Privacy Policy
Last updated: 13 August 2026
1. Who controls your data
The controller is Charlotte Chartrou, Individual founder — sole operator.
For privacy requests, contact charlotte@pionyra.com.
A UAE free zone entity is being incorporated; these notices will be updated upon registration.
2. Data we collect
We collect account details, company profile data, prompts, conversations, attached files, generated content, connected-account tokens, publication history, performance metrics, inbox messages, WhatsApp messages when connected, billing metadata and technical logs.
Connected-account tokens are encrypted and used only to operate the integrations you enable. We never ask for or store your social, Gmail or platform passwords.
Messages received from third parties through connected channels are used only so you can read, triage and respond to them in Pionyra.
3. Why we use it
For UAE businesses, we take account of the federal Personal Data Protection Law (PDPL) and, where relevant, DIFC or ADGM data protection regimes. If you process data about people located in the European Economic Area, GDPR may also apply.
We use data to provide the service, secure accounts, operate integrations, prepare AI outputs, process payments, send service notifications, comply with legal obligations and fix technical issues.
We do not sell your data and we do not use your content to train foundation models.
4. Service providers
We rely on the providers below. Each receives only the data needed for its role.
| Provider | Role | Hosting |
|---|---|---|
| Supabase | Database, authentication and file storage | Cloud infrastructure |
| Vercel | Application hosting | United States |
| Anthropic | AI content generation | United States |
| Groq | Fallback AI content generation | United States |
| Meta (Instagram, WhatsApp) | Publishing, insights and messaging | United States |
| Google (Gmail) | Email sending and Gmail actions if connected | United States |
| Publishing if connected | United States | |
| Stripe | Subscription payments | United States |
| Resend | Service emails | United States |
| Sentry | Technical error monitoring | United States |
| Pollinations / OpenAI | Image generation | United States |
Some providers may process data outside the UAE. We limit these transfers to service needs and use appropriate safeguards when required.
5. Retention
Account data and content are kept while your account is active. After account deletion, we erase service data within 30 days, except accounting records kept for legally required periods. Access tokens are deleted when an integration is disconnected. Technical logs are generally kept for 90 days.
6. Your rights
You can request access, correction, deletion, export or restriction of your personal data. We respond within one month unless local law allows or requires a different period.
Social data deletion requests can also be followed on the data deletion page.
7. Security
Access tokens are encrypted with AES-256, traffic is encrypted in transit, and account data is isolated at database level. No public post, email or scheduled outbound action leaves Pionyra without your explicit approval.
8. Cookies
We currently use only cookies that are necessary for session, security and authentication. Advertising, retargeting or profiling cookies are not active on the public site.
9. Changes
This policy may change. If a material change affects your rights or our use of data, we will notify you by email or at your next login.