Privacy policy
Updated
This policy explains how Pavela’s operator, identified below, acts as the controller of your personal data. It covers the website, account, saved goals and support correspondence.
Launch waitlist
Joining the waitlist does not create an account, purchase a plan or authorize payment. With your consent, we save your email, language, selected plan and any goal setup you submit, including numeric settings, milestones, timeframe and building choice, to retain your selections and notify you when Pavela launches. We record the submission time and consent version. Email and IP-derived keyed hashes are used for abuse prevention; rate-limit buckets are removed after 24 hours on subsequent submissions.
You can withdraw consent and request deletion at pavela@support.app. Withdrawal does not affect earlier lawful processing. Waitlist selections are kept while needed to operate the waitlist and send the requested launch notice, or until you withdraw consent. After that purpose ends, we delete the waitlist data unless you separately choose to transfer your selections into a verified account or retention is required by law. We do not automatically create accounts or send unrelated marketing.
1. Information we process
Account information: your email, account identifier, sign-in provider, authentication/session information, display name and language. If you sign in with Google, the authentication provider may receive the basic profile information you authorize, such as your name, email and profile image.
Goal information you provide: names, descriptions, numeric units and values, milestones, notes, dates, timeframes, target changes, completion/reopening history and corrections. We also keep technical identifiers and save receipts to synchronize changes and prevent duplicate writes. A goal may reveal personal information through what you choose to write.
Technical information: providers process network and request information, such as IP address, browser/device details, timestamps and security or error events, to deliver and protect the service. Support correspondence includes the contact details and information you send us. For a purchase, transaction references, amount/currency, payment status and access-plan information are needed to administer payment and access; Pavela does not need your full card number or CVV.
2. Purposes and legal bases
We process account and goal information to perform the agreement with you: signing you in, saving and synchronizing goals, reconstructing history, providing purchased access and handling service requests. Without the necessary account information we cannot provide an account; optional notes and profile details are your choice.
We rely on legitimate interests to secure the service, prevent abuse and duplicate operations, diagnose faults and handle disputes, taking your privacy rights into account. We process records required by accounting, consumer or other applicable laws to meet legal obligations. If a separate optional activity requires consent, we will request it and allow withdrawal without affecting earlier lawful processing.
We do not sell personal data, use your goals for advertising, or make decisions producing legal or similarly significant effects about you solely by automated means. The construction illustration is a representation of your recorded progress.
3. Who receives information
Supabase provides authentication and the PostgreSQL database. Cloudflare provides application hosting, request processing, domain/DNS services, traffic delivery and security. Providers and their subprocessors receive the information needed for those services.
Google handles Google sign-in if you choose it. WayForPay and the banks involved handle a purchase when you pay. These providers also have their own privacy notices for processing they carry out independently. Email providers process support messages and sign-in or account emails sent through them.
Authorized people operating Pavela may access information when necessary for support, security, maintenance or legal obligations. We may disclose information when lawfully required, to protect legal rights or to address fraud. We do not make your goals public by default.
4. Storage locations and international processing
Pavela’s database is configured in Supabase’s Frankfurt region. Provider support, email, network delivery and logs may involve other countries, including countries outside Ukraine and the European Economic Area; a database region does not mean every processing operation stays there.
Where applicable law requires safeguards for an international transfer, these must be provided through an applicable adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful mechanism. Contact us to request information about the safeguards relevant to your data.
5. Cookies and browser storage
Authentication cookies maintain sign-in and secure the login flow. Their lifetime is controlled by the authentication provider and they may be refreshed while you use the service; the installed client sets a maximum cookie age of 400 days. Language cookies STILL_LOCALE and PAVELA_LANGUAGE retain your language choice for up to one year. You can clear or block cookies in your browser, but blocking authentication storage can prevent sign-in.
The current tab’s session storage holds your pre-sign-in goal setup and plan selection, the email sign-in step and unresolved save requests so they can be retried. Setup drafts are accepted for up to seven days and the email step for one hour; remaining session-storage items are normally removed when the tab/session closes or the operation finishes. These drafts can contain goal text and notes. You can clear them in your browser. Existing data left by an earlier browser-only version is not automatically uploaded to your account.
We do not currently use advertising cookies or optional analytics trackers in the application. Necessary provider request logs and security processing are described above. If we introduce optional tracking, we will update this notice and obtain consent where required.
6. Retention and deletion
Account and goal data are kept while your account remains open, unless you delete the relevant goal or request account deletion. Correction history remains with the goal until deletion. Deleting a goal removes its saved content and associated correction evidence; minimal save/import identifiers and fingerprints may remain until account deletion to prevent a retry from recreating it. Inactivity alone does not currently delete an account.
Request account deletion from your sign-in email. After verifying ownership, we remove the account’s goals, preferences and authentication account. Any records that must be retained for accounting, legal obligations or an unresolved dispute are limited to what is necessary for that purpose and retained only as long as required. Support correspondence is kept while needed to resolve the request and any related obligations or claims. Provider logs and any provider backup copies follow the applicable provider retention and deletion cycles; deletion from every historical copy is not instantaneous.
Images you download or send to others, and browser data on your device, remain under your control. Deleting your Pavela account cannot recall copies you have already shared. Contact support about subscription cancellation alongside a deletion request.
7. Security and sharing
We use encrypted transport, server-side identity checks and account ownership controls to protect stored goals. Access is limited to what is needed to operate the service. No system can guarantee absolute security. Keep your email and device secure, and do not put passwords, card credentials or other people’s sensitive information into notes.
Share cards are generated on your device. Downloading a PNG does not publish it through Pavela. If you use your device’s share function, you choose the destination, and that service’s own rules then apply.
8. Your rights and requests
Subject to applicable law, you can request access and a copy, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it. You can edit your profile and goals in the app; contact us for the other requests, including account deletion or a machine-readable copy.
Email pavela@support.app, preferably from your sign-in address. We may need proportionate verification of account ownership. Do not send a password, one-time code or full payment-card details. We respond without undue delay and within the period required by the law applicable to your request; GDPR requests are normally answered within one month, with any lawful extension explained.
You may complain to the Ukrainian Parliament Commissioner for Human Rights or the competent data-protection authority in your country where applicable. You do not have to contact us first. The service is not directed at children. If you believe a child’s data was provided without appropriate authorization, contact us.
9. Policy updates
We will update the date when this policy changes and bring material changes to your attention. A new purpose requiring a different legal basis will not be introduced merely by changing this notice.
Service provider and contacts
- Registered name
- ФОП Гнатишин Вячеслав Юрійович
- Legal form
- Individual entrepreneur registered in Ukraine (ФОП)
- Ukrainian tax identification number
- 3709204411
- Registered and business address
- 10 Shevchenka Street, Ivano-Kepyne village, Bashtanka district, Mykolaiv region, 57315, Ukraine
- Phone
- +380665133872
- Support, privacy and complaints
- pavela@support.app
- Website
- pavela.app