Legal
Privacy Policy
What data PV0T collects, why, who we share it with, and the rights you have over it.
1. Who we are
PV0T OÜ (“PV0T,” “we,” “us,” or “our”) is a private limited company registered in Estonia (registry code 17468061, VAT number EE102970834), with its registered address at Järvevana tee 9, 11314 Tallinn, Estonia. We are the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and other applicable data protection law.
Contact us about privacy matters at contact@pv0t.com.
2. Scope
This Privacy Policy applies to pv0t.com and the PV0T application (together, the “Service”), including our AI assistant feature, FLCRUM.
3. What data we collect
| Category | Examples | Why we collect it |
|---|---|---|
| Account & identity | Name, date of birth, username, email address, avatar | To create and operate your account |
| Session & device | IP address, approximate location (city/region/country), device and browser type | Security — shown in your account’s session list so you can spot unrecognized logins |
| Authentication | Two-factor recovery codes (stored as one-way hashes); access tokens for services you connect (Notion, Google Calendar) | To secure your account and operate integrations you turn on |
| FLCRUM conversations | Messages you send to FLCRUM, commitments you mention, monthly usage counts | To provide the AI assistant feature (Section 5) |
| Productivity data | Time tracked on tasks, session activity, and — if you enable it — time spent away from a tracked task, with any reason you choose to give | To power your dashboards, analytics, and history |
| Your content | Notes, pages, planner items, and other content you create | To store and display what you create |
| Support requests | Anything in a support message, bug report, or content report, including your email and, for content reports, any screenshots you attach | To respond to you and investigate reports |
| Billing | Your plan, seat count, and billing sync status | To keep your subscription state accurate (Section 7.1) |
We do not process or store your payment card details or tax identification numbers ourselves — billing is handled entirely by Polar (Section 7.1).
4. Our legal basis for processing
- Performance of a contract — account data, your content, and billing data, to provide the Service you signed up for.
- Legitimate interests — session/device data for account security; aggregated usage for improving the Service.
- Consent — analytics cookies (Section 6); you can withdraw consent at any time.
- Legal obligation — billing records we’re required to keep for tax purposes.
5. FLCRUM, our AI assistant
When you use FLCRUM:
- Your messages, along with contextual information from your account — your name, email, workspace role, subscription plan, recent performance statistics, date of birth, active commitments you’ve mentioned, and (if connected) your upcoming Google Calendar events — are sent to OpenRouter, a third-party AI infrastructure provider, which routes the request to an underlying language model to generate FLCRUM’s response.
- This happens every time you send FLCRUM a message. FLCRUM does not retain memory with the model provider between requests — we resend your conversation history each time from our own records (or from your browser, if you’re using FLCRUM outside a workspace).
- FLCRUM can take actions in your account — for example, creating or deleting items and notes, updating your calendar, or inviting a workspace member — but only when you explicitly ask it to. You remain responsible for reviewing what FLCRUM does on your behalf; every action it takes is visible in your account afterward.
- If you’re using FLCRUM inside a workspace, your conversations are stored on our servers (Section 9). Outside a workspace (“personal” mode), your conversation history is stored only in your browser and isn’t sent to our servers.
- We don’t use your conversations to train our own AI models. Every request to OpenRouter explicitly instructs it to route only to providers that don’t collect or train on your data — this isn’t just an account setting, it’s enforced on every individual request.
- FLCRUM is not a substitute for professional advice (legal, medical, financial, or otherwise), and its responses may be inaccurate. Please don’t enter highly sensitive information — such as government ID numbers, medical records, or financial account credentials — into FLCRUM; it’s built for productivity, not for handling that category of data.
8. International data transfers
Our database, authentication, and file storage (Supabase) are hosted in the EU (Frankfurt, Germany). Where a provider listed in Section 7 processes data outside the EU/EEA, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as required by GDPR.
OpenRouter is based in the United States. As a commercial customer, our use of OpenRouter is governed by OpenRouter’s Data Processing Agreement, incorporated by reference into our agreement with them, which itself relies on Standard Contractual Clauses for transfers outside the EU. Every request also independently restricts processing to providers that don’t collect or train on your data (Section 5); we’re additionally moving FLCRUM’s requests to OpenRouter’s EU in-region routing, which processes requests entirely within the EU, once that’s enabled for our account.
9. How long we keep your data
We keep your data for as long as your account is active. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we’re legally required or permitted to retain it — for example, billing records for tax purposes, or reports about you that another user has filed, which we keep in de-identified form.
Within an active account, conversations and other activity data are subject to a retention window (180 days for conversations, 360 days for other tracked items, by default), which you or your workspace owner can configure from Settings → Data & Privacy, where you can also see which of your items currently fall outside that window.
10. Your rights
If you’re in the EU/EEA (or another jurisdiction with similar rights), you can:
- Access the personal data we hold about you.
- Correct inaccurate data — most of it directly in your account settings.
- Delete your account and data.
- Export your data in a portable format.
- Object to or restrict certain processing, including profiling.
- Withdraw consent for anything we process on that basis, at any time.
Exercise the first four rights directly from Settings → Data & Privacy. Your export covers your content, conversations, reports, workspaces, feedback, integrations you’ve connected, and account/session activity; it deliberately leaves out a small number of items for your own security (live connection tokens and session-security hashes), which the export file itself lists. For anything else, email contact@pv0t.com — we’ll respond within one month, as GDPR requires.
Looking for a quick summary instead? See Your Privacy Rights.
11. Automated decision-making
FLCRUM can take actions in your account, but only ones you explicitly ask for — it doesn’t independently decide to do something about your account without your instruction. We don’t use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.
12. Children’s privacy
The Service isn’t directed at, and isn’t intended for, anyone under 16. We enforce this age minimum when you create an account and if you later update your date of birth.
13. Security
We use industry-standard technical and organizational measures to protect your data, including encryption in transit, database-level access controls, optional two-factor authentication, and EU-based infrastructure with the security practices our hosting provider applies at the platform level.
14. Changes to this policy
We’ll post any changes here and update the “Last updated” date above. If a change is material, we’ll notify you by email or through the Service.