Privacy Policy
Seven Chairs — the AI team for founders
Effective date: 28 July 2026 Last updated: 28 July 2026
The short version. Seven Chairs is a tool you trust with real information about your business — so we keep this simple and honest. We collect what the product needs to work, and nothing more. Your conversations and business details are used to run your AI team — never to train AI models, never sold, never used for advertising. Everything the app remembers about you is visible, editable, and deletable inside the app. This policy explains the details.
1. Who we are
Seven Chairs (the "App", the "Service") is operated by:
IscoviciLabs Hakishon St., Tel Aviv, Israel Contact: support@sevenchairs.ai
For data-protection law (including the EU/UK GDPR and Israel's Protection of Privacy Law), we are the controller of the personal data described in this policy.
2. What this policy covers
This policy covers the Seven Chairs mobile app and the backend services that power it. It does not cover third-party services you reach through your own accounts (for example, the Google Play or Apple App Store purchase screens, which are governed by Google's and Apple's own policies).
3. What we collect
3.1 Account information
| Data | Where it comes from |
|---|---|
| Email address | You (email sign-in) or your Google/Apple account |
| Name and profile picture | Your Google account, if you sign in with Google (Apple, if you choose to share it) |
| Account identifiers | A random user ID we create for your account |
We never see or store your passwords for Google or Apple — sign-in happens with those providers directly.
3.2 Your business content — the heart of the product
Seven Chairs is built around an AI team that remembers your business. To do that, we process and store:
- Conversations — the messages you exchange with the AI team. Full chat threads are stored on your device. Our servers process messages in transit to generate replies, and store short session summaries so your team keeps context between conversations.
- Structured memory — facts the AI extracts from your conversations with your knowledge: business facts, goals, decisions, commitments, and a short founder bio. All of it is shown to you in the app (You → Your memory), where you can edit or delete any item. There is no hidden profile.
- Business metrics — numbers you enter yourself in the Cockpit: monthly recurring revenue, user count, expenses, cash on hand, and your revenue goal.
- Accountability data — goals, commitments, check-ins, and streaks.
This content can be deeply personal and commercially sensitive. We treat it that way: it is used only to provide the Service to you (see Section 5), is never sold, never used for advertising, and never used to train AI models — ours or anyone else's.
3.3 Purchase and subscription information
If you subscribe to Pro, we receive subscription status and purchase history (which plan, which store, when it renews or expires) from the app stores via RevenueCat, our subscription-management provider. We never receive or store your payment card details — payment is handled entirely by Google Play or the Apple App Store.
3.4 Usage and technical information
- Service usage records — to run fair usage limits and our message allowance, we record per-account usage events (for example, message counts and AI token counts per feature) and a message-credit balance.
- Technical data — standard server logs (including IP address and timestamps, kept briefly for security and reliability), and basic device information processed by our service providers (for example, device model and OS version, used by our subscription provider to manage purchases).
- Settings stored only on your device — your chosen coaching tone, active teammate, reminder preference, and revenue goal live on your device and are not transmitted to us as profile data.
3.5 What we do not collect
- No advertising identifiers, and no advertising or tracking SDKs.
- No contacts, no location, no microphone, no camera, no photos.
- No payment card numbers.
- No cross-app or cross-site tracking of any kind.
- No third-party analytics today. If we add product analytics in the future, it will be opt-in, clearly asked in the app, and described in Section 9.
4. AI processing — how your data meets the models
When you send a message, the App sends the conversation context — together with relevant items from your structured memory and, where relevant, your business metrics — to our backend, which calls a large language model (currently Anthropic's Claude models, routed through Vercel's AI Gateway) to generate your team's reply.
What matters most:
- No training. Our AI providers process your content to generate the reply and do not use it to train their models, under the commercial terms we use them on.
- Transient processing. Model inputs and outputs are processed to serve your request; we do not operate any advertising or profiling pipeline on them.
- Privacy-safe logging. Our servers are built not to write your conversations or memory into logs — error logging is deliberately restricted to technical summaries.
- AI outputs are informational only and can be wrong. See our Terms of Service for the important disclaimers about relying on AI outputs.
5. Why we process your data (purposes and legal bases)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Service: run your AI team, remember your business, show your metrics | Account info, business content, metrics | Performance of a contract (Art. 6(1)(b)) |
| Authentication and account management | Account info | Contract |
| Billing, subscriptions, message allowance and fair-use limits | Purchase info, usage records | Contract; legal obligation for billing records |
| Security, abuse prevention, rate limiting | Technical data, usage records | Legitimate interests (Art. 6(1)(f)) — keeping the Service safe |
| Service communications (sign-in codes, important notices) | Contract | |
| Product analytics (only if we add it — see Section 9) | Usage events | Consent (Art. 6(1)(a)) — off unless you opt in |
| Legal compliance and defense of claims | Minimum necessary | Legal obligation; legitimate interests |
We do not use your data for third-party advertising, and we do not sell it (see Section 12 for the California-specific statement).
6. Who processes data for us
We use a small number of service providers ("processors") to run Seven Chairs. They may only process your data on our instructions, to provide their service to us:
| Provider | What they do for us | Where |
|---|---|---|
| Supabase | Database and authentication (your account, memory, metrics, usage records) | United States (AWS us-east-1) |
| Vercel | Hosts our backend API and server logs | United States / global edge |
| Anthropic (via Vercel AI Gateway) | Generates AI replies from the context we send | United States |
| RevenueCat | Subscription management and receipt validation | United States |
| Google Play / Apple App Store | Payment processing, sign-in (if you choose Google/Apple sign-in) | Per their policies |
| Resend (planned — from the moment we send sign-in emails through it) | Sends sign-in codes and service emails | United States |
| PostHog (planned — only with your opt-in consent, see Section 9) | Product analytics | European Union |
| Sentry (planned — if we add crash reporting) | Crash and error reporting | United States / EU |
Beyond processors, we disclose personal data only: (a) if required by law, court order, or enforceable governmental request; (b) to protect the rights, safety, or property of our users, the public, or us; or (c) as part of a merger, acquisition, or asset sale — in which case this policy continues to apply to your data and we will notify you of any change of controller.
7. International transfers
We operate from Israel; our main processors are in the United States; you may be anywhere.
- EU/UK → Israel: Israel benefits from an EU adequacy decision (reaffirmed by the European Commission in 2024) and UK adequacy regulations, so your data may be processed in Israel with the same level of protection recognised by EU/UK law.
- Transfers to the US and elsewhere are protected by appropriate safeguards — the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU-U.S. Data Privacy Framework.
- From Israel, transfers abroad are made in accordance with the Israeli Privacy Protection (Transfer of Data Abroad) Regulations.
8. How long we keep data
| Data | Retention |
|---|---|
| Account, memory, metrics, accountability data | While your account exists; deleted within 30 days of account deletion |
| Chat threads | On your device — removed when you sign out, delete the app, or clear them |
| Session summaries | While your account exists; deletable in-app; removed with account deletion |
| Usage and billing records | Up to 7 years where needed for tax, accounting, and billing-dispute obligations |
| Server logs | Approximately 30 days |
| Backups | Rotated on a schedule; deleted data leaves backups within 90 days |
9. Analytics and consent
Today, the App contains no third-party analytics or tracking SDK. The only usage measurement is first-party service telemetry needed to run the product (Section 3.4).
If we introduce product analytics (to understand which features help founders most), we will: use a privacy-respecting provider configured to host data in the EU; disable session recording and text capture in conversations; and — most importantly — ask you first. Analytics will be off unless you opt in, and a switch in the app will let you change your mind at any time. Because the App uses no cookies and no cross-app tracking, you will not see cookie banners in the App — the in-app consent choice is the equivalent control.
Our marketing website (when it launches) will carry its own cookie notice for any website analytics.
10. Security
- Every user's data is isolated with row-level security — your account can only ever read its own rows, enforced in the database itself.
- Data is encrypted in transit (TLS) and at rest.
- Secrets and service credentials are never shipped in the app and never logged; privileged server credentials are restricted to server-side use.
- Server logging is deliberately PII-safe by design: conversations and memory are excluded from logs.
- Payment webhooks are authenticated; unauthenticated calls are rejected.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by law (including the 72-hour GDPR standard and Israeli breach-reporting requirements).
11. Your rights and controls
Built into the app (fastest):
- See and edit everything the AI remembers: You → Your memory — view, edit, or delete any item.
- Your metrics and goals are editable in the app.
- Sign out clears device-local settings.
- Delete your account: see our account deletion page — an in-app deletion flow is rolling out; the email route works today.
Under the GDPR / UK GDPR (if you are in the EEA/UK) you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time (for anything based on consent, like optional analytics). You may lodge a complaint with your local supervisory authority.
Under Israel's Protection of Privacy Law, you have the right to inspect information held about you and to request correction or deletion, and you may complain to the Privacy Protection Authority.
Under the CCPA/CPRA (California): you have the rights to know, delete, correct, and to opt out of "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We will never discriminate against you for exercising your rights. (Categories collected, per the CCPA taxonomy: identifiers; commercial information; internet/electronic activity; and the user content described in Section 3.2 — for the purposes in Section 5, from the sources in Section 3, disclosed only to the service providers in Section 6.)
To exercise any right, email support@sevenchairs.ai from the address linked to your account (or include enough information for us to verify you). We respond within 30 days (45 for CCPA, extendable as the law allows). You may use an authorized agent where the law provides for one.
12. Do Not Sell or Share
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is no advertising in Seven Chairs.
13. Children
Seven Chairs is a business tool for adults. It is not directed to anyone under 18, and you may not use it if you are under 18. We do not knowingly collect data from children; if you believe a child has provided us personal data, contact us and we will delete it.
14. Automated decision-making
We do not make automated decisions about you that produce legal or similarly significant effects. The AI generates suggestions and analysis for you to evaluate — you decide. Message allowances and rate limits are applied automatically as part of the service you signed up for, and are not profiling.
15. Changes to this policy
We will post any changes here and update the date above. For material changes, we will tell you in the app or by email before they take effect. Continued use after the effective date means the updated policy applies.
16. Contact
Questions, requests, or complaints: support@sevenchairs.ai. We read everything.
This policy is provided in English. Summaries in other languages, if any, are for convenience — the English version controls.