تخطّ إلى المحتوى
Trafikpilot

آخر تحديث: {date}

Privacy Policy

This document is a working draft under legal review. Content may change before Trafikpilot launches publicly.

كيف نجمع بياناتك ونحميها ونستخدمها.

What we collect

Account: your email, an optional display name, and (if you signed up with email + password) a hashed password. Handled by Firebase Authentication.

Profile and progress: your onboarding goal, daily practice results, streak, and bookmarks. Stored in Firestore keyed to your user ID.

Subscription: if you buy Premium, payment details are handled by Stripe and entitlement status by RevenueCat. We never see your card number.

AI Coach: your questions and our answers are logged by our AI backend so we can improve answer quality and detect abuse.

Subprocessors

We never sell your data. To operate the service we rely on the following data processors, each acting only on our instructions:

Google Cloud (Firebase Authentication, Firestore, App Check) — sign-in, your profile + progress data, and bot-protection tokens. Data is stored in the europe-west1 region (Belgium).

Stripe Payments Europe Ltd — payment processing and the Customer Portal. Data is processed in the European Economic Area; payment-card details never reach our servers.

RevenueCat, Inc. — subscription-entitlement ledger, keeping Premium status in sync between the web and our mobile apps. RevenueCat is based in the United States; see the next section for the safeguards we rely on.

Vercel — hosts the website edge and serverless functions. Acts as a transmitter; does not store your account data.

Cloudflare — content delivery + bot mitigation in front of our AI backend.

Our AI Coach backend (chat.ikorkort.ai) — operated by Corneon-AI; receives your question text + a short-lived auth token, returns the answer.

Each provider has a Data Processing Agreement in place with us; copies are available on request from support@ikorkort.ai.

International data transfers

Most of your data stays inside the European Economic Area — Firebase is configured to the europe-west1 region (Belgium) and Stripe processes payments via its Irish entity.

RevenueCat is based in the United States. Transfers to RevenueCat are made under the EU-US Data Privacy Framework (DPF), under which the U.S. provides an adequate level of protection for personal data of EU/EEA residents. The same safeguard applies to Cloudflare's U.S. operations.

You can request a copy of the relevant transfer safeguards (Standard Contractual Clauses or DPF certification) by emailing support@ikorkort.ai.

Your rights under GDPR

Under the GDPR you have the right to: access the data we hold about you, have it corrected if wrong, export it in a machine-readable format, have it erased ('right to be forgotten'), restrict or object to processing, and withdraw any consent you previously gave.

Most of these are available directly in the app: Account → Data lets you download your data, and Account → Danger Zone lets you delete your account and all associated personal data (active subscriptions are cancelled at the same time).

For any request the app doesn't surface — restriction, objection, or a copy of our records — email support@ikorkort.ai. We respond within 30 days, as required by GDPR Article 12. If you're not satisfied with our response, you can lodge a complaint with the Swedish data-protection authority Integritetsskyddsmyndigheten (IMY) at imy.se.

Cookies and browser storage

We use only the cookies and local-storage items required to run the service — sign-in, language, theme, security, payment-flow. We do not use third-party analytics or advertising cookies today.

A full inventory with each item's name, purpose and lifetime is on the Cookie Policy page.

How long we keep data

Active accounts: profile, progress, and AI-coach history live for as long as your account exists.

Account deletion: when you delete your account from Account → Danger Zone, your profile and practice data are removed immediately. Active subscriptions are cancelled at the same time.

Billing records: Stripe is required by Swedish accounting law (Bokföringslagen) to retain invoice + transaction history for 7 years, even after the customer object is deleted. We don't have a way to override that retention.

Backups: encrypted infrastructure backups may retain a deleted account for up to 30 days before they roll over.


Contact

Questions about this document? Email support@ikorkort.ai and we'll get back to you in reasonable time.