Scope and who is responsible
Boostify, a Danish sole proprietorship registered under CVR 44697327, c/o Christian Nymark Jensen, Vestre Alle 1, 4. th, 9000 Aalborg, Denmark, operates Eloquend and is the controller of the personal data described in this Policy (“Eloquend,” “we,” “us,” or “our”). You can contact our support and privacy channel at support@eloquend.com or send formal legal notices to chris@eloquend.com, or call +45 61 61 67 61 Monday–Friday, 09:00–16:00 Danish time (CET/CEST), excluding Danish public holidays. Voicemail is available outside those hours.
This Policy applies to Eloquend’s website and application. It does not govern LinkedIn, Google, Stripe, or another third-party service you choose to use; those services process data under their own notices.
If a Business User acts as a controller or processor and submits personal data for Eloquend to process on its or a client’s behalf, Eloquend acts as processor or subprocessor for that content under our Data Processing Addendum. The Business User remains responsible for its authority, instructions, purpose, lawful basis, and notices. This Policy still applies to Account, security, billing, analytics, legal, and other data for which Eloquend determines the purposes and means of processing.
Information we collect and where it comes from
| Category | What it includes | Source |
|---|---|---|
| Account and authentication | Email address, account ID, sign-in method, account timestamps, and authentication records. If you use Google sign-in, we may receive your name, email address, profile image, and Google identity reference. Password authentication is handled by Supabase Auth; Eloquend does not store your password in readable form. | You, Supabase Auth, and Google if selected |
| Profile and writing preferences | Name or brand, headline, role, company, website, industry, goals, intended audience, language, tone, formality, post preferences, custom instructions, about text, and profile image. | You, including during onboarding and in Settings |
| Content and files | Ideas, prompts, chats, drafts, generated or edited posts and carousels, saved ideas, schedules, images, documents, videos, uploaded media, voice input, transcripts, and related titles and formatting settings. | You and the outputs generated at your request |
| LinkedIn connection and publishing | LinkedIn member ID, name, profile image, OAuth access and refresh tokens, token expiry and connection state, content and media you ask us to publish, scheduling information, and LinkedIn post or asset references and delivery status. | LinkedIn and your publishing instructions |
| Subscription and transaction data | Selected plan and billing interval, consumer or business purchase selection, business legal name and CVR/VAT ID where supplied, Stripe customer, checkout, subscription, price and invoice references, tax-inclusive order details, the legal document and checkout disclosure versions shown, subscription and payment status, trial and billing dates, and entitlement state. Stripe collects the complete payment-card details; Eloquend does not receive them. | You and Stripe |
| Communications | Email address and delivery information for service messages, such as welcome, subscription confirmation, trial conversion, renewal, cancellation, legal-change, and failed-scheduled-post notices, plus messages and attachments you send to support. | You and our email delivery provider |
| Usage, device, and diagnostic data | Page path without query strings, referring page, browser and device type, operating system, timestamps, coarse request and deployment information, feature events, usage counts, provider/model used, generation or transcription status, file size or audio duration, error codes, and security or rate-limit signals. IP addresses may be processed by hosting and security systems; Eloquend hashes IP-derived rate-limit identifiers where used for that purpose. | Your browser, device, and use of the service |
| Privacy and legal records | The policy and terms versions acknowledged, date and sign-up method, subscription contract and disclosure evidence, data-export and deletion requests, legal or copyright notices, restriction reasons, review requests, decisions, workflow status, and limited audit evidence that a request completed. | You and Eloquend’s compliance systems |
How we use personal data and our legal bases
Where the EU or UK GDPR applies, we rely on the legal bases below. The same purposes describe our use of personal data elsewhere.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account; save settings and content; generate, edit, export, schedule, and publish content; provide support; and operate requested integrations. | Account, profile, content, files, LinkedIn, usage, and communications data | Performance of our contract with you, including steps you request before entering it (GDPR Article 6(1)(b)), but only for personal data relating to the person who is party to that contract. |
| Process incidental personal data about another person that a user supplies outside a Business User processor relationship, solely to fulfil the user-directed writing or communication request and operate the requested feature. | Content, files, prompts, profile context, and generated output concerning that person | Our legitimate interests in providing the user-directed service efficiently and operating Eloquend (Article 6(1)(f)). We apply data minimization, no advertising use or provider training, ZDR text routing, short media retention, user deletion controls, an adults-and-professional-use context, and a prohibition on inappropriate sensitive data. |
| Process subscriptions, payments, refunds, and access entitlements. | Account, subscription, transaction, and usage data | Performance of our contract (Article 6(1)(b)) and compliance with tax, accounting, and payment obligations (Article 6(1)(c)). |
| Send service communications and respond to support or privacy requests. | Account, communications, publishing status, and privacy-request data | Performance of our contract and our legitimate interests in supporting users and documenting requests (Articles 6(1)(b) and 6(1)(f)). |
| Protect accounts and infrastructure, enforce limits, prevent fraud or abuse, investigate errors, and maintain availability. | Account, device, security, usage, and diagnostic data | Our legitimate interests in operating a safe and reliable service (Article 6(1)(f)) and legal obligations where applicable (Article 6(1)(c)). |
| Measure feature adoption, understand aggregate service use, and improve usability, reliability, and product decisions. | Minimized browser analytics and account-linked product events described below | Our legitimate interests in understanding and improving Eloquend (Article 6(1)(f)). You may object as described in “Your rights and choices.” |
| Comply with law, resolve disputes, and establish, exercise, or defend legal claims. | Relevant account, transaction, content, communications, and legal records | Legal obligations (Article 6(1)(c)) and our legitimate interests in protecting legal rights (Article 6(1)(f)). |
The account, authentication, and core content data requested during sign-up and use is needed to provide Eloquend. Optional profile fields, LinkedIn connection, voice input, and Google sign-in are not required. We do not use solely automated decision-making that produces legal or similarly significant effects about you.
If someone used Eloquend with information about you
An Eloquend user may include information about another person in a prompt, draft, file, voice input, or publishing request. The information generally comes from that user rather than from you. It may include your name, professional or contact details, public profile information, correspondence, opinions, voice, image or likeness, or other information the user chooses to supply. Eloquend is not designed for children’s data or special-category or similarly sensitive personal data.
Where a Business User determines the purpose and means of this processing, that Business User is the controller and Eloquend is its processor or subprocessor. Contact the Business User first about its purpose, lawful basis, and use of the result. Where Eloquend acts as an independent controller for incidental third-party data, we process it under Article 6(1)(f) only to fulfil the user-directed request and operate the feature, subject to the safeguards described above.
The information may be disclosed to the infrastructure and AI providers listed in “How we disclose personal data,” and to LinkedIn only if the user directs publication. Provider and Eloquend retention follows “How long we keep personal data.” You may ask for access, correction, deletion, restriction, or objection and may complain to a supervisory authority using the contact and rights information below. This public section is Eloquend’s general Article 14 notice where direct individual notice would involve disproportionate effort. If Eloquend directly contacts you or reuses the information beyond the user’s immediate request, we will provide direct notice before or when that first contact or additional use occurs, unless law provides an exception.
AI features and your content
To generate text, Eloquend sends the prompt and only the profile settings and existing content needed for the requested feature through Vercel AI Gateway. The current workflow routes Claude directly to Anthropic as the primary route and routes GPT through Microsoft Azure as the fallback route. Image prompts and voice recordings are sent directly to OpenAI for image generation and transcription.
- Eloquend does not use private user content to train its own foundation model and does not opt in to provider training. Every text-generation request requires Zero Data Retention, disallows prompt training, is pinned to an approved provider, and does not enable prompt caching.
- Vercel AI Gateway and the selected text provider receive the input, relevant context, technical request metadata, and generated output. Under the configured ZDR routes, they do not retain prompt or output content after the request. Limited service metadata, such as model, provider, token counts, timing, and status, may be processed without prompt or output content.
- Direct OpenAI image generation is not covered by Eloquend’s text ZDR routing. OpenAI may retain image inputs and outputs for up to 30 days for abuse monitoring, with longer retention where required for safety or law. Direct transcription requests have no application-state or abuse-monitoring retention under OpenAI’s current endpoint controls. Eloquend holds raw voice audio only in request memory and retains limited transcription event metadata for 7 days.
- Eloquend stores drafts, generated outputs, transcripts, and associated files in your account when the product saves or auto-saves them. Saved account content follows the account-content retention period below.
- If browser speech recognition is used as a fallback, your browser or operating-system provider may process audio under its own terms and privacy notice.
- AI output can be incorrect or unexpected. Review it before publishing, especially where it refers to people or contains factual claims.
LinkedIn and third-party accounts
Google sign-in and LinkedIn publishing are optional. When you choose one, the provider receives the information needed to complete authentication or the requested publishing action and independently processes data under its privacy notice.
Eloquend uses LinkedIn’s OAuth flow and official API. We receive the limited profile and token data listed above and keep OAuth tokens in a server-restricted store. We do not receive your LinkedIn password, messages, or connection list. We use the connection to publish or schedule content only when you direct us to do so. You can disconnect LinkedIn in Settings; you can also revoke access in LinkedIn.
Content published to LinkedIn becomes subject to your LinkedIn settings and LinkedIn’s own processing. Deleting content or your Eloquend account does not automatically remove a post that has already been published on LinkedIn.
How we disclose personal data
We disclose personal data only as needed for the purposes in this Policy. We do not sell personal data or share it for cross-context behavioral advertising.
| Recipient | Purpose and data involved |
|---|---|
| Supabase | Authentication, PostgreSQL database, private file storage, and scheduled backend functions. |
| Vercel | Website and application hosting, server functions, request logs, deployment diagnostics, and AI Gateway routing. |
| Anthropic, Microsoft Azure, OpenAI, and Vercel AI Gateway | ZDR text generation through AI Gateway using Anthropic-hosted Claude or Azure-hosted GPT; OpenAI separately processes image prompts and voice audio for image generation and transcription. |
| Optional account connection and publishing. LinkedIn acts under its own privacy notice for its platform. | |
| Optional Google authentication. Google acts under its own privacy notice for the sign-in service. | |
| Stripe | Checkout, payment processing, subscriptions, invoices, tax and fraud functions, and the billing portal. Stripe receives payment details directly and also acts under its own privacy notice for parts of its processing. |
| Resend | Delivery and diagnostics for transactional service emails. |
| PostHog EU | Cookieless website measurement and limited account-linked product analytics. |
| Sentry | Sanitized error, log, and performance monitoring. Default personal-data collection and session replay are disabled. |
- We may disclose information to professional advisers, auditors, insurers, or authorities when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or establish or defend legal claims.
- If Eloquend is involved in a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality and applicable-law requirements.
- We may use information that has been aggregated or anonymized so that it no longer identifies a person. This Policy does not restrict information that is no longer personal data.
International data transfers
Eloquend uses providers that operate in the European Economic Area, the United States, and other countries. PostHog is configured for EU Cloud, but other service providers and their subprocessors may process data outside your country.
Where European data-protection law applies to a transfer outside the EEA, we use an available lawful transfer mechanism, such as an adequacy decision (including the EU–U.S. Data Privacy Framework where applicable), the European Commission’s Standard Contractual Clauses, and supplementary safeguards where appropriate. Contact us if you want information about the safeguard used for a particular transfer.
How long we keep personal data
We keep personal data only for the period needed for the purpose collected, including providing the service, meeting legal obligations, resolving disputes, and maintaining security. The service uses the following periods and criteria:
| Data | Retention |
|---|---|
| Account, profile, drafts, posts, ideas, schedules, files, and LinkedIn connection | For the life of the account or until you remove the item or connection, then deleted through the applicable workflow, subject to legal exceptions and backup rotation. |
| Text-generation inputs and outputs at AI Gateway providers | Zero Data Retention: prompt and output content is not retained after the request and prompt caching is not enabled. Limited non-content service metadata may remain under the provider’s applicable operational and contractual controls. Content saved in Eloquend follows the account-content period above. |
| Direct OpenAI image and transcription processing | Image-generation inputs and outputs may be retained by OpenAI for up to 30 days for abuse monitoring, subject to documented safety or legal exceptions. OpenAI’s current transcription endpoint does not retain application state or abuse-monitoring content. Eloquend holds raw audio only in request memory. Saved images and transcripts follow the account-content period. |
| Voice transcription event metadata | Limited provider, status, error, duration, byte-count, and fallback metadata is retained for up to 7 days. It does not contain the raw audio or transcript. Usage-accounting records follow the separate period below. |
| Temporary upload reservations | Terminal or expired reservation records are retained for up to 7 days. |
| Transactional email diagnostics | Up to 90 days after the email event. |
| Usage-accounting events | Up to 13 months after the event, unless needed longer for a dispute or legal obligation. |
| Account-export files and request metadata | A prepared export file expires after 24 hours. Manual export request metadata expires after 7 days once no active file depends on it. |
| Subscription, invoice, tax, and accounting records | For the period required by applicable bookkeeping, tax, payment, and fraud-prevention law. Danish accounting records are generally kept for 5 years after the end of the relevant financial year. |
| Subscription contract evidence | The accepted legal version, checkout disclosure, business-purchase details, price, trial, and renewal evidence is retained with related transaction records for the period reasonably needed to prove the contract, meet accounting obligations, and resolve disputes, normally up to 5 years after the relevant financial year unless a longer active claim requires it. |
| PostHog EU analytics | Less than 12 months. Eloquend rotates and deletes the entire production analytics project before its oldest event reaches 12 months. Account-linked identifiers and events are also included in the account-deletion workflow. PostHog is suppressed for United Kingdom and unclassified production traffic. |
| Sentry error telemetry | Up to 30 days under the configured Sentry Developer plan. |
| Vercel runtime logs | Up to 1 day under the configured Vercel Pro plan. No extended observability retention or log drain is enabled. |
| Legal acknowledgements and privacy requests | Account-linked acknowledgements are kept while the account exists. A completed deletion leaves only non-identifying outcome metrics for up to 12 months; unresolved requests are retained until completed and investigated. |
| Illegal-content, copyright, and restriction-review records | Normally up to 3 years after the final decision, or longer where needed for an active legal claim, authority request, repeat-abuse evidence, or a legal retention duty. |
Deletion from active systems may not immediately remove restricted copies in disaster-recovery backups. Those copies remain protected, are not used for ordinary business purposes, and are removed as backups rotate. We may retain limited information for longer when law requires it, a legal claim is active, or deletion would impair security or the rights of another person.
How we protect personal data
We use technical and organizational safeguards appropriate to the nature of the service. These include encrypted transport, provider encryption at rest, private user-file buckets, row-level database access controls, server-restricted OAuth tokens and billing writes, signed short-lived file access, scoped secrets, request-origin checks, content security policies, dependency and vulnerability checks, sanitized logs, and controlled deletion and export workflows.
No online service can guarantee absolute security. Protect your password and connected accounts, use a unique password, keep your devices secure, and contact us promptly if you suspect unauthorized account access.
Your rights and choices
Depending on where you live and subject to legal limits, you may have the right to:
- access personal data and receive information about how it is used;
- correct inaccurate or incomplete personal data;
- delete personal data;
- restrict or object to processing, including processing based on legitimate interests;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible;
- withdraw consent at any time where a processing activity relies on consent, without affecting earlier lawful processing; and
- complain to a competent data-protection authority.
You can edit many profile fields, disconnect LinkedIn, manage billing, export account data, or request account deletion from Settings. You may also email support@eloquend.com. We may need to verify your identity and clarify the scope of a request. We will respond within the period required by applicable law; under the GDPR this is generally one month, subject to permitted extensions.
Rights are not absolute. For example, we may retain accounting records required by law or decline a request that would adversely affect another person’s rights. You will not receive discriminatory treatment for exercising a privacy right. If you disagree with our response and local law provides an appeal, reply to our decision and ask us to review it.
If you are in the EEA, you may complain to the supervisory authority where you live, work, or believe an infringement occurred. In Denmark, the authority is Datatilsynet (the Danish Data Protection Agency).
Children
Eloquend is a professional content-creation service for adults and is not directed to anyone under 18. We do not knowingly permit an Account for or collect personal data directly from a person under 18. If you believe a person under 18 has provided personal data to Eloquend, contact us so we can investigate and delete it where appropriate.
Changes to this Policy
We may update this Policy when the service, vendors, or legal requirements change. We will post the revised version here and update the date and version above. If a change materially affects how we use personal data, we will provide additional notice before it takes effect, such as an in-product or email notice, when required. If consent is legally required for a new use, we will request it rather than treating silence as consent.