RGPD / GDPR
Privacy policy
2026-08 · The Spanish version governs where both exist.
The short version
We cannot read your chats. Conversation content is encrypted on your device before it syncs, and our servers store only ciphertext they cannot open. We keep no plaintext logs. There is nothing to sell, subpoena, or leak.
Controller
Demimonde S.L., CIF [CIF], [ADDRESS], Spain. Contact for data protection matters: privacy@demimonde.dev. You may complain to the AEPD (agpd.es) at any time.
What we process and why
Account metadata (random identifiers, tier, timestamps) — performance of the contract (Art. 6.1.b).
Usage metering (token counts, latency, status codes; no content) — billing and abuse prevention, legitimate interest (Art. 6.1.f).
Optional email, if you provide it — consent (Art. 6.1.a), for receipts and security notices only.
Encrypted sync blobs — these leave our systems as opaque ciphertext; we are effectively a processor without the key.
Processors
Hosting and database: Vercel / Neon (EU regions where offered). Inference: RunPod (EU region pinned). Payments: Stripe and a crypto payment gateway. Email: Resend. A current list with DPA status is maintained at /legal/en/privacy and updated within 30 days of any change.
International transfers outside the EEA are covered by Standard Contractual Clauses where applicable.
Retention
Session metadata: 30 days after expiry. Usage events: 24 months for accounting. Billing records: the statutory period (6 years, Spanish mercantile law). Sync blobs: until you delete them or trigger a panic wipe. Hashed credentials: until account deletion.
Your rights
Access, rectification, erasure, restriction, portability and objection — exercisable from Settings (export and erase are self-service and immediate) or by writing to privacy@demimonde.dev. We respond within 30 days.
The delete button actually deletes: sessions are revoked, blobs hard-deleted, and only legally-required billing tombstones survive.
Breach notification
In the event of a personal data breach we notify the AEPD within 72 hours and affected users without undue delay where risk is high.