Skip to content

Version 2026-07-29.1

Drafted in-house. External legal review is not yet complete — these terms apply; this notes how they were written.

Privacy

What we store, why, for how long and who else sees it — one row per actual store instead of “as long as necessary”. At the bottom you can export everything, or delete everything, with one button.

Terms of use
Everyone

The short version

We store your email address, what you checked and what the check concluded. That is essentially all of it.

We sell nothing on, build no profile about you and hand nothing to advertisers. An advertiser learns that the advert was shown — not who it was shown to.

You can export everything we hold about you and delete all of it, directly in the product, without asking us for permission. The buttons are at the bottom of this page.

Everyone

Who the controller is

The controller is Aurolabs AB · 559523-4989 · VAT SE559523498901 · c/o DeFlavion International AB, Skogsängsvägen 54D, 135 35 Tyresö · hej@pssst.fyi.

We have no data protection officer. We are not a public authority, our core activity is neither large-scale regular monitoring of people nor large-scale processing of sensitive data, and Article 37 therefore does not require one. Questions about personal data go to the address above and are answered by us.

We process personal data in Sweden and within the EU/EEA. Where anything leaves the EU is set out under Recipients below.

Everyone

What we collect

Six categories, and none of them is sensitive within the meaning of the GDPR.

Category

Account

What it is

Email address, chosen language, plan and how many checks you have used

Where from

From you

Category

What you check

What it is

The listing link, the listing text, make, model, year, mileage, town and whatever you typed in the free-text field

Where from

From you

Category

The result

What it is

The verdict, the traps, the price position, the checklist and the sources

Where from

Created by us

Category

Seller answers

What it is

The answers to the checklist and the photos the seller uploads

Where from

From the seller

Category

Company details

What it is

Company name, registration number, country and VAT number — sellers only

Where from

From you

Category

Payment

What it is

Amount, currency, time and Stripe's reference. Never a card number.

Where from

From Stripe

Category

Consent

What it is

Which wording you agreed to, when, and whether you waived withdrawal

Where from

From you

Category

Technical log

What it is

IP address (truncated in the consent record), browser string and service events

Where from

Automatically

Everyone

Why, and on what legal basis

One purpose per row. We do not use the data for anything not listed here.

Purpose

Deliver the check you ordered, take payment and give you access to the result

Legal basis

Performance of a contract — Art. 6(1)(b)

Purpose

Send sign-in links and delivery emails

Legal basis

Performance of a contract — Art. 6(1)(b)

Purpose

Publish a seller's self-audit and show it to matched buyers

Legal basis

Performance of a contract with the seller — Art. 6(1)(b)

Purpose

Stop the free check being farmed, and protect the service from overload

Legal basis

Legitimate interest — Art. 6(1)(f). Our interest in a service that holds up, weighed against the data being an IP address and nothing else.

Purpose

Keep the evidence of consent and of the withdrawal waiver

Legal basis

Legal obligation — Art. 6(1)(c) (Distance Contracts Act), and legitimate interest — Art. 6(1)(f), to be able to answer a legal claim

Purpose

Account for payments

Legal basis

Legal obligation — Art. 6(1)(c) (Swedish Bookkeeping Act 1999:1078)

Purpose

See which link brought you here

Legal basis

Consent — Art. 6(1)(a). You can take it back at any time, further down this page.

Purpose

Understand what went wrong in a run and make the check better

Legal basis

Legitimate interest — Art. 6(1)(f)

Everyone

Sensitive data, profiling and automated decisions

We never ask for special-category data under Article 9 and do not need it. Do not type health, politics, religion or anything similar into the free-text field — it ends up in the check.

No automated decision-making with legal effects for you within the meaning of Article 22. The AI system writes text about a car. It makes no decision about you, gives you no score, and drives no credit, insurance or employment outcome.

The 0–100 score on a seller's page measures how well documented the car is. It does not measure the seller, and it is computed from how many questions were answered — not by a model judging a person.

We build no profile about you and do no audience targeting. A placed advert is matched against the car you are checking, not against who you are.

Everyone

How long we keep it, per store

We chose to list every actual store rather than write “as long as necessary”. A script prunes to exactly these periods, so a period in the table is something that actually happens.

Where it lives

accounts/

What it holds

Email address, language, plan, quota and a seller's company details

How long

24 months after your last sign-in. Deleted immediately when you delete the account.

Where it lives

runs/

What it holds

The check: the question, the result, the sources and the seller shares

How long

24 months. On erasure the email is removed and the check becomes anonymous.

Where it lives

jobs/

What it holds

The working folder for a run: the prompt and the model's raw output

How long

90 days

Where it lives

fills/

What it holds

The link between a seller link and the check it belongs to

How long

Follows the check — 24 months

Where it lives

listings/

What it holds

A published self-audit: slug, town, region, expiry date

How long

Visible for 30 days, then kept 12 months as a record of delivery. Deleted immediately when the seller deletes their account.

Where it lives

consents/

What it holds

Which wording was agreed, when, a truncated IP, and whether withdrawal was waived

How long

3 years from the purchase, as long as a consumer claim can be brought. On erasure the email is removed and the record becomes evidence without a name.

Where it lives

logins/

What it holds

A one-time token for the sign-in link

How long

30 minutes, and it is deleted the second you use it

Where it lives

garage/

What it holds

The link between a garage link and an email address

How long

24 months. Deleted with the account.

Where it lives

events.jsonl

What it holds

Service events: timestamp, event and the run's token. No email address.

How long

14 months

Where it lives

free-ips.json

What it holds

IP address and timestamp for free checks, to stop bulk abuse

How long

30 days, then the entry is pruned

Where it lives

offers.json

What it holds

Which seller link received the discount code, and when it expires

How long

12 months after the code expires

Where it lives

tombstones.json

What it holds

A one-way hash of a deleted email, so an old session cannot revive the account

How long

180 days after the deletion

Where it lives

public/pssst-uploads/

What it holds

Photos the seller uploaded. All metadata, including GPS, is stripped before the file touches disk.

How long

12 months, or immediately when the seller deletes their account

Where it lives

Postgres

What it holds

An index over the same checks and listings as above, when the database is switched on

How long

The same periods as the files. An erasure hits both.

Everyone

Who else sees anything

Five suppliers, each with a data processing agreement and a narrow job.

We sell no personal data. We hand nothing to advertisers. We disclose to a public authority only where the law requires it, and only what is required.

Who

OpenAI

What they receive

The listing text and your question. Not your email address, not your name.

Basis and safeguard

Processor. Data processing agreement. The transfer to the USA rests on the EU–US Data Privacy Framework, under which OpenAI is certified. The data is not used to train models.

Who

Stripe

What they receive

Amount, currency and email address. The card number goes straight to Stripe and never passes through us.

Basis and safeguard

Independent controller for the payment itself, processor otherwise. DPA. The transfer to the USA rests on the EU–US Data Privacy Framework, under which Stripe is certified.

Who

Resend

What they receive

The email address and the contents of the mail we send you

Basis and safeguard

Processor. DPA. The transfer to the USA rests on the EU–US Data Privacy Framework, under which Resend is certified.

Who

DigitalOcean (Amsterdam, EU)

What they receive

Operation and storage of everything on the server

Basis and safeguard

Processor. DPA. Servers inside the EU/EEA.

Who

DigitalOcean Managed Postgres (Amsterdam, EU)

What they receive

The index over checks and listings

Basis and safeguard

Processor. DPA. Servers inside the EU/EEA.

Everyone

Transfers outside the EU/EEA

OpenAI, Stripe and Resend are US companies and may process data in the USA. All three are certified under the EU–US Data Privacy Framework, so the transfer rests on the European Commission's adequacy decision. Should that decision cease to apply, the transfer falls back on the Commission's Standard Contractual Clauses, and we then carry out the assessment those clauses require. The server and the database sit inside the EU/EEA.

We choose EU data residency where the supplier offers it. Hosting and the database sit inside the EU/EEA.

If you want to see the clauses that apply to a given supplier: email us and we will send them.

Everyone

Cookies

Five cookies, four of them necessary. Nothing beyond the necessary ones is written before you say yes, and “continuing to browse” does not count as a yes.

The table below is the same register the product actually runs on — the same rows as in the banner, read from the same file. It therefore cannot say anything other than what the code does.

If the categories change the register changes version (currently 2026-07-29.1) and you are asked again. You can change your choice at the bottom of this page, and if you say no the analytics cookie is deleted the same second.

Cookie

pssst_session

Category

Necessary

Why

Keeps you signed in after you click the link we mailed you. Without it there is no account.

Kept

90 days

Cookie

pssst_viewer

Category

Necessary

Why

Remembers that this browser was granted one specific check, so you can reopen your own result.

Kept

90 days

Cookie

pssst_lang

Category

Necessary

Why

Remembers the language you picked, so the choice survives navigation.

Kept

1 year

Cookie

pssst_consent

Category

Necessary

Why

Stores this very choice. Without it we would have to ask you on every page.

Kept

1 year

Cookie

__stripe_mid / __stripe_sid / m

Category

Necessary

Why

Set by Stripe, our payment processor, to detect card fraud during checkout. They are only ever set once you open the payment step — never on arrival, and never if you only use the free check.

Kept

__stripe_mid 1 year · __stripe_sid 30 minutes · m 2 years

Cookie

pssst_src

Category

Analytics (consent required)

Why

Records which link brought you here, so we can tell which of our own posts actually help people. Never shared, never used to build a profile.

Kept

90 days

Everyone

Your rights

You have the right to access, rectification, erasure, restriction, objection and portability, and the right to withdraw a consent at any time.

Two of them you do not have to ask for. Signed in, you can export everything we hold about you as a JSON file and delete your account outright — the buttons are at the bottom of this page, they work immediately, and there is no waiting period.

Other requests are answered within a month. If a request is complex we may extend by two months, and we will tell you before the first month is up. It costs nothing.

An erasure removes your account and the link between you and your checks. Two things survive, and both are deliberate: the consent record stays without your email address, because it is the evidence that a purchase was made lawfully, and the accounting record at our payment provider must be kept under the Bookkeeping Act.

Everyone

Security

Traffic is encrypted. Sign-in uses a one-time link by email, so there is no password to leak. The session is signed and lasts 90 days.

Uploaded photos are stripped of all metadata, including GPS position, before the file is saved — a photo taken on the driveway should not be able to give away the driveway.

If you delete your account a one-way hash is set as a block, so an old but technically valid session cannot revive it.

In the event of a personal data breach likely to result in a risk we notify IMY within 72 hours, and tell you directly if the risk is high.

Everyone

If you are not happy

Come to us first — hej@pssst.fyi. We answer.

To complain formally, contact the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, imy.se. You may complain where you live, where you work, or where you believe the infringement took place.

Everyone

Children

The service is for people aged 18 and over. We do not target children and do not knowingly collect data about children. If we learn that an account belongs to a child, we delete it.

Everyone

Changes to this policy

Version 2026-07-29.1. If we change something material we write it here, and email you if you have an account.

If what the cookies do changes, the cookie register changes version and the banner asks for your consent again. An old yes to different wording does not count as a yes to this one.

Aurolabs AB · 559523-4989 · VAT SE559523498901 · c/o DeFlavion International AB, Skogsängsvägen 54D, 135 35 Tyresö · hej@pssst.fyi

Your data, right now

Signed in, these work immediately — no request, no waiting period.

Export everything
Integritetspolicy — vad vi sparar och varför · Pssst