Palstora Privacy Policy
This Privacy Policy explains how Palstora collects, uses, stores, shares, and protects personal data.
Palstora is a product operated under the Palsfy brand.
The service is provided by Brian Nguyen, a Swedish sole trader, operating under the Palsfy brand (“Palstora”, “Palsfy”, “we”, “us”, or “our”).
Controller: Brian Nguyen, Swedish sole trader
Brand: Palsfy
Product: Palstora
Business address: Kemivägen 7A, Gothenburg, Sweden
Contact email: [email protected]
Website: www.palstora.com
We have not appointed a Data Protection Officer. For privacy questions or requests, contact us at [email protected].
01What Palstora does
Palstora is a home inventory and item storage management app.
Users can create workspaces, upload item photos, organize items into storage hierarchy, invite other people to shared workspaces, use AI-assisted item names, descriptions, tags, and indicative price estimates, export inventory information as CSV or PDF, and export uploaded item and container images as a ZIP file from workspaces the user owns.
Palstora is intended mainly for personal, family, household, and home inventory use. Small business use may also be possible.
02Who this policy applies to
This Privacy Policy applies to:
- account users;
- invited workspace members;
- people who receive workspace invitations;
- people who contact us for support;
- paying customers;
- website and app visitors.
Palstora accounts are intended for users who are at least 18 years old. Families may use Palstora under the responsibility of an adult account holder.
03Personal data we collect
Account data
We collect and process account data such as:
- name;
- email address;
- avatar/profile image;
- user ID;
- login and authentication information;
- social login information if you choose to sign in with a third-party login provider;
- account settings and preferences.
Authentication is provided through Clerk. We may also store parts of your profile in Supabase so the app can function correctly.
Workspace and sharing data
We collect and process workspace data such as:
- workspace name;
- workspace owner;
- workspace members;
- member roles and permissions;
- invited users’ email addresses;
- pending invites;
- invite status;
- creation records for items.
Workspace owners and admins may be able to see member email addresses and manage access depending on their role.
Pending workspace invites expire after 30 days.
Inventory and photo data
You may upload and store item data such as:
- item photos;
- compressed item photos;
- thumbnails;
- item names;
- item descriptions;
- tags;
- storage hierarchy;
- folders or categories;
- indicative price estimates;
- notes or other free-text information you choose to enter.
We store compressed versions and thumbnails of uploaded photos. We aim to strip EXIF/photo metadata, such as embedded camera metadata or GPS metadata, before storage.
We only support photo uploads. We do not intend Palstora to be used for uploading sensitive documents.
Because item names, descriptions, storage hierarchy, and notes are free-text fields, you may choose to enter personal data there. You should avoid entering sensitive personal data, private documents, identity documents, medical information, financial information, legal documents, or other people’s private information.
AI-generated data
Palstora uses Google Cloud Gemini Enterprise Agent Platform and Gemini models to generate AI-assisted:
- item names;
- item descriptions;
- tags;
- indicative price estimates.
AI may run automatically after upload, when you request it, or both.
We do not store the full AI prompt/request in Supabase. We store AI outputs such as the generated title, description, tags, and indicative price estimate.
We do not use your photos or inventory content to train Palstora-owned AI models. Our AI provider states that customer data is not used to train or fine-tune AI/ML models without prior permission or instruction. Some limited processing, retention, caching, or abuse-monitoring measures may still apply depending on the Google Cloud configuration and service terms.
We do not use Google Search grounding, Google Maps grounding, or external search sources for price estimation.
Payment and subscription data
If you purchase a subscription, payments are processed by Stripe.
We may store:
- your plan;
- subscription status;
- Stripe customer ID;
- Stripe subscription ID;
- payment status;
- relevant subscription timestamps.
We do not store full card numbers or CVC codes. Billing address, tax details, and payment method details are processed by Stripe.
Stripe may send receipts, invoices, or payment-related emails depending on our Stripe settings.
If you downgrade your plan, cancel, or lose access to a paid subscription, some items, photos, AI outputs, or storage hierarchy entries may exceed the limits of your new plan. Content beyond the limits of your active plan may be hidden, disabled, or marked for deletion. We keep this excess content for up to 90 days to give you time to upgrade, export, or delete content. After that period, we may permanently delete excess content.
Email and communication data
We use Resend for transactional emails, such as:
- workspace invitations;
- account notifications;
- service notifications;
- security notices;
- billing-related notices.
Transactional emails may include your email address, delivery metadata, and the content of the email. We avoid including sensitive inventory details in emails.
We may send marketing emails or newsletters only if you opt in. You can unsubscribe from marketing emails at any time.
We use Zoho for email inboxes and support communication. If you email [email protected], your email address, message content, and any information you include in the message may be processed through Zoho.
Logs, security, and technical data
We process technical data needed to operate and secure the service, such as:
- device and browser information;
- request metadata;
- security events;
- server logs;
- authentication logs;
- Cloudflare and Hetzner technical logs;
- Clerk authentication/security logs;
- approximate technical location information where generated by infrastructure providers.
We do not store full IP addresses in Supabase as part of normal app data. However, providers such as Cloudflare, Hetzner, Clerk, Stripe, and other infrastructure providers may process IP addresses and technical request metadata for security, fraud prevention, routing, logging, and service operation.
We do not use Google Analytics, Meta Pixel, marketing pixels, PostHog, Plausible, Sentry, or other product analytics tools at this time.
We may use Cloudflare security features. We do not use Cloudflare analytics as a product analytics tool.
04Why we process personal data and our legal bases
We process personal data for the following purposes:
| Purpose | Examples of data | Legal basis |
|---|---|---|
| Provide the Palstora service | account, profile, workspace, inventory, photos, AI outputs, sharing data | performance of a contract |
| Authenticate users | email, name, avatar, login data, session data | performance of a contract; legitimate interests for security |
| Store and organize inventory | photos, item data, storage data, workspace data | performance of a contract |
| Generate AI suggestions | photos, item data, generated titles, descriptions, tags, price estimates | performance of a contract |
| Enable workspace sharing | member emails, roles, invites, permissions | performance of a contract; legitimate interests |
| Process subscriptions and payments | plan, Stripe IDs, payment status | performance of a contract; legal obligation for accounting/tax records |
| Send transactional emails | email address, invite and account messages | performance of a contract; legitimate interests |
| Send marketing emails | email address, marketing preferences | consent |
| Provide support | email address, support messages, issue details | performance of a contract; legitimate interests |
| Secure and protect the service | logs, technical metadata, security events | legitimate interests |
| Meet legal and accounting obligations | invoices, payment records, legal records | legal obligation |
| Provide export and data portability features | inventory records, uploaded photos, export job metadata, temporary ZIP files, signed download links | performance of a contract; legal obligation or legitimate interests when responding to privacy or data protection requests |
| Handle disputes or legal claims | relevant account, billing, communication, and security records | legitimate interests; legal claims |
Our legitimate interests include operating a secure service, preventing abuse and fraud, troubleshooting issues, improving reliability, enforcing our terms, and protecting users and workspaces.
Where we rely on consent, such as for marketing emails, you can withdraw consent at any time.
05AI processing and automated processing
Palstora uses AI to help generate item names, descriptions, tags, and indicative price estimates.
AI outputs are suggestions only. They may be inaccurate, incomplete, or unsuitable for your situation.
Palstora does not make automated decisions that produce legal effects or similarly significant effects about you. The AI does not decide whether you receive insurance, credit, employment, public benefits, or any similar right or service.
You can edit AI-generated names, descriptions, tags, and price estimates.
07Sensitive data
Palstora is not intended for sensitive personal data.
You should not upload or enter:
- passports;
- national ID documents;
- bank records;
- medical records;
- legal documents;
- documents containing other people’s private information;
- photos that clearly identify people unless you have permission;
- information about health, religion, politics, sexuality, criminal offences, or similar sensitive topics.
We do not routinely review user uploads. If we become aware of content that creates legal, security, privacy, or safety risk, we may remove or restrict it.
09International transfers
We are based in Sweden and aim to use EU-region infrastructure where practical.
However, some providers may process personal data outside Sweden, the EU, or the EEA. This may include processing in the United States or other countries where our providers or their subprocessors operate.
Where required, transfers are handled using safeguards such as:
- adequacy decisions;
- the EU-U.S. Data Privacy Framework where applicable;
- Standard Contractual Clauses;
- data processing agreements;
- vendor security and privacy terms.
Do not assume that all Palstora data stays only in Sweden or only in the EU/EEA.
10How long we keep data
We keep personal data only as long as needed for the purposes described in this policy, unless a longer period is required or permitted for legal, accounting, tax, security, fraud prevention, dispute, or legal-claim reasons.
| Data | Retention |
|---|---|
| Account and profile data | until account deletion, unless limited records must be retained |
| Workspace membership data | until removed from the workspace, account deletion, or workspace deletion |
| Private workspace data | until the workspace or account is deleted |
| Shared workspace content | until the workspace owner deletes it or the workspace is deleted |
| Item photos, compressed images, and thumbnails | until the item, workspace, or relevant account is deleted |
| AI-generated titles, descriptions, tags, and price estimates | until the item, workspace, or relevant account is deleted |
| Content exceeding downgraded plan limits (items, photos, thumbnails, AI outputs) | up to 90 days after downgrade before permanent deletion, unless you upgrade or delete it earlier |
| Item creation records | until the item is deleted; creator attribution is anonymized when the user account is deleted |
| Pending invites | 30 days unless accepted, revoked, or deleted earlier |
| Marketing email consent | until withdrawn or no longer needed |
| Marketing suppression/unsubscribe records | as needed to respect opt-outs |
| Support emails | up to 2 years unless needed longer for legal, security, billing, or dispute reasons |
| Security and server logs | up to 90 days unless needed longer for security, fraud prevention, legal obligations, or disputes |
| Database backups | approximately 7 days |
| Billing and payment records | as required for accounting, tax, chargebacks, fraud prevention, disputes, and legal obligations |
| Image export ZIP files | available for 7 days after generation, then automatically deleted from live storage by daily cleanup; may remain in database backups for up to the backup retention period |
| Image export job metadata | until account deletion or as needed for privacy request records, security, or legal obligations |
When data is deleted from live systems, it may remain in backups until the backup retention period expires.
11Account, item, and workspace deletion
You can delete your account from account settings where available or by contacting [email protected].
When you delete your account, we delete or anonymize your personal account data from live systems as soon as reasonably practical.
Account deletion permanently deletes all workspaces you own and removes your membership from workspaces owned by others. Associated Palstora subscriptions are cancelled where technically possible.
If you delete an item, its associated photo, compressed image, thumbnail, AI outputs, and item data are deleted from live systems.
If you delete a workspace, its items, photos, AI outputs, storage hierarchy, invites, memberships, and related data are deleted from live systems.
If you downgrade or cancel your plan, content that exceeds the limits of your active plan may be hidden, disabled, or marked for deletion. We keep this excess content for up to 90 days before permanent deletion to give you time to upgrade, export, or delete content during that period.
If you are a member of another user’s workspace, deleting your account removes your access but does not automatically delete the workspace or its content. Content you contributed may remain for the workspace owner and other members, with your personal attribution anonymized where practical.
Some limited records may be retained where needed for billing, accounting, tax, security, fraud prevention, dispute handling, legal obligations, or legal claims.
12Your privacy rights
Depending on where you live, you may have rights to:
- access your personal data;
- receive a copy of your personal data;
- correct inaccurate data;
- delete your data;
- restrict processing;
- object to processing;
- withdraw consent where processing is based on consent;
- request data portability;
- complain to a data protection authority.
You can export your inventory data through self-service exports. Palstora supports inventory export formats such as CSV and PDF, and a separate image export as a ZIP file containing uploaded item and container images from workspaces you own. Image export is subject to fair-use limits: one request every 7 days, each export is available for 7 days, and each export can generate up to 3 short-lived download links. Each signed download link expires after 10 minutes. A signed link may be reused during its expiry, so the limit applies to link generation, not guaranteed completed downloads.
You can edit AI-generated names, descriptions, tags, and price estimates.
To exercise your rights or for legal, privacy, and data protection requests, contact us at [email protected]. For support or technical help with exports, contact [email protected].
We normally respond to privacy requests within one month. If a request is complex or we receive many requests, we may need more time, where allowed by law. We may ask you to verify your identity before responding.
13Complaints
If you are in Sweden, you can contact the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, if you believe we have handled your personal data incorrectly.
If you live outside Sweden, you may also have the right to contact your local data protection authority.
We would appreciate the chance to address your concern first. You can contact us at [email protected].
14Security
We use technical and organizational measures designed to protect personal data, including:
- authentication through Clerk;
- private storage and access controls;
- server-side AI processing;
- encrypted connections where supported;
- restricted administrator access;
- infrastructure security controls;
- security logging;
- backup and recovery processes.
No online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials safe and for inviting only people you trust to your workspaces.
16Marketing emails
We may send marketing emails only if you opt in.
You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting [email protected].
Even if you unsubscribe from marketing emails, we may still send necessary service emails, such as account, security, workspace, billing, or legal notices.
17Children and families
Palstora accounts are intended for users who are at least 18 years old.
Parents or legal guardians may allow family members to participate under the adult’s responsibility.
We do not knowingly allow children to create their own Palstora accounts. If you believe a child has created an account or provided personal data without appropriate permission, contact us at [email protected].
18Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will provide reasonable notice, such as by email, in-app notice, or requiring renewed acceptance where appropriate.
The latest version will be available at www.palstora.com.
19Contact
For privacy questions, requests, or complaints, contact:
Palstora
A product operated under the Palsfy brand
Provided by Brian Nguyen, Swedish sole trader
Business address: Kemivägen 7A, Gothenburg, Sweden
Email: [email protected]
Website: www.palstora.com
Palstora Privacy Policy 1.0 · Effective July 5, 2026