Skip to legal content
Recallora Back to home
Beta legal draft

Privacy notice

This pre-launch draft explains the product's data and usage boundaries. Recallora must not enter commercial release until the legal entity name, address, and authorised contact details are added.

1. What data do we process?

We process account and security information, verified business context and product or service catalogue entries, reusable brand-reference images, plans, directives, content revisions and media created inside Recallora, owner-reported performance metrics, social-account references and capability metadata, as well as credit, subscription, and transaction records. Adding a username does not import old posts. If a provider connection is later enabled, requested scopes and token-secret references are handled separately and are not exposed to the browser.

2. Use of artificial intelligence

Recallora may use the configured AI provider for plan and copy generation, Google Gemini Nano Banana 2 for images, and Google Veo for video. Only the context needed to complete the request is sent to the provider. If you provide a website, a limited number of pages on the same domain may be read securely. Business facts inferred by AI do not enter verified memory until you approve them.

3. Purpose and legal basis

Data is processed to provide the service, protect your account, generate the content you request, prepare reminders and share packages, and retain required transaction records. Final GDPR and local-law bases will be completed with legal counsel after the service entity and launch markets are confirmed.

4. Retention, export, and deletion

You can export your data and initiate a deletion request from your account. Starting a request does not mean data is deleted automatically. The current version moves the request to a manual-review state after a seven-day waiting period; it does not remove data or mark the request complete by itself. Data is not deleted until identity, scope, and applicable retention duties are reviewed. Limited security, accounting, or legally required records may be retained for the applicable period.

5. Security

Sessions use secure, HTTP-only cookies. Business data is separated by workspace boundaries, and critical operations may require reauthentication and immutable audit records. No internet service can guarantee absolute security.

6. Contact and rights

The controller/processor role, contact address, subprocessors, international-transfer mechanism, and rights-request process will be added before commercial launch.