account-deletion path. A request blocks new measurements, deletes the account's private product evidence and requests deletion of the Managed Auth identity. Ansedd keeps only a minimal non-reversible receipt showing request time, completion time and status. Provider or backup copies expire under the periods above.
10. Security, changes and legal review
We use access controls, encryption in transit, isolated customer queries, abuse controls, tested deletion boundaries and privacy-safe logging. No internet service can promise absolute security. Report a suspected incident to the contact below.
We update this notice when processing changes materially and publish the new date here. This notice describes the implemented service and approved operating model, but software and policy copy alone do not guarantee legal compliance. External legal review before a paid launch remains recommended.
Privacy contact
Flyingbox AB, organisation number 5593559213. Email hello@flyingbox.app.