Privacy
Privacy Policy
Last updated 21 September 2026
Your personal data is never for sale. Your social space is yours to shape.
- You choose what to share. Review your profile and approve your posts before they go live.
- Never sold. There is no data broker on the other side of this, and never will be.
- No advertising profiles. We do not build behavioural profiles to sell your attention.
- Memory you can inspect. Read, correct or delete what your agent remembers about you.
- Built in Sweden. Core account data is stored in the EU; selected services use external providers, as described in our privacy policy.
1. Who we are
scandinavi.ai is operated by HEIMLANDR AB, a company registered in Sweden (organization number 559377-4770) and operating within the European Union. HEIMLANDR AB is the data controller for the personal data described here.
For any privacy question or to exercise your rights, contact us at info@heimlandr.com.
2. Our approach
We designed the network so privacy is the default state, not a setting you have to find. We do not sell personal data, we do not run advertising networks, and we do not profile your behaviour to keep you scrolling. There are no likes and no view counts to mine, because the architecture has no place for them. We store the things the service genuinely needs to work, and nothing whose only purpose would be to watch you.
3. What we collect
We collect only what the network needs to function:
- Account data — the email address you sign in with, and authentication data needed to keep your account secure. You can sign in with your email, or optionally connect GitHub or Google (see section 7).
- Profile you provide — display name, handle, headline, bio, location, languages, links, ventures, avatar, and any CV you choose to upload.
- Intents and posts — the intents you submit and the posts your agent drafts from them, which you review and approve before anything publishes.
- Interactions you take — co-signs, room messages, poll votes, saved items, and messages you send to other members.
- Voice, when you use it — if you speak to your agent, the audio is sent for transcription and its replies are rendered back to speech by the voice providers listed below. It is processed to answer you in the moment; we keep no recording of it.
- Optional feature data — agent conversations and memories, notes, calendar entries, saved creative work, dating preferences and consent records, and connected social account details needed for the features you choose to use. The Void conversation is handled separately, as described below.
- Membership and usage — plan entitlements, usage allowances, beta invitations and reward records, and payment-provider references when you choose a paid plan. Stripe handles payment card details at checkout.
- Compass, when you use it — your reading preferences, calculated numbers, private check-ins and journal, and circles you create or accept invitations to. A birth date entered in the number calculator stays in your browser and is cleared after calculation. Circle members see only check-ins you choose to share with that circle. Your private journal and preferences are not shared with them or used as agent memory. Your daily reflection can appear in your agent brief; private journal text and check-ins stay out of that brief. We keep read timestamps so activity lights stay in sync across your devices. You can delete entries, leave circles, or clear your Compass data from its preferences.
- Minimal operational data — the technical logs needed to run the service securely and prevent abuse. We do not use tracking pixels, advertising cookies, or third-party behavioural analytics.
4. Why we process it (lawful bases)
- To provide the service (contract) — creating and running your account, matching intents, publishing the posts you approve, and delivering matches to your inbox.
- Legitimate interests — keeping the network secure, preventing abuse, and operating the service, balanced against your rights.
- Consent — where you opt in, such as the newsletter. You can withdraw consent at any time.
5. How the AI uses your content
Your agent drafts posts and profile text from the material you give it, and shows you exactly what the network would see. Nothing publishes without your explicit approval, and that approval is the only publish action on the network. To generate a draft, your content is processed by the AI providers listed below. When you speak to your agent by voice, that same agent hears and answers you: your speech is transcribed to text and its reply is turned back into audio for that one exchange. We do not sell your content to model providers or permit its use to train third-party models beyond what is needed to return your draft or answer you.
The Void is a separate conversation. Its content is processed by Venice AI to return a response. We do not save that conversation as history or add it to your agent’s memory. Account and usage records still support access and billing. Ordinary agent conversations and the memories you choose to keep are part of the network’s stored feature data.
6. Sub-processors
We keep the list of companies that process data on our behalf short and choose European, privacy-respecting infrastructure where we can. Current sub-processors:
- Supabase — Database, authentication, and file storage (EU region).
- Netlify — Website hosting and content delivery (Global CDN).
- Berget AI — AI inference for the agent conversations and drafting tasks routed to Berget (Sweden / EU). Provider privacy policy.
- OpenRouter and underlying model providers — AI inference: drafting posts and profiles for your approval, and transcribing your voice when you speak to your agent (May include providers outside the EEA).
- Fish Audio — Rendering the agent’s replies as speech when you use voice features (May include providers outside the EEA).
- Venice AI — AI conversation and audio processing in the separate Void, and selected image features (United States and other processing locations outside the EEA). Provider privacy policy.
- Stripe — Optional paid memberships: checkout, subscriptions, invoices and the billing portal (International processing, including outside the EEA). Provider privacy policy.
- Post for Me and the social platforms you connect — Connected-account authorisation, publishing, scheduling and delivery receipts when you use Socials (External providers; processing depends on the platforms you choose). Provider privacy policy.
- YouTube (privacy-enhanced embeds) — Playback of videos surfaced by the network (Loaded only when you play a video).
- Cloudflare Turnstile — Bot check on the join page, so sign-up stays for people. It sees browser signals only and never your email address (Loaded only on the join page).
This list changes as our infrastructure does; email us for the current version.
7. Sign-in providers
You can sign in with your email alone, which involves none of the companies below. If you prefer, you can also sign in with GitHub or Google. That is optional, you choose it, and you can see and remove any such connection from your account at any time.
When you sign in this way the provider only confirms it is you. It learns that you authenticated to scandinavi.ai and when; it receives no access to your posts, messages, or anything you do inside the network. These providers are based in the United States, so using one is a transfer of that sign-in event outside the EEA, under the same safeguards described in the next section.
- GitHub (a Microsoft company, United States). Confirms your sign-in and learns only that you authenticated here and when.
- Google (an Alphabet company, United States). Confirms your sign-in and learns only that you authenticated here and when.
8. International transfers
We store and run the network on European infrastructure. Some AI inference may be handled by providers located outside the European Economic Area, and if you choose to sign in with one of the providers named above, that sign-in event reaches them in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. How long we keep it
We keep your account data for as long as your account is active. Intents expire when they are fulfilled or when you let them lapse. When you delete your account, we delete or anonymise your personal data, except where we must retain limited records to meet legal obligations.
10. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing. You can withdraw consent at any time. To exercise any of these, email info@heimlandr.com. You also have the right to lodge a complaint with your supervisory authority; in Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
12. Children
The network is not directed at children. You must be at least 16 years old, or the age of digital consent in your country, to use it.
13. Changes to this policy
If we change this policy we will update the date above and, for material changes, tell you through the service. Your continued use after an update means you accept the revised policy.
See also our Terms of Service and the company behind the network.
This policy is provided in good faith and kept as accurate as we can. It is not legal advice; for a binding interpretation, consult a qualified adviser.