Privacy Policy

Effective date: 13 August 2025

1) Who we are (data controller)

Twitchemote AB ("Twitchemote", "we," "us")

Fabrikörvägen 4A, 13152 Stockholm, Sweden

Contact: contact@twitchemote.com

We operate twitchemote.com (the "Service"). This Policy explains how we collect, use, share, and protect personal data, and your rights under the EU/EEA General Data Protection Regulation (GDPR).

2) What we collect

We collect the minimum data needed to run the Service.

Data you provide

  • Account details (e.g., name/username, email, password hash) if you create an account.
  • Purchases (plan, price, currency, time of purchase). We do not store full card numbers; payments are handled by our payment partner.
  • Content: prompts, images, uploads, and assets you create or submit ("User Content" and "Generated Content").
  • Support messages and correspondence.

Data collected automatically

  • Device and usage data (e.g., IP address, browser type/version, language, pages viewed, timestamps, referral URLs, feature interactions).
  • Event and diagnostic logs to keep the Service stable and secure.
  • Cookies or similar technologies (see Section 7).

3) Why we process your data (purposes) & legal bases

We use your data for the following purposes, under these GDPR legal bases:

  • Provide the Service (create accounts, let you generate/download assets, operate features) – Contract (Art. 6(1)(b)), Legitimate interests (Art. 6(1)(f)).
  • Payments and billing (process purchases, detect fraud) – Contract, Legal obligation (tax/accounting), Legitimate interests.
  • Security and integrity (prevent abuse, enforce limits, protect against attacks) – Legitimate interests.
  • Improve quality and safety (debugging, diagnostics, feature testing, content quality checks) – Legitimate interests.
  • Showcase & marketing (with safeguards; see Section 5) – Legitimate interests or Consent where required by law.
  • Communications (service emails, updates, policy changes) – Contract, Legitimate interests; for optional marketing emails – Consent.
  • Legal compliance (tax, accounting, regulatory requests) – Legal obligation.

4) What we share and with whom

We share data only with trusted service providers who help us run the Service. They act under data-processing agreements and only on our instructions.

  • Hosting & delivery: Vercel (hosting/CDN), which may process logs and basic connection data to serve the site reliably and quickly.
  • Backend & storage: Supabase (application backend and storage).
  • Payments: Stripe (payment processing, fraud prevention). We do not store full card numbers.

We may also share data:

  • To comply with law or valid legal requests.
  • To protect rights and safety (investigate abuse, enforce Terms).
  • Business transfers (e.g., merger or acquisition); your data remains protected under this Policy or a comparable one.

We do not sell your personal data.

5) Content, showcasing, and improvement use

  • You stay in control of your creations. See the Terms & Conditions for ownership and license details.
  • To operate the Service and maintain quality/safety, we may store and review User Content and Generated Content (e.g., to resolve a bug, prevent misuse, or improve visual quality and consistency).
  • We may showcase examples of assets for marketing (e.g., on our website, social channels, or product materials).
  • Opt-out: If you prefer that your assets (User Content or Generated Content) are not used for showcasing, email contact@twitchemote.com with subject "Opt-out of showcasing" and include links/IDs of the assets or your account email. We will honor your request where required by law and going forward.
  • Where legally necessary, we will also respect requests to limit the use of your content for feature improvement. Contact contact@twitchemote.com to request this.

6) International transfers

We may process data outside your country, including outside the EEA. When we transfer personal data internationally, we rely on GDPR-approved safeguards (e.g., Standard Contractual Clauses and additional measures as needed) to protect your data.

7) Cookies and similar technologies

We use:

  • Essential cookies to run core features (security, session, downloads).
  • Functional/Performance cookies to understand usage and improve reliability.

You can manage cookies in your browser settings. If we introduce optional analytics/marketing cookies, we will request consent via a banner and update this Policy.

8) Data retention

We retain personal data only for as long as necessary for the purposes above:

  • Account data: while your account is active and for a reasonable period afterward (e.g., to manage requests or disputes).
  • Content (uploads/outputs): as needed to operate the Service and for the uses described in Section 5; removed earlier upon valid deletion or opt-out requests, subject to backups and legal obligations.
  • Payment records: retained as required by tax and accounting laws.
  • Logs/diagnostics: kept for a limited period for security and troubleshooting.

Backups may persist for a short time after deletion but are removed on a rolling schedule.

9) Your rights (EEA/GDPR)

Subject to conditions and exceptions in law, you have the right to:

  • Access your personal data and get a copy.
  • Rectify inaccurate or incomplete data.
  • Erase data ("right to be forgotten").
  • Restrict processing in certain cases.
  • Portability of data you provided to us, in a structured, commonly used format.
  • Object to processing based on legitimate interests (including showcasing/marketing) and to direct marketing at any time.
  • Withdraw consent where processing is based on consent (this does not affect past processing).

To exercise rights, email contact@twitchemote.com. We may need to verify your identity. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.

10) Security

We use technical and organizational measures to protect personal data, including encryption in transit, access controls, and restricted employee access on a need-to-know basis. No system is perfectly secure; you also play a role by using strong, unique passwords and keeping them confidential.

11) Children

The Service is not directed to children. If you are below the age at which you can lawfully consent to online services in your country, you must have parental permission. If we learn we have collected personal data from a child without appropriate consent, we will take steps to delete it.

12) Communications

We may send you transactional emails (e.g., receipts, critical notices). You can unsubscribe from non-essential marketing emails at any time via the email footer or by contacting us.

13) Changes to this Policy

We may update this Policy from time to time. We will post the new version and update the Effective date. If changes are material, we will take additional steps to inform you where appropriate. Continued use of the Service after the updated Policy takes effect means you accept the changes.

14) Contact us

Twitchemote AB
Fabrikörvägen 4A, 13152 Stockholm, Sweden

contact@twitchemote.com