Back to Home
Legal

Privacy Policy

Effective date: July 5, 2026 · Version: 1.0

Palstora Privacy Policy

This Privacy Policy explains how Palstora collects, uses, stores, shares, and protects personal data.

Palstora is a product operated under the Palsfy brand.

The service is provided by Brian Nguyen, a Swedish sole trader, operating under the Palsfy brand (“Palstora”, “Palsfy”, “we”, “us”, or “our”).

Controller: Brian Nguyen, Swedish sole trader
Brand: Palsfy
Product: Palstora
Business address: Kemivägen 7A, Gothenburg, Sweden
Contact email: [email protected]
Website: www.palstora.com

We have not appointed a Data Protection Officer. For privacy questions or requests, contact us at [email protected].


01What Palstora does

Palstora is a home inventory and item storage management app.

Users can create workspaces, upload item photos, organize items into storage hierarchy, invite other people to shared workspaces, use AI-assisted item names, descriptions, tags, and indicative price estimates, export inventory information as CSV or PDF, and export uploaded item and container images as a ZIP file from workspaces the user owns.

Palstora is intended mainly for personal, family, household, and home inventory use. Small business use may also be possible.


02Who this policy applies to

This Privacy Policy applies to:

  • account users;
  • invited workspace members;
  • people who receive workspace invitations;
  • people who contact us for support;
  • paying customers;
  • website and app visitors.

Palstora accounts are intended for users who are at least 18 years old. Families may use Palstora under the responsibility of an adult account holder.


03Personal data we collect

Account data

We collect and process account data such as:

  • name;
  • email address;
  • avatar/profile image;
  • user ID;
  • login and authentication information;
  • social login information if you choose to sign in with a third-party login provider;
  • account settings and preferences.

Authentication is provided through Clerk. We may also store parts of your profile in Supabase so the app can function correctly.

Workspace and sharing data

We collect and process workspace data such as:

  • workspace name;
  • workspace owner;
  • workspace members;
  • member roles and permissions;
  • invited users’ email addresses;
  • pending invites;
  • invite status;
  • creation records for items.

Workspace owners and admins may be able to see member email addresses and manage access depending on their role.

Pending workspace invites expire after 30 days.

Inventory and photo data

You may upload and store item data such as:

  • item photos;
  • compressed item photos;
  • thumbnails;
  • item names;
  • item descriptions;
  • tags;
  • storage hierarchy;
  • folders or categories;
  • indicative price estimates;
  • notes or other free-text information you choose to enter.

We store compressed versions and thumbnails of uploaded photos. We aim to strip EXIF/photo metadata, such as embedded camera metadata or GPS metadata, before storage.

We only support photo uploads. We do not intend Palstora to be used for uploading sensitive documents.

Because item names, descriptions, storage hierarchy, and notes are free-text fields, you may choose to enter personal data there. You should avoid entering sensitive personal data, private documents, identity documents, medical information, financial information, legal documents, or other people’s private information.

AI-generated data

Palstora uses Google Cloud Gemini Enterprise Agent Platform and Gemini models to generate AI-assisted:

  • item names;
  • item descriptions;
  • tags;
  • indicative price estimates.

AI may run automatically after upload, when you request it, or both.

We do not store the full AI prompt/request in Supabase. We store AI outputs such as the generated title, description, tags, and indicative price estimate.

We do not use your photos or inventory content to train Palstora-owned AI models. Our AI provider states that customer data is not used to train or fine-tune AI/ML models without prior permission or instruction. Some limited processing, retention, caching, or abuse-monitoring measures may still apply depending on the Google Cloud configuration and service terms.

We do not use Google Search grounding, Google Maps grounding, or external search sources for price estimation.

Payment and subscription data

If you purchase a subscription, payments are processed by Stripe.

We may store:

  • your plan;
  • subscription status;
  • Stripe customer ID;
  • Stripe subscription ID;
  • payment status;
  • relevant subscription timestamps.

We do not store full card numbers or CVC codes. Billing address, tax details, and payment method details are processed by Stripe.

Stripe may send receipts, invoices, or payment-related emails depending on our Stripe settings.

If you downgrade your plan, cancel, or lose access to a paid subscription, some items, photos, AI outputs, or storage hierarchy entries may exceed the limits of your new plan. Content beyond the limits of your active plan may be hidden, disabled, or marked for deletion. We keep this excess content for up to 90 days to give you time to upgrade, export, or delete content. After that period, we may permanently delete excess content.

Email and communication data

We use Resend for transactional emails, such as:

  • workspace invitations;
  • account notifications;
  • service notifications;
  • security notices;
  • billing-related notices.

Transactional emails may include your email address, delivery metadata, and the content of the email. We avoid including sensitive inventory details in emails.

We may send marketing emails or newsletters only if you opt in. You can unsubscribe from marketing emails at any time.

We use Zoho for email inboxes and support communication. If you email [email protected], your email address, message content, and any information you include in the message may be processed through Zoho.

Logs, security, and technical data

We process technical data needed to operate and secure the service, such as:

  • device and browser information;
  • request metadata;
  • security events;
  • server logs;
  • authentication logs;
  • Cloudflare and Hetzner technical logs;
  • Clerk authentication/security logs;
  • approximate technical location information where generated by infrastructure providers.

We do not store full IP addresses in Supabase as part of normal app data. However, providers such as Cloudflare, Hetzner, Clerk, Stripe, and other infrastructure providers may process IP addresses and technical request metadata for security, fraud prevention, routing, logging, and service operation.

We do not use Google Analytics, Meta Pixel, marketing pixels, PostHog, Plausible, Sentry, or other product analytics tools at this time.

We may use Cloudflare security features. We do not use Cloudflare analytics as a product analytics tool.


05AI processing and automated processing

Palstora uses AI to help generate item names, descriptions, tags, and indicative price estimates.

AI outputs are suggestions only. They may be inaccurate, incomplete, or unsuitable for your situation.

Palstora does not make automated decisions that produce legal effects or similarly significant effects about you. The AI does not decide whether you receive insurance, credit, employment, public benefits, or any similar right or service.

You can edit AI-generated names, descriptions, tags, and price estimates.


06Workspaces and shared content

Workspace owners control their workspaces.

If you add content to a workspace owned by someone else, that content may remain available to the workspace owner and authorized members even if you later delete your account.

When a member deletes their account, we remove or anonymize their personal attribution where practical. For example, an item may remain in the workspace, but the creator may be shown internally or technically as a deleted or anonymized user.

If you delete your account, all workspaces you own, including shared workspaces, are permanently deleted with their contents.

If you are a member of workspaces owned by others, account deletion removes your access but does not delete those workspaces.


07Sensitive data

Palstora is not intended for sensitive personal data.

You should not upload or enter:

  • passports;
  • national ID documents;
  • bank records;
  • medical records;
  • legal documents;
  • documents containing other people’s private information;
  • photos that clearly identify people unless you have permission;
  • information about health, religion, politics, sexuality, criminal offences, or similar sensitive topics.

We do not routinely review user uploads. If we become aware of content that creates legal, security, privacy, or safety risk, we may remove or restrict it.


08Who we share data with

We use service providers to operate Palstora. These providers process personal data only as needed to provide their services to us, subject to their contracts and legal terms.

Current providers include:

ProviderPurpose
Clerkauthentication and user/session management
Supabasedatabase, file storage, and application data
Google CloudAI processing through Gemini Enterprise Agent Platform and Gemini models
Cloudflaresecurity, CDN, routing, and technical protection
Hetznerhosting infrastructure
Resendtransactional emails
Stripepayments and subscriptions
Zohosupport email inboxes and business email
Social login providersauthentication, if you choose social login

We may also share personal data where necessary to:

  • comply with law;
  • respond to lawful requests;
  • protect our rights, users, or service;
  • investigate fraud, abuse, or security incidents;
  • handle disputes or legal claims;
  • complete a business transfer, merger, restructuring, or sale of assets, if that ever occurs.

We do not sell personal data.


09International transfers

We are based in Sweden and aim to use EU-region infrastructure where practical.

However, some providers may process personal data outside Sweden, the EU, or the EEA. This may include processing in the United States or other countries where our providers or their subprocessors operate.

Where required, transfers are handled using safeguards such as:

  • adequacy decisions;
  • the EU-U.S. Data Privacy Framework where applicable;
  • Standard Contractual Clauses;
  • data processing agreements;
  • vendor security and privacy terms.

Do not assume that all Palstora data stays only in Sweden or only in the EU/EEA.


10How long we keep data

We keep personal data only as long as needed for the purposes described in this policy, unless a longer period is required or permitted for legal, accounting, tax, security, fraud prevention, dispute, or legal-claim reasons.

DataRetention
Account and profile datauntil account deletion, unless limited records must be retained
Workspace membership datauntil removed from the workspace, account deletion, or workspace deletion
Private workspace datauntil the workspace or account is deleted
Shared workspace contentuntil the workspace owner deletes it or the workspace is deleted
Item photos, compressed images, and thumbnailsuntil the item, workspace, or relevant account is deleted
AI-generated titles, descriptions, tags, and price estimatesuntil the item, workspace, or relevant account is deleted
Content exceeding downgraded plan limits (items, photos, thumbnails, AI outputs)up to 90 days after downgrade before permanent deletion, unless you upgrade or delete it earlier
Item creation recordsuntil the item is deleted; creator attribution is anonymized when the user account is deleted
Pending invites30 days unless accepted, revoked, or deleted earlier
Marketing email consentuntil withdrawn or no longer needed
Marketing suppression/unsubscribe recordsas needed to respect opt-outs
Support emailsup to 2 years unless needed longer for legal, security, billing, or dispute reasons
Security and server logsup to 90 days unless needed longer for security, fraud prevention, legal obligations, or disputes
Database backupsapproximately 7 days
Billing and payment recordsas required for accounting, tax, chargebacks, fraud prevention, disputes, and legal obligations
Image export ZIP filesavailable for 7 days after generation, then automatically deleted from live storage by daily cleanup; may remain in database backups for up to the backup retention period
Image export job metadatauntil account deletion or as needed for privacy request records, security, or legal obligations

When data is deleted from live systems, it may remain in backups until the backup retention period expires.


11Account, item, and workspace deletion

You can delete your account from account settings where available or by contacting [email protected].

When you delete your account, we delete or anonymize your personal account data from live systems as soon as reasonably practical.

Account deletion permanently deletes all workspaces you own and removes your membership from workspaces owned by others. Associated Palstora subscriptions are cancelled where technically possible.

If you delete an item, its associated photo, compressed image, thumbnail, AI outputs, and item data are deleted from live systems.

If you delete a workspace, its items, photos, AI outputs, storage hierarchy, invites, memberships, and related data are deleted from live systems.

If you downgrade or cancel your plan, content that exceeds the limits of your active plan may be hidden, disabled, or marked for deletion. We keep this excess content for up to 90 days before permanent deletion to give you time to upgrade, export, or delete content during that period.

If you are a member of another user’s workspace, deleting your account removes your access but does not automatically delete the workspace or its content. Content you contributed may remain for the workspace owner and other members, with your personal attribution anonymized where practical.

Some limited records may be retained where needed for billing, accounting, tax, security, fraud prevention, dispute handling, legal obligations, or legal claims.


12Your privacy rights

Depending on where you live, you may have rights to:

  • access your personal data;
  • receive a copy of your personal data;
  • correct inaccurate data;
  • delete your data;
  • restrict processing;
  • object to processing;
  • withdraw consent where processing is based on consent;
  • request data portability;
  • complain to a data protection authority.

You can export your inventory data through self-service exports. Palstora supports inventory export formats such as CSV and PDF, and a separate image export as a ZIP file containing uploaded item and container images from workspaces you own. Image export is subject to fair-use limits: one request every 7 days, each export is available for 7 days, and each export can generate up to 3 short-lived download links. Each signed download link expires after 10 minutes. A signed link may be reused during its expiry, so the limit applies to link generation, not guaranteed completed downloads.

You can edit AI-generated names, descriptions, tags, and price estimates.

To exercise your rights or for legal, privacy, and data protection requests, contact us at [email protected]. For support or technical help with exports, contact [email protected].

We normally respond to privacy requests within one month. If a request is complex or we receive many requests, we may need more time, where allowed by law. We may ask you to verify your identity before responding.


13Complaints

If you are in Sweden, you can contact the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, if you believe we have handled your personal data incorrectly.

If you live outside Sweden, you may also have the right to contact your local data protection authority.

We would appreciate the chance to address your concern first. You can contact us at [email protected].


14Security

We use technical and organizational measures designed to protect personal data, including:

  • authentication through Clerk;
  • private storage and access controls;
  • server-side AI processing;
  • encrypted connections where supported;
  • restricted administrator access;
  • infrastructure security controls;
  • security logging;
  • backup and recovery processes.

No online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials safe and for inviting only people you trust to your workspaces.


15Cookies and similar technologies

Palstora uses technologies necessary to operate the website and app, such as authentication, session management, security, and payment processing.

We do not currently use Google Analytics, Meta Pixel, marketing pixels, or third-party behavioral advertising trackers.

If we add non-essential analytics, advertising, or tracking technologies in the future, we will update this policy and request consent where required.


16Marketing emails

We may send marketing emails only if you opt in.

You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting [email protected].

Even if you unsubscribe from marketing emails, we may still send necessary service emails, such as account, security, workspace, billing, or legal notices.


17Children and families

Palstora accounts are intended for users who are at least 18 years old.

Parents or legal guardians may allow family members to participate under the adult’s responsibility.

We do not knowingly allow children to create their own Palstora accounts. If you believe a child has created an account or provided personal data without appropriate permission, contact us at [email protected].


18Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will provide reasonable notice, such as by email, in-app notice, or requiring renewed acceptance where appropriate.

The latest version will be available at www.palstora.com.


19Contact

For privacy questions, requests, or complaints, contact:

Palstora
A product operated under the Palsfy brand
Provided by Brian Nguyen, Swedish sole trader
Business address: Kemivägen 7A, Gothenburg, Sweden
Email: [email protected]
Website: www.palstora.com

Palstora Privacy Policy 1.0 · Effective July 5, 2026