PRIVACY · EFFECTIVE 29 AUGUST 2026

Privacy Policy

This Privacy Policy explains how Daniel Rossi Marinho - Unipessoal Lda, operating as CONSELA (“CONSELA”, “we”, “us”), processes personal data through consela.ai and the CONSELA application (the “Service”). VAT/NIPC: PT519202120 / 519202120. Our legal identity and contact details are available on our Legal Information page.

1. Roles

For account, billing, security, support and direct product-operation data, CONSELA is generally the data controller. When an organization uses the Service to upload or process information about its personnel, customers or other individuals, the organization may be the controller and CONSELA may act as its processor. A separate Data Processing Addendum applies to business customers where appropriate.

2. Data we collect

  • Account data: name, email, password credentials, verification state and organization membership.
  • Workspace data: organization, project and meeting names, descriptions, prompts, documents, reports, transcripts, consensus documents, chats, notifications and permissions.
  • Support data: tickets, messages and attachments.
  • Billing data: plan, subscription status, Stripe customer/subscription identifiers and invoices. Stripe processes card details; CONSELA does not store full card numbers.
  • Technical and security data: IP address, authentication events, rate-limit/anti-abuse signals, browser/device information, logs, job identifiers, error reports and audit events.
  • Communications: service emails, account notices and preferences. Marketing communications, if introduced, require a separate lawful basis and opt-out.

3. How we use data

  • Provide, secure and troubleshoot the Service.
  • Create and manage accounts, organizations, invitations and permissions.
  • Run meetings, web research, AI analysis, follow-up conversations and generated documents at the user’s request.
  • Process subscriptions, invoices, taxes, refunds and fraud prevention.
  • Respond to support requests and communicate service changes.
  • Prevent abuse, protect users and investigate security incidents.
  • Measure reliability and improve the Service where permitted and disclosed. We do not use customer meeting content to train general-purpose models unless a customer separately agrees in writing.
  • Comply with legal obligations and establish, exercise or defend legal claims.

4. Legal bases for EEA users

Depending on the activity, we rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is required. We will not treat optional marketing or non-essential tracking as necessary for the contract.

5. United States privacy disclosures

Where applicable US state privacy law applies, we collect the following categories of personal information: identifiers and contact details; commercial and subscription information; internet or network activity and device information; professional or organization information; user-generated workspace content; and inferences or preferences derived from your use of the Service. We collect these categories from you, your organization, identity or sign-in providers, service providers, and your device or browser.

We use these categories to provide and secure the Service, authenticate users, administer organizations and subscriptions, process payments, provide support, conduct requested research and AI operations, prevent abuse, communicate service information, and comply with law. We disclose them to hosting, email, payment, security, AI-inference and research providers for these business purposes. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information outside the purposes permitted by applicable law. We do not have actual knowledge that we sell or share personal information of consumers under 16.

Depending on the applicable law, you may have rights to know or access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising or certain profiling, limit sensitive-personal-information use, and appeal a denied request. Submit a request through your account where available or by email to [email protected]. We may reasonably verify your identity using your account, account email, or information necessary to protect your data. We generally respond to California requests within 45 days and may extend once by another 45 days when permitted, with notice. If we deny a request, you may appeal by replying to our decision or emailing us with “Privacy appeal” in the subject line. We do not discriminate against you for exercising applicable privacy rights.

6. AI and external services

Meeting prompts, uploaded content and relevant context may be sent to OpenRouter and research providers to produce the requested result. CONSELA does not use a direct OpenAI integration. OpenRouter routes are selected for zero-data-retention (ZDR) eligibility where available and configured; availability, endpoint terms and routing remain subject to the selected OpenRouter route. CONSELA requires each active route and research provider to apply the retention and deletion terms stated in its contract or service configuration, and will update the Subprocessor List when the processing chain changes. Current provider categories include OpenRouter, Exa, Tavily, Stripe, ZeptoMail, Google Drive API, Google Sign-In and encrypted backup storage when configured, Cloudflare security services where enabled, and Hetzner hosting. Providers may process data outside the EEA. See the AI Disclosure.

7. Sharing

We share data with service providers acting under instructions, with organization members according to workspace permissions, when a user creates a share link, when required by law, or during a business transaction such as a merger or acquisition. We do not sell personal information or share it for cross-context behavioural advertising. Whether any provider activity constitutes “sharing” under a US state law is assessed separately.

8. International transfers

We use appropriate safeguards for restricted transfers, which may include an adequacy decision, Standard Contractual Clauses, a Data Processing Addendum and supplementary measures. Provider-specific transfer details are described in the Subprocessor List and may change when providers or routes change.

9. Retention

We retain personal data only for as long as necessary for the purposes described here. A verified member-account deletion request is scheduled for processing after a 14-day grace period. The member may cancel the request before processing begins; when eligible, processing removes access and anonymizes the account while preserving organization-owned content. Project deletion requests are scheduled for 14 days, hide the project immediately, and can be cancelled by restoring the project during the grace period. At the end of that period, project meetings, reports, files and related content are permanently purged unless a documented legal or security hold applies. Organization deletion requests are scheduled for 14 days. Organization changes and invitations are disabled immediately, and the request may be cancelled during the grace period. After that period, the organization is quarantined for the applicable export, security and retention processes. Encrypted production backups are retained on a rolling 14-day schedule. Security and anti-abuse logs are retained for up to 12 months. Support records are retained for up to 24 months after resolution. Billing, accounting, legal-acceptance and incident records may be retained for legally required periods. Normal OpenCode/LLM sessions and traces are not retained after processing unless an administrator explicitly enables a debug trace, which expires after 14 days. OpenRouter, Exa and Tavily receive only the data needed for the requested operation and are configured or contractually required to delete it under their applicable retention and ZDR terms.

10. Security

We use access controls, authentication protections, encryption in transit, tenant authorization and operational monitoring appropriate to the risk. No internet service is completely secure. Suspected incidents should be reported to [email protected].

11. Your rights

Subject to legal limits, EEA residents may request access, correction, deletion, restriction, portability and objection, and may withdraw consent. US residents may have rights under applicable state laws, including the rights described in section 5. Use the Your Data Rights page or email us. You may complain to your local data-protection authority.

12. Children

The Service is intended for people aged 18 or older. We do not knowingly offer accounts to anyone under 18. Contact us if you believe a minor has provided personal data.

13. Cookies

See our Cookie Policy. Strictly necessary cookies may be used to operate the Service; non-essential analytics or advertising technologies require consent where applicable.

14. Changes

We may update this policy and will publish the new version and effective date. Material changes may also be communicated through the Service or email.

15. Contact

Privacy requests and questions: [email protected]. CONSELA is established in Portugal and does not currently appoint a separate EU representative or data-protection officer. Full legal contact details are available on our Legal Information page.