PRIVACY · EFFECTIVE 6 SEPTEMBER 2026

Privacy Policy

This Privacy Policy explains how Daniel Rossi Marinho - Unipessoal Lda, operating as CONSELA (“CONSELA”, “we”, “us”), processes personal data through consela.ai and the CONSELA application (the “Service”). VAT/NIPC: PT519202120 / 519202120. Our legal identity and contact details are available on our Legal Information page.

1. Roles

For account, billing, security, support and direct product-operation data, CONSELA is generally the data controller. When an organization uses the Service to upload or process information about its personnel, customers or other individuals, the organization may be the controller and CONSELA may act as its processor. A separate Data Processing Addendum applies to business customers where appropriate.

2. Data we collect

  • Account data: name, email, password credentials, verification state and organization membership.
  • Workspace data: organization, project and meeting names, descriptions, prompts, documents, reports, transcripts, consensus documents, chats, notifications and permissions.
  • Support data: tickets, privacy-request classifications, messages and attachments.
  • Billing metadata: plan, entitlement and subscription status, Stripe customer/subscription identifiers, billing-period dates, usage and webhook/compliance references. Stripe is the billing system of record and manages payment details, invoices and subscription management; CONSELA does not store full card numbers.
  • Technical and security data: IP address, authentication events, rate-limit/anti-abuse signals, browser/device information, logs, job identifiers, error reports and audit events.
  • Communications: service emails and account notices. CONSELA does not currently send marketing communications.

3. How we use data

  • Provide, secure and troubleshoot the Service.
  • Create and manage accounts, organizations, invitations and permissions.
  • Run meetings, web research, AI analysis, follow-up conversations and generated documents at the user’s request.
  • Process subscriptions, invoices, taxes, refunds and fraud prevention.
  • Respond to support requests and communicate service changes.
  • Prevent abuse, protect users and investigate security incidents.
  • Measure reliability and improve the Service where permitted and disclosed. We do not use customer meeting content to train general-purpose models unless a customer separately agrees in writing.
  • Comply with legal obligations and establish, exercise or defend legal claims.

4. Legal bases for EEA users

Depending on the activity, we rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is required. We will not treat optional marketing or non-essential tracking as necessary for the contract.

5. United States privacy disclosures

Where applicable US state privacy law applies, we collect the following categories of personal information: identifiers and contact details; commercial and subscription information; internet or network activity and device information; professional or organization information; user-generated workspace content; and inferences or preferences derived from your use of the Service. We collect these categories from you, your organization, identity or sign-in providers, service providers, and your device or browser.

We use these categories to provide and secure the Service, authenticate users, administer organizations and subscriptions, process payments, provide support, conduct requested research and AI operations, prevent abuse, communicate service information, and comply with law. We disclose them to hosting, email, payment, security, AI-inference and research providers for these business purposes. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information outside the purposes permitted by applicable law. We do not have actual knowledge that we sell or share personal information of consumers under 16.

Depending on the applicable law, you may have rights to know or access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising or certain profiling, limit sensitive-personal-information use, and appeal a denied request. Submit a request through your account where available or by email to admin@consela.ai. We may reasonably verify your identity using your account, account email, or information necessary to protect your data. We generally respond to California requests within 45 days and may extend once by another 45 days when permitted, with notice. If we deny a request, you may appeal by replying to our decision or emailing us with “Privacy appeal” in the subject line. We do not discriminate against you for exercising applicable privacy rights.

6. AI and external services

Meeting prompts, uploaded content and relevant context may be sent to our AI provider to produce the requested result. AI inference is configured to use provider routes that offer zero data retention for prompts and outputs. Web-research providers receive generated search queries and necessary request metadata; they do not receive the full brief or uploaded documents as a separate research payload. Because a generated query may contain workspace-derived information, users should avoid including personal data, credentials or information they do not want disclosed to a search provider. Web-research provider policies and retention practices differ. See the Subprocessor List and AI Disclosure for provider-specific details. Providers may process data outside the EEA.

7. Sharing

We share data with service providers acting under instructions, with organization members according to workspace permissions, when a user creates a share link, when required by law, or during a business transaction such as a merger or acquisition. We do not sell personal information or share it for cross-context behavioural advertising. Whether any provider activity constitutes “sharing” under a US state law is assessed separately.

8. International transfers

We use appropriate safeguards for restricted transfers, which may include an adequacy decision, Standard Contractual Clauses, a Data Processing Addendum and supplementary measures. Provider-specific transfer details are described in the Subprocessor List and may change when providers or routes change.

9. Retention

We retain personal data only for as long as necessary for the purposes described here. A verified member-account deletion request is scheduled for processing after a 14-day grace period. The member may cancel the request before processing begins; when eligible, processing removes access and anonymizes the account while preserving organization-owned content. Project deletion requests are scheduled for 14 days, hide the project immediately, and can be cancelled by restoring the project during the grace period. At the end of that period, project meetings, reports, files and related content are permanently purged unless a documented legal or security hold applies. Organization deletion requests are scheduled for 14 days. Organization changes and invitations are disabled immediately, and the request may be cancelled during the grace period. After that period, the organization is quarantined for 30 days for export, security and retention processes, then its projects and organization-owned records are permanently purged unless a documented legal or security hold applies. Operational, accounting and legal records may be retained for their stated or legally required periods, with the deleted organization reference removed where appropriate. Encrypted infrastructure backups stored in Cloudflare R2 are retained on a rolling 30-day schedule. Security and anti-abuse logs are retained for up to 12 months. Support records are retained for up to 24 months after resolution. Billing, accounting, legal-acceptance and incident records may be retained for legally required periods. Normal AI sessions and traces are not retained after processing unless an administrator explicitly enables a debug trace, which expires after 14 days. Research-provider retention follows the applicable provider policies and account settings. CONSELA does not retain raw research-provider response payloads as a separate research database; citations and generated conclusions may remain in workspace content according to the retention rules above.

Product activity retention: Daily activity aggregates are retained for 90 days and then deleted. These aggregates do not include IP addresses, URLs, request content, prompts, documents, user agents or advertising identifiers.

10. Security

We use access controls, authentication protections, encryption in transit, encryption at rest for project files and extracted-text sidecars, tenant authorization and operational monitoring appropriate to the risk. Authorized administrators may access support content and, where necessary, account or workspace content to investigate or resolve a support request, security incident or service failure. Access may include support messages and attachments and is limited by application roles and support workflows. No internet service is completely secure. Suspected incidents should be reported to admin@consela.ai.

11. Your rights

Subject to legal limits, EEA residents may request access, correction, deletion, restriction, portability and objection, and may withdraw consent. US residents may have rights under applicable state laws, including the rights described in section 5. Use the Your Data Rights page or email us. You may complain to your local data-protection authority.

12. Children

The Service is intended only for people aged 18 or older who are legally able to enter a contract. We do not knowingly offer, market or maintain accounts for anyone under 18. We collect an adult-eligibility attestation at registration to document the user’s representation, but this is not identity or age verification. Contact us if you believe a minor has provided personal data so we can suspend and review the account.

13. Cookies

See our Cookie Policy. Strictly necessary cookies may be used to operate the Service; non-essential analytics or advertising technologies require consent where applicable.

14. Changes

We may update this policy and will publish the new version and effective date. Material changes may also be communicated through the Service or email.

15. Contact

Privacy requests and questions: admin@consela.ai. CONSELA is established in Portugal and does not currently appoint a separate EU representative or data-protection officer. Full legal contact details are available on our Legal Information page.