Draft: pending legal review.
Privacy policy
Effective date: 16 July 2026 (draft)
This policy covers both this website (connota.ai) and the Connota product (app.connota.ai). It's written in plain language on purpose. If anything is unclear, ask us.
Who we are
Connota is operated by [COMPANY LEGAL NAME], [ADDRESS], registered with the Dutch Chamber of Commerce under number [KVK NUMBER]. We are the controller for the personal data described in this policy. For anything in it, email early-access@connota.ai. Privacy requests go to the same address.
What we collect
We collect only what the service needs to work:
- Account details: your name and email address.
- Brand content you upload: assets, briefings, brand documents and the knowledge you add to your Brand Brain.
- Analysis results: the findings, scores and reports generated from your content.
- Waitlist data: the email address and language preference you submit through the waitlist form.
- Usage and billing data: which features you use, your credit usage and payment records. Payments are handled by Stripe; we never see your card number.
- Technical data: server logs and error reports that help us keep the service running.
Why we use it
We use this data to:
- provide the service: running the analyses and focus-group sessions you request;
- manage your account, subscription and billing;
- tell waitlist subscribers about the launch, the only thing that address is used for;
- keep the platform secure, reliable and improving.
We do not sell personal data, and we do not use it for third-party advertising.
Our legal bases
The GDPR asks us to name a legal basis for each use. In plain words:
- Contract: running your analyses and your account is us performing our contract with you.
- Legitimate interest: keeping the service secure, monitoring errors and looking at aggregated usage statistics.
- Consent: the waitlist email; you gave it to us for exactly one purpose and can withdraw it at any time.
- Legal obligation: keeping billing records for as long as tax law requires.
Processors and subprocessors
A small set of service providers processes data on our behalf:
- Supabase: database and file storage (EU, Frankfurt); uploaded assets live in a private storage bucket
- Anthropic: AI analysis processing (United States)
- Vercel: hosting, CDN and cookieless web analytics (US company, global edge network)
- Stripe: payments (United States)
- Resend: transactional email (United States)
- Google: optional sign-in and optional Google Drive import (United States)
- Figma: optional design-file import (United States)
- Inngest: background job processing (United States)
- Sentry: error monitoring (United States)
Running an analysis means sending the content you submit (your uploaded assets and briefing text) to the Anthropic API in the United States. That is an international data transfer, and we would rather say so plainly than bury it. Our AI provider does not use this content to train its models. For transfers to US-based processors we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses, as applicable per processor.
Where your data lives
Your brand content, analyses and account data are stored in the European Union, in Frankfurt (Germany). European data residency for storage is a design decision, not an afterthought. Processing by some of the providers above happens in the United States, as described; storage itself stays in Frankfurt.
How long we keep it
Account content (your uploads, analyses and Brand Brain) is kept for the lifetime of your account and removed when you delete your account, or ask us to. Waitlist addresses are kept until launch communication is complete, or until you ask to be taken off the list. Billing records are kept as long as Dutch tax law requires (seven years). Error logs are short-lived and deleted automatically.
Your rights
Under the GDPR you can, at any time:
- access the personal data we hold about you;
- have it corrected or completed;
- have it erased;
- restrict or object to how we process it;
- receive it in a portable format;
- withdraw consent where processing is based on consent.
To exercise any of these rights, email us at early-access@connota.ai. No forms, no hoops. If you are not happy with how we handle it, you can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Automated decision-making
Connota's analyses are advisory information about creative work: they inform your judgement, they don't replace it. We make no automated decisions about people that have legal or similarly significant effects.
Children
Connota is not directed at anyone under 16, and we don't knowingly collect their data. If you believe we have, tell us and we'll delete it.
Security
Data is encrypted in transit, stored in access-controlled infrastructure, and uploaded assets sit in a private storage bucket that is never publicly reachable. Internal access follows least privilege: keys and permissions are scoped to what each part of the system actually needs. No security theatre — just the basics, done properly.
Cookies
Essential cookies only: a session cookie that keeps you signed in to the app, and a functional cookie that remembers your language preference. No analytics cookies, no advertising cookies: not on this site, not in the product. This website uses Vercel Web Analytics for aggregated, cookieless page statistics (visits, pages, referrers); it does not identify or track individual visitors.
Changes to this policy
When this policy changes, we update this page and adjust the date at the top. If a change is material, we announce it to account holders directly.
Privacy requests
For any privacy question or request, email us at early-access@connota.ai.