Version 2026-07-29.1
Drafted in-house. External legal review is not yet complete — these terms apply; this notes how they were written.
Privacy
What we store, why, for how long and who else sees it — one row per actual store instead of “as long as necessary”. At the bottom you can export everything, or delete everything, with one button.
Terms of use →The short version
We store your email address, what you checked and what the check concluded. That is essentially all of it.
We sell nothing on, build no profile about you and hand nothing to advertisers. An advertiser learns that the advert was shown — not who it was shown to.
You can export everything we hold about you and delete all of it, directly in the product, without asking us for permission. The buttons are at the bottom of this page.
Who the controller is
The controller is Aurolabs AB · 559523-4989 · VAT SE559523498901 · c/o DeFlavion International AB, Skogsängsvägen 54D, 135 35 Tyresö · hej@pssst.fyi.
We have no data protection officer. We are not a public authority, our core activity is neither large-scale regular monitoring of people nor large-scale processing of sensitive data, and Article 37 therefore does not require one. Questions about personal data go to the address above and are answered by us.
We process personal data in Sweden and within the EU/EEA. Where anything leaves the EU is set out under Recipients below.
What we collect
Six categories, and none of them is sensitive within the meaning of the GDPR.
Category
What it is
Where from
Category
Account
What it is
Email address, chosen language, plan and how many checks you have used
Where from
From you
Category
What you check
What it is
The listing link, the listing text, make, model, year, mileage, town and whatever you typed in the free-text field
Where from
From you
Category
The result
What it is
The verdict, the traps, the price position, the checklist and the sources
Where from
Created by us
Category
Seller answers
What it is
The answers to the checklist and the photos the seller uploads
Where from
From the seller
Category
Company details
What it is
Company name, registration number, country and VAT number — sellers only
Where from
From you
Category
Payment
What it is
Amount, currency, time and Stripe's reference. Never a card number.
Where from
From Stripe
Category
Consent
What it is
Which wording you agreed to, when, and whether you waived withdrawal
Where from
From you
Category
Technical log
What it is
IP address (truncated in the consent record), browser string and service events
Where from
Automatically
Why, and on what legal basis
One purpose per row. We do not use the data for anything not listed here.
Purpose
Legal basis
Purpose
Deliver the check you ordered, take payment and give you access to the result
Legal basis
Performance of a contract — Art. 6(1)(b)
Purpose
Send sign-in links and delivery emails
Legal basis
Performance of a contract — Art. 6(1)(b)
Purpose
Publish a seller's self-audit and show it to matched buyers
Legal basis
Performance of a contract with the seller — Art. 6(1)(b)
Purpose
Stop the free check being farmed, and protect the service from overload
Legal basis
Legitimate interest — Art. 6(1)(f). Our interest in a service that holds up, weighed against the data being an IP address and nothing else.
Purpose
Keep the evidence of consent and of the withdrawal waiver
Legal basis
Legal obligation — Art. 6(1)(c) (Distance Contracts Act), and legitimate interest — Art. 6(1)(f), to be able to answer a legal claim
Purpose
Account for payments
Legal basis
Legal obligation — Art. 6(1)(c) (Swedish Bookkeeping Act 1999:1078)
Purpose
See which link brought you here
Legal basis
Consent — Art. 6(1)(a). You can take it back at any time, further down this page.
Purpose
Understand what went wrong in a run and make the check better
Legal basis
Legitimate interest — Art. 6(1)(f)
Sensitive data, profiling and automated decisions
We never ask for special-category data under Article 9 and do not need it. Do not type health, politics, religion or anything similar into the free-text field — it ends up in the check.
No automated decision-making with legal effects for you within the meaning of Article 22. The AI system writes text about a car. It makes no decision about you, gives you no score, and drives no credit, insurance or employment outcome.
The 0–100 score on a seller's page measures how well documented the car is. It does not measure the seller, and it is computed from how many questions were answered — not by a model judging a person.
We build no profile about you and do no audience targeting. A placed advert is matched against the car you are checking, not against who you are.
How long we keep it, per store
We chose to list every actual store rather than write “as long as necessary”. A script prunes to exactly these periods, so a period in the table is something that actually happens.
Where it lives
What it holds
How long
Where it lives
accounts/
What it holds
Email address, language, plan, quota and a seller's company details
How long
24 months after your last sign-in. Deleted immediately when you delete the account.
Where it lives
runs/
What it holds
The check: the question, the result, the sources and the seller shares
How long
24 months. On erasure the email is removed and the check becomes anonymous.
Where it lives
jobs/
What it holds
The working folder for a run: the prompt and the model's raw output
How long
90 days
Where it lives
fills/
What it holds
The link between a seller link and the check it belongs to
How long
Follows the check — 24 months
Where it lives
listings/
What it holds
A published self-audit: slug, town, region, expiry date
How long
Visible for 30 days, then kept 12 months as a record of delivery. Deleted immediately when the seller deletes their account.
Where it lives
consents/
What it holds
Which wording was agreed, when, a truncated IP, and whether withdrawal was waived
How long
3 years from the purchase, as long as a consumer claim can be brought. On erasure the email is removed and the record becomes evidence without a name.
Where it lives
logins/
What it holds
A one-time token for the sign-in link
How long
30 minutes, and it is deleted the second you use it
Where it lives
garage/
What it holds
The link between a garage link and an email address
How long
24 months. Deleted with the account.
Where it lives
events.jsonl
What it holds
Service events: timestamp, event and the run's token. No email address.
How long
14 months
Where it lives
free-ips.json
What it holds
IP address and timestamp for free checks, to stop bulk abuse
How long
30 days, then the entry is pruned
Where it lives
offers.json
What it holds
Which seller link received the discount code, and when it expires
How long
12 months after the code expires
Where it lives
tombstones.json
What it holds
A one-way hash of a deleted email, so an old session cannot revive the account
How long
180 days after the deletion
Where it lives
public/pssst-uploads/
What it holds
Photos the seller uploaded. All metadata, including GPS, is stripped before the file touches disk.
How long
12 months, or immediately when the seller deletes their account
Where it lives
Postgres
What it holds
An index over the same checks and listings as above, when the database is switched on
How long
The same periods as the files. An erasure hits both.
Who else sees anything
Five suppliers, each with a data processing agreement and a narrow job.
We sell no personal data. We hand nothing to advertisers. We disclose to a public authority only where the law requires it, and only what is required.
Who
What they receive
Basis and safeguard
Who
OpenAI
What they receive
The listing text and your question. Not your email address, not your name.
Basis and safeguard
Processor. Data processing agreement. The transfer to the USA rests on the EU–US Data Privacy Framework, under which OpenAI is certified. The data is not used to train models.
Who
Stripe
What they receive
Amount, currency and email address. The card number goes straight to Stripe and never passes through us.
Basis and safeguard
Independent controller for the payment itself, processor otherwise. DPA. The transfer to the USA rests on the EU–US Data Privacy Framework, under which Stripe is certified.
Who
Resend
What they receive
The email address and the contents of the mail we send you
Basis and safeguard
Processor. DPA. The transfer to the USA rests on the EU–US Data Privacy Framework, under which Resend is certified.
Who
DigitalOcean (Amsterdam, EU)
What they receive
Operation and storage of everything on the server
Basis and safeguard
Processor. DPA. Servers inside the EU/EEA.
Who
DigitalOcean Managed Postgres (Amsterdam, EU)
What they receive
The index over checks and listings
Basis and safeguard
Processor. DPA. Servers inside the EU/EEA.
Transfers outside the EU/EEA
OpenAI, Stripe and Resend are US companies and may process data in the USA. All three are certified under the EU–US Data Privacy Framework, so the transfer rests on the European Commission's adequacy decision. Should that decision cease to apply, the transfer falls back on the Commission's Standard Contractual Clauses, and we then carry out the assessment those clauses require. The server and the database sit inside the EU/EEA.
We choose EU data residency where the supplier offers it. Hosting and the database sit inside the EU/EEA.
If you want to see the clauses that apply to a given supplier: email us and we will send them.
Cookies
Five cookies, four of them necessary. Nothing beyond the necessary ones is written before you say yes, and “continuing to browse” does not count as a yes.
The table below is the same register the product actually runs on — the same rows as in the banner, read from the same file. It therefore cannot say anything other than what the code does.
If the categories change the register changes version (currently 2026-07-29.1) and you are asked again. You can change your choice at the bottom of this page, and if you say no the analytics cookie is deleted the same second.
Cookie
Category
Why
Kept
Cookie
pssst_session
Category
Necessary
Why
Keeps you signed in after you click the link we mailed you. Without it there is no account.
Kept
90 days
Cookie
pssst_viewer
Category
Necessary
Why
Remembers that this browser was granted one specific check, so you can reopen your own result.
Kept
90 days
Cookie
pssst_lang
Category
Necessary
Why
Remembers the language you picked, so the choice survives navigation.
Kept
1 year
Cookie
pssst_consent
Category
Necessary
Why
Stores this very choice. Without it we would have to ask you on every page.
Kept
1 year
Cookie
__stripe_mid / __stripe_sid / m
Category
Necessary
Why
Set by Stripe, our payment processor, to detect card fraud during checkout. They are only ever set once you open the payment step — never on arrival, and never if you only use the free check.
Kept
__stripe_mid 1 year · __stripe_sid 30 minutes · m 2 years
Cookie
pssst_src
Category
Analytics (consent required)
Why
Records which link brought you here, so we can tell which of our own posts actually help people. Never shared, never used to build a profile.
Kept
90 days
Your rights
You have the right to access, rectification, erasure, restriction, objection and portability, and the right to withdraw a consent at any time.
Two of them you do not have to ask for. Signed in, you can export everything we hold about you as a JSON file and delete your account outright — the buttons are at the bottom of this page, they work immediately, and there is no waiting period.
Other requests are answered within a month. If a request is complex we may extend by two months, and we will tell you before the first month is up. It costs nothing.
An erasure removes your account and the link between you and your checks. Two things survive, and both are deliberate: the consent record stays without your email address, because it is the evidence that a purchase was made lawfully, and the accounting record at our payment provider must be kept under the Bookkeeping Act.
Security
Traffic is encrypted. Sign-in uses a one-time link by email, so there is no password to leak. The session is signed and lasts 90 days.
Uploaded photos are stripped of all metadata, including GPS position, before the file is saved — a photo taken on the driveway should not be able to give away the driveway.
If you delete your account a one-way hash is set as a block, so an old but technically valid session cannot revive it.
In the event of a personal data breach likely to result in a risk we notify IMY within 72 hours, and tell you directly if the risk is high.
If you are not happy
Come to us first — hej@pssst.fyi. We answer.
To complain formally, contact the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, imy.se. You may complain where you live, where you work, or where you believe the infringement took place.
Children
The service is for people aged 18 and over. We do not target children and do not knowingly collect data about children. If we learn that an account belongs to a child, we delete it.
Changes to this policy
Version 2026-07-29.1. If we change something material we write it here, and email you if you have an account.
If what the cookies do changes, the cookie register changes version and the banner asks for your consent again. An old yes to different wording does not count as a yes to this one.
Aurolabs AB · 559523-4989 · VAT SE559523498901 · c/o DeFlavion International AB, Skogsängsvägen 54D, 135 35 Tyresö · hej@pssst.fyi
Your data, right now
Signed in, these work immediately — no request, no waiting period.