Privacy Policy
This page explains what personal data Dwelvia collects, for what purpose, on what legal basis, and which third-party providers (subprocessors) it is shared with to run the service — including hosting, the database, email delivery and the AI assistant. We process the minimum data needed to run the app and we do not sell it.
Who is responsible for the data
The data controller is the operator of the Dwelvia service (dwelvia.app). For privacy questions and to
exercise your rights, use the in-app feedback form or write to [email protected].
What data we collect
| Category | What exactly | Why |
|---|---|---|
| Account | Email, name (if you sign in with Google), password hash (scrypt — the password itself is not stored) | Sign-in, identification, contact |
| Projects | Floor plans, estimates, settings, sharing and roles | Core function — storing and editing your projects |
| Messages | In-app messages, feedback-form submissions | Support, improving the service |
| AI requests | Your command text + a compact fragment of the active plan | To carry out your command (only when you use the assistant) |
| Technical | IP address, session data, security/error logs | Security, reliability, abuse prevention |
| Referral source | UTM tags, referrer, campaign keyword (first-touch, stored locally in the browser; attached to the account at registration) | To understand where users came from (analytics, NO third-party trackers) |
Legal basis (GDPR)
- Performance of a contract — providing the service (account, storing and processing your projects).
- Legitimate interest — security, abuse prevention, basic diagnostics.
- Consent — for optional features (e.g. you initiate use of the AI assistant yourself).
Who the data is shared with — subprocessors
We engage vetted providers only to the extent needed to run the service. Each processes data under our instructions. Some may process data outside Ukraine/the EU (e.g. the US) — in that case transfers rely on the Standard Contractual Clauses (SCCs) of the respective providers.
| Provider | Role | What it receives |
|---|---|---|
| Fly.io | Hosting/compute (Warsaw region, EU) | All application data while running |
| Cloudflare | CDN, proxy, TLS, protection (WAF); optionally Workers AI | Network traffic; for Workers AI — the AI request text |
| Managed DB (Postgres) | Storing accounts and projects | Account and project data |
| Anthropic (Claude API) | AI assistant (default) | Command text + plan fragment — only when the assistant is used |
| Google (Gemini API) | AI assistant (alternative/optional) | Command text + plan fragment — only if enabled |
| Google (OAuth) | Sign in with Google (optional) | Email and name from your Google account |
| Resend | Sending service emails (confirmations, invites) | Email and message content |
AI assistant — important details
- Optional: AI processing only starts when you address the assistant.
- Minimization: we send your text and a compact fragment of the active plan (the relevant objects) — not your whole account or other projects.
- No AI when possible: synonyms, item lookup and moving furniture are computed on our server without sending anything to any AI provider.
- Free tiers: some providers' free AI plans may use submitted data to improve their models. Therefore do not enter confidential data into the assistant; for sensitive projects use paid tiers / a provider without such use.
Data from Google services (Limited Use)
When you sign in with Google we receive your email and name solely to create and identify your account. Dwelvia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- use this data only to provide and improve the sign-in/account feature you expect;
- do not transfer it to third parties except as needed to provide the service, as required by law, or with your consent;
- do not use it for advertising;
- do not let humans read it, except with your consent, for security (e.g. abuse investigation), or where required by law.
You can revoke Dwelvia's access in your Google account settings (Third-party apps with access).
How long we keep it
Account and project data — as long as your account exists or until you delete it. Technical logs — for the limited time needed for security and diagnostics. After account deletion we delete or anonymize related data, unless the law requires us to keep it longer.
Your rights
Under the GDPR and Ukrainian law you have the right to access your data, rectify, delete, restrict or object to
processing, and to data portability (export a project as a .dwelvia file). To exercise your
rights, use the feedback form or [email protected].
Security
Connections over HTTPS only; passwords stored as a hash (scrypt); session cookies marked HttpOnly;
actions protected by a CSRF token. More about cookies in the Cookie Policy.
Children
The service is not intended for persons under 16; we do not knowingly collect their data.
Changes and contact
We may update this policy; material changes will be marked on this page. This is a baseline template — before a
commercial release it should be reviewed with a lawyer for your jurisdiction. Questions — via the feedback form or
[email protected]. Updated: September 2026.