Privacy Policy

Effective Date: March 19, 2025

Last Updated: April 07, 2025

1. Information We Collect

1.1 Information You Provide to Us

  • Account Information: When you sign up for shellA, we collect your email address and billing details for account management and customer support.
  • Support Inquiries: If you contact us, we may store your messages and contact details to assist you.

1.2 Information We Automatically Collect

  • Usage Data: We collect telemetry and analytics on how you use shellA, including feature engagement, interaction events, and performance diagnostics. This may include anonymized metadata and logs.
  • Device & Log Data: We collect device identifiers, operating system version, time zone, and system logs to improve performance and security.

1.3 Data We Do Not Store Permanently

  • shellA does not permanently store user-generated content such as chat messages or file contents in a database.
  • Full file structures-shellA only processes them temporarily in memory.
  • OpenAI API responses-data is transmitted securely to OpenAI for processing and discarded after response.

2. How We Use Your Information

  • Provide, maintain, and improve the functionality of shellA.
  • Authenticate logins through third-party providers (e.g., Google, Microsoft Entra).
  • Manage subscriptions and process payments via Stripe.
  • Monitor and enhance performance, security, and reliability.
  • Respond to customer support inquiries.
  • Comply with legal obligations.

3. How We Share Your Information

3.1 Third-Party Services

  • Authentication Providers: Login is handled via Google and Microsoft Entra. We do not access or store passwords.
  • Payment Processors: Stripe securely handles all payment and billing data. ByteSpell does not store payment card details.
  • AI Processing: OpenAI processes user input and metadata. Their Data Processing Addendum applies.
  • Infrastructure & Hosting: We use Vercel and Google Cloud services to host and deploy shellA.
  • Logging & Monitoring: Logs may be sent to cloud monitoring services for error tracking and uptime assurance.

3.2 Legal & Compliance

  • To comply with applicable laws and law enforcement requests.
  • To protect the safety and rights of ByteSpell, users, or the public.

4. Data Security & Retention

4.1 Security Measures

  • Encryption in transit for all network communications.
  • Access control for infrastructure and administrative systems.
  • Regular audits and vulnerability scanning.

4.2 Retention

  • Email and billing info are retained while the account is active.
  • Inactive accounts may be deleted after 24 months.
  • Log data may be stored temporarily for troubleshooting and analytics.

5. Your Rights & Choices

If you reside in the EU, UK, or a jurisdiction with data protection laws, you have rights including:

  • Right to access or correct your personal data
  • Right to request deletion (right to be forgotten)
  • Right to object to processing or withdraw consent
  • Right to export your data
  • Right to file a complaint with your local authority

6. International Data Transfers

We operate in and process data in the United States. By using shellA, you consent to transferring your data to the U.S. We rely on standard contractual clauses or your explicit consent when applicable.

7. Legal Bases for Processing

We process your data based on:

  • Consent when you use the Service or opt in to communications
  • Performance of a contract when you sign up for shellA
  • Legal obligations and compliance requirements
  • Legitimate interests like platform integrity and improvement

8. Data Processor Agreements (DPAs)

We have entered into Data Processing Agreements with OpenAI, Stripe, and other third parties to ensure their compliance with GDPR and to safeguard personal data shared with them during service operation.

9. Children’s Privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal information from minors.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Major updates will be communicated through the app or by email. Continued use of shellA after such changes constitutes acceptance.

11. Contact

For privacy questions, requests, or GDPR-related inquiries, contact:

ashley@bytespell.com

© 2025 ByteSpell. All rights reserved.