
Last updated: August 2026
ParetoStudio is operated from Italy. For any privacy-related matter, you can reach us at support@paretostudio.io.
The competent supervisory authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority). You have the right to lodge a complaint with the Garante at any time. More information: www.garanteprivacy.it.
| Category | Data | Source |
|---|---|---|
| Account | Email, display name, hashed password | You (at signup) |
| Content | Prompts, agent configurations, skills, version history | You (in-app) |
| Collaboration | Team names, memberships, roles, invite email addresses | You and your team |
| Billing | Plan type, subscription status, usage counters | Paddle (via webhooks) |
| Auth tokens | Session cookies (sb-*-auth-token) | Supabase Auth |
| Marketing | Newsletter consent flag and timestamp | You (at signup, optional) |
| Security & usage | IP address, request timestamps, API key identifier, tool name, rate-limit counters | Generated when you use the Service or API |
| Analytics | Pseudonymous product events, user ID, page URLs | Collected only after consent |
| Chrome Extension | API key, cached prompt library, recent prompt identifiers, active-tab hostname, and the current chat composer during insertion verification | Your browser and ParetoStudio account |
We use IP addresses only for security, abuse prevention, rate limiting, and recent MCP activity visible in your account — never for advertising or behavioral profiling. We do not create device fingerprints.
| Processing | Legal Basis | GDPR Article |
|---|---|---|
| Provide the service | Performance of contract | Art. 6(1)(b) |
| Process payments | Performance of contract | Art. 6(1)(b) |
| Send marketing emails | Consent (opt-in at signup) | Art. 6(1)(a) |
| Security logging | Legitimate interest | Art. 6(1)(f) |
The ParetoStudio Chrome Extension uses your API key to fetch your saved prompt library from paretostudio.io over HTTPS. The key, a five-minute prompt cache, and up to ten recent prompt identifiers are stored in chrome.storage.local on your browser. They are used only to authenticate, load, search, and insert the prompts you choose.
The extension processes the active tab hostname locally to determine whether direct insertion is supported. On a supported chat, its content script locates the active message composer, writes the prompt you selected, and reads that composer immediately afterward only to confirm that the insertion succeeded. It does not read conversation history, retain composer content, or transmit chat-page content to ParetoStudio or third parties. On unsupported pages, it copies the selected prompt to your clipboard instead.
ParetoStudio does not sell extension data, use it for advertising, or use it to profile browsing activity. You can delete locally stored extension data by choosing Disconnect account in the extension or by removing the extension from the browser. Revoking the corresponding API key in Settings immediately prevents further API access.
| Provider | Purpose | Region | DPA |
|---|---|---|---|
| Supabase | Authentication, database, storage | EU (AWS eu-west-1, Ireland) | View DPA |
| Paddle | Payment processing (Merchant of Record) | UK/US (EU SCCs) | View DPA |
| Vercel | Hosting, edge functions, cookieless analytics & performance metrics | US (EU SCCs) | View DPA |
| Upstash | Rate limiting (Redis) | EU (AWS eu-west-1) | View DPA |
| Resend | Transactional email (welcome, billing notices, team invitations) | EU (Ireland) | View DPA |
| Sentry | Error monitoring & crash reporting | EU (Germany) | View DPA |
| PostHog | Product analytics (consent-based; no advertising or cross-site tracking) | EU (Ireland) | View DPA |
Payment processing is handled by Paddle, which acts as our Merchant of Record. Any changes to this arrangement will be reflected in this policy.
Your primary data (database, authentication) is stored in the EU (AWS eu-west-1, Ireland). Some sub-processors (Paddle, Vercel) may process data in the US under EU Standard Contractual Clauses (SCCs) as approved by the European Commission. We ensure that all transfers comply with GDPR Chapter V requirements.
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Prompts, agents, skills, and version history | Until you delete them or your account |
| Subscription metadata | Until account deletion |
| Webhook events (logs) | 90 days (auto-deleted) |
| Security and API activity logs | 90 days |
When you delete your account, all your data is permanently removed from our systems (cascading deletion). Paddle retains its own records per its privacy policy and applicable financial regulations.
Under GDPR, you have the right to:
For self-service actions, visit your Settings page. For all other requests, email support@paretostudio.io. We respond to all requests within 30 days as required by GDPR Art. 12(3).
You also have the right to lodge a complaint with the Garante per la protezione dei dati personali.
ParetoStudio uses two categories of cookies:
sb-*-auth-token (Supabase authentication session). Strictly necessary for the service to function. No consent required under ePrivacy Directive Art. 5(3).ph_* (PostHog, EU region). Set only after you accept via the cookie banner. They help us understand how the app is used so we can improve it. You can decline, and nothing analytics-related is stored or sent. We do not load these until you opt in.We do not use advertising or cross-site tracking cookies, and we do not build individual advertising profiles. Our performance monitoring (Vercel Web Analytics & Speed Insights) remains cookieless and aggregated. PostHog analytics are processed in the EU and only with your consent.
You must be at least 14 years old to use ParetoStudio, in accordance with Italian law (D.Lgs. 101/2018, Art. 2-quinquies, implementing GDPR Art. 8). If we become aware that a user is under 14, we will promptly delete their account and data.
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email or an in-app notice. The “Last updated” date at the top indicates when the policy was last revised.
For any questions or concerns about this Privacy Policy, contact us at support@paretostudio.io.