Legal
Privacy Policy
Last updated: August 3, 2026
1. Who is responsible for your data
The data controller for the personal data described here is:
Ailandmedia AB
Campus Gräsvik 2, 371 75 Karlskrona, Sverige
Organisationsnummer: 559533-7626
azza@ailandmedia.com
2. What we collect
- Account details — your name, email address and password (stored encrypted).
- Billing details — your name, email, billing address and VAT number if you give one. Card numbers never reach us; they go straight to Stripe.
- Your brand and content — your website address and what we read from it, your answers, uploaded images, video and documents, and the content we generate for you.
- Connected accounts — access tokens for the social accounts you connect, and performance data about the posts we publish for you.
- Technical data — IP address, browser and device information, and logs, used to keep the service running and secure.
3. Why we use it, and on what basis
| What for | Legal basis |
|---|---|
| Running the service — your account, generating content, scheduling and publishing | Performance of our contract with you |
| Taking payment, and keeping invoices | Performance of our contract; legal obligation for accounting records |
| Keeping the service secure and preventing abuse | Our legitimate interest in a service that works |
| Service emails — account verification and password reset | Performance of our contract |
| Marketing emails, if any | Your consent — withdrawable at any time |
4. Who we share it with
We do not sell your data. We share it only with the companies that help us run the service, and only what each one needs. These are all of them:
| Who | What they get | Why |
|---|---|---|
| Stripe (Ireland / USA) | Your name, email, billing address and VAT number — and your card details, direct from you | Taking payment, invoices, VAT |
| UploadThing (USA) | Every image, video, PDF and document you upload | Storing your media and brand documents |
| Anthropic (USA) | Your messages to our assistant, and the brand context sent with them | Powers the in-app assistant |
| Google (USA) | Your website content, brand profile, uploaded documents and the content generated from them | Reads your site, writes posts and captions, builds your strategy |
| OpenAI (USA) | Your brand profile answers | Legacy brand documents — being retired |
| Cloudflare (USA) | IP address, browser, device signals | Bot protection (see section 5) |
| Resend (USA) | Your email address and the message | Sending our emails |
| Sentry (USA) | Technical error diagnostics. Deliberately configured not to send your IP address, cookies or session | Finding and fixing faults |
| Pexels (USA) | Only the words you type when searching for a stock image, sent from our server | Stock photo and video search |
| Railway, Neon, Vercel | Everything above, as stored data | Hosting and databases |
| Instagram, Facebook, LinkedIn | Only the posts you choose to publish | Publishing on your behalf |
We do not use your content to train AI models, and we use these providers under business terms where your content is processed only to return a result to us — not to train their models.
5. Bot detection — Cloudflare Turnstile
We use Cloudflare Turnstile to protect the site from bots and abuse. When you use certain features — such as the free brand preview — Turnstile processes your IP address, browser type, your device's TLS fingerprint and signals about how you interact with the page, to confirm you are a person.
Cloudflare processes this on our behalf under the Cloudflare Turnstile Privacy Policy. Turnstile is designed to be privacy-preserving — it does not track you across websites or use this for advertising.
6. Sending data outside the EU
Several of the companies above are in the United States, so your data is transferred outside the EU. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the provider is certified under it.
You can ask us for details of the safeguards that apply to any particular provider.
7. How long we keep it
- Your account and content — while your account is open, and for a short period after you close it in case you come back.
- Invoices and accounting records — seven years, as Swedish bookkeeping law requires.
- Technical logs — a short retention period for security and troubleshooting.
When you close your account we delete your content, other than records the law requires us to keep.
8. Security
Data is encrypted in transit and at rest, access to personal data is limited to those who need it, and card details never touch our servers. No system is perfectly secure, but if a breach affects your personal data we will tell you and the regulator as the law requires.
9. Your rights
You can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or send it to another provider. You can withdraw consent to marketing at any time.
Email azza@ailandmedia.com and we will respond within one month. If you think we have handled your data wrongly, you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish data protection authority.
10. Changes to this policy
If we change this policy in a way that materially affects you, we will email you. The date at the top always shows when it was last updated.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
azza@ailandmedia.com