Privacy Policy
This draft has not yet been published — no effective date has been set.
Draft notice: this page is a working draft, not a reviewed legal document. The bracketed placeholder (operating entity, registered address) needs real information — and this notice removed — before Pinevon or Anchor is offered to real customers. It has not been reviewed by a lawyer, and does not yet cover jurisdiction-specific obligations (e.g. GDPR/CCPA data-subject request mechanics) beyond the general description below.
1. Who this policy covers
This policy is issued by [Pinevon legal entity name and jurisdiction — same value as the Terms of Service] for pinevon.com and its product Anchor (together, the "Service"). It covers anyone who creates a Pinevon account, browses this site, or talks to the Pinevon Assistant chat widget.
2. What we collect
- Account data: email address and authentication credentials, handled by Supabase Auth — we never see or store your raw password.
- Profile data: display name and avatar, if you choose to add them.
- Contact form submissions: whatever you enter (name, email, phone, company, message, category, and an optional attachment) is sent to our team by email; it is not stored in a database beyond what your own email provider retains.
- Chat widget conversations: messages you send to the Pinevon Assistant are sent to a third-party AI provider (below) to generate a response. They are not currently stored in a database on our side.
- Basic page-view analytics: which page was visited, the referring page, and a coarse device/country signal — recorded without cookies or any identifier tied to you across visits. See §9.
3. How we use it
To provide the Service: authenticate you, remember your profile, respond to contact-form messages, answer questions through the chat widget, and understand which pages are actually being used so we can improve them. We do not sell your data or use it for third-party advertising.
4. AI processing, specifically
When you send a message to the Pinevon Assistant, that message (plus recent conversation context, capped at the last 20 messages) is sent to whichever configured AI provider is available at the time — Anthropic, OpenAI, Google Gemini, or Groq — to generate a reply. Each provider processes the request under its own API terms. We don't send your account data or unrelated browsing history along with a chat message, only the conversation itself.
5. Who we share data with
We use the following sub-processors to run the Service. None of them are permitted to use your data for their own purposes.
We don't sell your data to third parties, and we don't share it for anyone else's advertising purposes.
6. Data retention and deletion
We retain your account data for as long as your account is active. If you close your account, we delete your profile data within a reasonable period, except where we're required to retain records for legal or accounting reasons. [Set an exact retention window here once decided — e.g. "30 days after account closure."]
7. Security
Authentication and password storage are handled entirely by Supabase Auth — we never see or store a raw password. Secrets and API keys are never bundled into frontend code. See Anchor's security page for the technical detail behind the product itself.
8. Your rights
You can view and update your profile from your account page at any time, or contact us to access, correct, or delete your data.
9. Cookies and analytics
This site uses one essential, functional cookie (issued by Supabase Auth) to keep you signed in — nothing else is stored client-side to identify you. Page-view analytics are collected without cookies, without a persistent visitor ID, and without any tracking across other sites: we record the page, the referrer, and a coarse country/device signal, and nothing that identifies you personally. Because no non-essential or tracking cookie is set, no cookie-consent banner is shown.
10. Children's privacy
The Service is intended for business use and isn't directed at children. We don't knowingly collect data from children under 13 (or the relevant local minimum age).
11. Changes to this policy
We may update this policy as the Service evolves. We'll post the updated version here with a new effective date.
12. Contact
Questions about this policy, or a data request: privacy@pinevon.com