Privacy Policy
Seven Chairs — the AI team for founders
Effective date: 28 July 2026 Last updated: 7 September 2026
The short version. Seven Chairs is a tool you trust with real information about your business — so we keep this simple and honest. We collect what the product needs to work, and nothing more. Your conversations and business details are used to run your AI team — never to train AI models, never sold, never used for advertising. Your advisors are AI: answering you means sending what you write to Anthropic and Vercel, and the App asks your permission before any of it goes (Section 4). Everything the app remembers about you is visible, editable, and deletable inside the app. This policy explains the details.
1. Who we are
Seven Chairs (the "App", the "Service") is operated by:
IscoviciLabs Hakishon St., Tel Aviv, Israel Contact: support@sevenchairs.ai
For data-protection law (including the EU/UK GDPR and Israel's Protection of Privacy Law), we are the controller of the personal data described in this policy.
2. What this policy covers
This policy covers the Seven Chairs mobile app and the backend services that power it. It does not cover third-party services you reach through your own accounts (for example, the Google Play or Apple App Store purchase screens, which are governed by Google's and Apple's own policies).
3. What we collect
3.1 Account information
| Data | Where it comes from |
|---|---|
| Email address | You (email sign-in) or your Google/Apple account |
| Name and profile picture | Your Google account, if you sign in with Google (Apple, if you choose to share it) |
| Account identifiers | A random user ID we create for your account |
We never see or store your passwords for Google or Apple — sign-in happens with those providers directly.
3.2 Your business content — the heart of the product
Seven Chairs is built around an AI team that remembers your business. To do that, we process and store:
- Conversations — the messages you exchange with the AI team. Full chat threads are stored on your device. Our servers process messages in transit to generate replies, and store short session summaries so your team keeps context between conversations.
- Structured memory — facts the AI extracts from your conversations with your knowledge: business facts, goals, decisions, commitments, and a short founder bio. All of it is shown to you in the app (You → Your memory), where you can edit or delete any item. There is no hidden profile.
- Business metrics — numbers you enter yourself in the Cockpit: monthly recurring revenue, user count, expenses, and cash on hand. Your revenue goal is the exception: it is a line drawn on your own chart and stays on your device (Section 3.4).
- Accountability data — goals, commitments, check-ins, and streaks.
This content can be deeply personal and commercially sensitive. We treat it that way: it is used only to provide the Service to you (see Section 5), is never sold, never used for advertising, and never used to train AI models — ours or anyone else's.
3.3 Purchase and subscription information
If you subscribe to Pro, we receive subscription status and purchase history (which plan, which store, when it renews or expires) from the app stores via RevenueCat, our subscription-management provider. We never receive or store your payment card details — payment is handled entirely by Google Play or the Apple App Store.
3.4 Usage and technical information
- Service usage records — to run fair usage limits and our message allowance, we record per-account usage events (for example, message counts and AI token counts per feature) and a message-credit balance.
- Technical data — standard server logs (including IP address and timestamps, kept briefly for security and reliability), and basic device information processed by our service providers (for example, device model and OS version, used by our subscription provider to manage purchases).
- Settings kept on your device — your chosen coaching tone, which teammate you last spoke with, and your revenue goal are kept in the app's own storage on your device, not against your account. Two of them still travel when you use the app: the tone and the active teammate are sent with each message, because they decide how the reply is written and who writes it. The tone is used for that request and not stored; the teammate is recorded in the usage records above, as which advisor a message went to. Your revenue goal never leaves the device at all.
- Notification preferences are stored on our servers — your quiet hours, a preferred reminder hour if you set one, the four switches for what your team may reach out about, and your device timezone. The job that decides whether to reach out runs on our servers rather than on your phone, so it has to read them there (Sections 3.5 and 8).
3.5 Push notifications and reminders
If you allow notifications, we store this device's Expo push token — an address for the device, issued by Expo, not a name or an identity — and your device timezone, so a reminder arrives in your morning rather than ours. An hourly job on our servers then asks whether there is anything worth saying. Almost always there is not, and nothing is sent. At most one notification a day.
When there is something to say, the message is sent to Expo's push service (Section 6), which relays it towards your device. That message quotes you. A commitment reminder is built around the title you typed: the body reads You said “…” today. Still on?, with your own commitment where the … is, and — when more than one is due that day — how many others. A reminder about a commitment that slipped puts your title in the same place, in whichever coaching tone you chose. A streak reminder carries the number of days. A commitment is one of the memory items listed in Section 3.2, so that is a real disclosure, not a formality. It is also the only one: no business fact, goal, decision, session summary, or founder bio is ever put into a notification, and neither are your chat messages or your Cockpit numbers.
Getting those words onto your screen means two more companies handle them. Expo passes the notification to Apple's push service on an iPhone or iPad, and to Google's on an Android device — that is the only way a notification reaches a phone at all. Expo names both as its own sub-processors, for “Sending push notifications to users”. Neither is our processor, and we do not claim they hold that text to the same standard our processors do: the note under the table in Section 6 explains why we cannot. The app says the same thing before it asks you for notification permission, and again on the card where you change it.
If you would rather your own words did not travel that way, you choose which of these your team may send — and can turn all of them off — in the app (You → When your team reaches out), or in your device's notification settings.
3.6 What we do not collect
- No advertising identifiers, and no advertising or tracking SDKs.
- No contacts, no location, no microphone, no camera, no photos.
- No payment card numbers.
- No cross-app or cross-site tracking of any kind.
- Third-party product analytics runs only with your opt-in consent — asked clearly in the app, never on by default (Section 9). Crash reporting keeps the app stable and never carries your conversations (Section 9).
4. AI processing — how your data meets the models
We ask first, and nothing goes until you say yes. Before your team can answer you, the App shows a screen listing exactly what would be sent and who receives it, and asks. Until you say yes, nothing you write reaches Anthropic or Vercel: your advisors stay quiet and the rest of the App keeps working. You can change the answer at any time. Because the ask comes before you sign in, the same control sits in two places under the same name: What your team sends on the sign-in screen, for anyone who says no and stops there, and You → What your team sends once you are signed in.
Once you have said yes, sending a message sends the conversation context — together with relevant items from your structured memory and, where relevant, your business metrics — to our backend, which calls a large language model (currently Anthropic's Claude models, routed through Vercel's AI Gateway) to generate your team's reply. The consent screen itself carries the full list of what travels. A gateway can normally serve the same Claude model from more than one company's infrastructure — Anthropic's own, or a cloud provider's copy of it. Ours is not allowed to: every request we send names Anthropic as the only provider permitted to answer it, which is what makes the two-company list above a fact about our configuration rather than a hope about how the Gateway routes.
The answer is recorded on the device, so the App asks again on each device you install it on. Your memory, business facts, goals and metrics belong to your account rather than to a device — so if you say yes on one device, the context your account holds can be sent from that device even if you said no on another. To stop all sending, answer no on each device you use.
Saying no does not mean the App stops using our servers. Your account, your setup answers, the business facts and memory your team keeps, your goals, commitments, check-ins and Cockpit numbers are stored on our own backend (Supabase — Section 6) whichever way you answer, so they are there on your next session and your next device. What the answer controls is whether any of it, and anything you write, leaves us for Anthropic and Vercel.
What matters most:
- No training. Our AI providers process your content to generate the reply and do not use it to train their models, under the commercial terms we use them on.
- Transient processing. Model inputs and outputs are processed to serve your request; we do not operate any advertising or profiling pipeline on them.
- Privacy-safe logging. Our servers are built not to write your conversations or memory into logs — error logging is deliberately restricted to technical summaries.
- AI outputs are informational only and can be wrong. See our Terms of Service for the important disclaimers about relying on AI outputs.
5. Why we process your data (purposes and legal bases)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Service: run your AI team, remember your business, show your metrics | Account info, business content, metrics | Performance of a contract (Art. 6(1)(b)) |
| Authentication and account management | Account info | Contract |
| Billing, subscriptions, message allowance and fair-use limits | Purchase info, usage records | Contract; legal obligation for billing records |
| Security, abuse prevention, rate limiting | Technical data, usage records | Legitimate interests (Art. 6(1)(f)) — keeping the Service safe |
| Service communications (sign-in codes, important notices) | Contract | |
| Sending the reminders you turn on (see Section 3.5) | Commitments, goals, check-in history, device push token and timezone | Contract — the accountability features you asked for |
| Product analytics (see Section 9) | Usage events | Consent (Art. 6(1)(a)) — off unless you opt in |
| Crash and error reporting (see Section 9) | Technical data (crash reports, device model, app version) | Legitimate interests (Art. 6(1)(f)) — keeping the app working |
| Legal compliance and defense of claims | Minimum necessary | Legal obligation; legitimate interests |
We do not use your data for third-party advertising, and we do not sell it (see Section 12 for the California-specific statement).
6. Who processes data for us
We use a small number of service providers ("processors") to run Seven Chairs. They process your personal data only for the purposes we set, and they are bound to keep it confidential.
And one thing that sentence on its own would hide. Six of the companies below — Vercel, Supabase, Sentry, Expo, PostHog and RevenueCat — reserve in their own published terms the right to use technical, telemetry, aggregated or de-identified data from running their service to operate and improve it: error counts, request volumes, usage statistics. Those are terms we accepted, not terms we negotiated away, and you can read them on each company's own site in a couple of minutes — so we would rather name them here than let the line above imply we had them removed. What those clauses reach is that class of data. They are not a licence to your conversations or your memory: that content is processed for the purposes we set, and the two companies that see what you write to your team — Anthropic and Vercel — are barred from training on it by the commercial terms we use them on (Section 4).
| Provider | What they do for us | Where |
|---|---|---|
| Supabase | Database and authentication (your account, memory, metrics, usage records) | United States (AWS us-east-1) |
| Vercel | Hosts our backend API and server logs | United States / global edge |
| Anthropic (via Vercel AI Gateway) | Generates your team's replies from the context we send. Every request names Anthropic as the only provider allowed to answer it, so the Gateway cannot hand it to another company's copy of the model (Section 4) | Anthropic's own infrastructure — we call its API and do not choose a region |
| RevenueCat | Subscription management and receipt validation | United States |
| Apple — the App Store, push delivery, and Sign in with Apple if you use it | Takes payment for subscriptions bought on iOS. Delivers our notifications to iPhones and iPads: Apple's push service receives the text of the notification — which quotes a commitment in your own words (Section 3.5) — in order to put it on your screen. Expo lists Apple as its own sub-processor for exactly that. Separately, if you choose Sign in with Apple, Apple authenticates you on your device and returns an identity token — plus the email address you agree to share — which we exchange for a Seven Chairs session. Not a processor — see the note under this table | Per Apple's own policies |
| Google — Google Play, push delivery, and Google Sign-In if you use it | Takes payment for subscriptions bought on Android. Delivers our notifications to Android devices: Google's push service receives the text of the notification — which quotes a commitment in your own words (Section 3.5) — in order to put it on your screen. Expo lists Google as its own sub-processor for exactly that. Separately, if you choose Google Sign-In, Google authenticates you on your device and returns an identity token — with your name, email address and profile picture — which we exchange for a Seven Chairs session. Not a processor — see the note under this table | Per Google's own policies |
| Expo | Relays push notifications: receives your device's push token and the text of the notification, then hands it to Apple or Google for delivery (Section 3.5). Expo's own sub-processor list names both for “Sending push notifications to users” | United States |
| Resend | Delivers one email and no other: the one carrying your sign-in code, relayed as the mail server our authentication provider hands it to. There are no marketing, waitlist or notification emails going through it | United States |
| PostHog (only with your opt-in consent — see Section 9) | Product analytics | European Union |
| Sentry | Crash and error reporting from the mobile app — technical reports only (Section 9). Our backend API is wired for the same reporting but has no Sentry credential configured, so as things stand it sends Sentry nothing | European Union |
Apple and Google are not processors, and we will not pretend they are. Neither company acts on our instructions. Apple's Developer Program License Agreement (Schedule 1) appoints Apple as our agent or commissionaire for App Store sales; Google's Play Developer Distribution Agreement (§9.3) puts us and Google in a controller-to-controller relationship, by having us agree to Google's Controller-Controller Data Protection Terms. Sign in with Apple and Google Sign-In are different products again from those stores, and they run on your device, between you and that company — the app only receives the result. Push delivery is a third relationship again, and it is the one that carries your own sentences. Apple's and Google's push services receive the text of a notification — a commitment quoted back to you (Section 3.5) — because there is no other route to a phone's lock screen. We reach them through Expo, whose published sub-processor list names Apple and Google for “Sending push notifications to users”; that is Expo's arrangement with them, not a promise we are in a position to make. What this means for you: those dealings are governed by Apple's and Google's own privacy policies, we have no say in what they do with the data they collect there, and we cannot make promises on their behalf — including the same-or-equal-protection confirmation described next.
Confirmed 7 September 2026 — the processors in the table above provide the same or equal protection of your data that this policy promises you, and every one of them is bound in writing to do it. Seven of the eight are bound to us directly, each under a data-processing agreement made under Article 28 of the GDPR — Expo's being the European Commission's own standard contractual clauses, written into its Terms rather than kept as a separate document. Article 28(3) is where that standard comes from, rather than from our summary of it: process your data only on our documented instructions, keep it confidential, secure it to the Article 32 standard, impose the same obligations on any sub-processor, help us meet our security and breach-notification duties, assist with your rights requests, and delete or return your data at the end. The eighth, Anthropic, was never ours to bind and is covered a different way, set out below. Each paragraph that follows names the clause behind one of them, because a confirmation you cannot check is only a nicer-sounding way of saying trust us.
What the confirmation does not say. It does not say these companies touch your data only to provide their service to us. The paragraph above the table says the opposite and is still true: six of them reserve the right to use technical, telemetry, aggregated or de-identified data from running their service to operate and improve it, and Vercel's terms reach furthest, letting it use System Data “for any business purposes in its sole discretion”. Confirming the protection standard does not delete those clauses — we accepted them, we did not negotiate them away, and a confirmation written to imply otherwise would be the easiest sentence on this page to catch us on. What these agreements govern is your personal data: your conversations, your memory, your account. Where a processor offered us the wider option we turned it down — Sentry's amendment carries a “use of aggregated identifying data” permission, and ours is switched off.
In force the moment we signed up — five that needed no signature from us. Supabase — Terms §7(b): “The Parties agree to comply with the Data Processing Addendum, which is incorporated into this Agreement.” Vercel — Terms §10.1 says it processes personal information “in accordance with Vercel's Data Processing Addendum … which is incorporated by reference”, and the DPA itself “shall become legally binding upon Customer entering into the Agreement”. Expo — Terms §3.2 incorporates no separate document at all: it makes Expo the processor and writes the European Commission's module-two standard contractual clauses (C/2021/3972) into the Terms themselves, so Expo's version of these obligations is the SCCs rather than a DPA of its own. RevenueCat — Terms §4.2: its DPA “is hereby incorporated by reference and forms an integral part of the parties' agreement with one another.” Resend — its DPA “becomes legally binding upon Customer's acceptance of the Agreement or execution of this DPA”, with the signature blocks marked “for reference purposes only”.
Bound through Vercel rather than by us — one that was never ours to sign. Anthropic — we have no contract with Anthropic and no Anthropic API key; every model call goes through Vercel's AI Gateway on Vercel's own provider agreements. Anthropic is named on Vercel's own published sub-processor list (security.vercel.com) for “Generative AI services”, and Vercel's DPA §7 (“Subprocessing”) commits Vercel to “enter into a written agreement with each Subprocessor, imposing data protection obligations substantially similar to those set out in this Addendum” — so the standard Anthropic owes runs down the chain from the agreement that already binds Vercel to us. It is a real commitment and it is one step removed, which is the honest way to put it: our remedy is against Vercel, not against Anthropic.
Signed and accepted on 7 September 2026 — the two that needed a person. PostHog — the DPA is generated inside the product (app.posthog.com/legal); it was signed on that date by Or Iscovici t/a Seven Chairs and countersigned by PostHog's VP Operations. It carries the obligations listed at the top of this notice as §2.2.4 (no selling or sharing), §3 (confidentiality), §4 (Article 32 security), §7 (breach notice without undue delay), §8 (audit), §9 (deletion or return) and §10.3–§10.4 (Data Privacy Framework participation, and the standard contractual clauses, which signing the DPA is deemed to sign) — and it passes the standard on: §5.2 requires PostHog to “enter into a written contract with any Subprocessor” which “shall impose upon the Subprocessor equivalent obligations as imposed by this Agreement upon the Processor”, and adds that where a sub-processor fails, “Processor shall remain fully liable to the Company”. Sentry — Data Processing Amendment v5.1.0, accepted on the same date through our organisation's Legal & Compliance console.
Who it does not cover — Apple and Google. The Apple and Google rows are not covered by that sentence and will not be, for the reason set out in the paragraph immediately before this notice: those are not processors acting on our instructions but businesses you deal with directly under their own policies — the stores, the sign-in services, and the push services that put a notification on your screen, including the text of a reminder in your own words. We cannot promise anything on their behalf, and we will not write the confirmation loosely enough to seem to include them.
Beyond processors, we disclose personal data only: (a) if required by law, court order, or enforceable governmental request; (b) to protect the rights, safety, or property of our users, the public, or us; or (c) as part of a merger, acquisition, or asset sale — in which case this policy continues to apply to your data and we will notify you of any change of controller.
7. International transfers
We operate from Israel; our main processors are in the United States; you may be anywhere.
- EU/UK → Israel: Israel benefits from an EU adequacy decision (reaffirmed by the European Commission in 2024) and UK adequacy regulations, so your data may be processed in Israel with the same level of protection recognised by EU/UK law.
- Transfers to the US and elsewhere are protected by appropriate safeguards — the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU-U.S. Data Privacy Framework.
- From Israel, transfers abroad are made in accordance with the Israeli Privacy Protection (Transfer of Data Abroad) Regulations.
8. How long we keep data
| Data | Retention |
|---|---|
| Account, memory, metrics, accountability data | While your account exists; deleted within 30 days of account deletion |
| Chat threads | On your device — removed when you sign out, delete the app, or clear them |
| Session summaries | While your account exists; deletable in-app; removed with account deletion |
| Usage and billing records | Up to 7 years where needed for tax, accounting, and billing-dispute obligations |
| Push token and notification preferences | While your account exists; a token the push service reports as dead is deleted on the next run |
| Server logs | Approximately 30 days |
| Backups | Rotated on a schedule; deleted data leaves backups within 90 days |
9. Analytics and consent
Product analytics (PostHog) is opt-in. The app asks you once, plainly, as the last step of setup, before you sign in. Nothing is captured unless you choose to share, and a switch in the app (You → Usage analytics) lets you change your mind at any time; turning it off stops capture immediately. When you do opt in: data is hosted in the EU, there is no session recording and no autocapture, and events carry feature names and counts only — never message text, memory items, metric values, or business names. Because the App uses no cookies and no cross-app tracking, you will not see cookie banners in the App — the in-app consent choices are the equivalent controls: this one, and the AI-processing choice in Section 4.
Crash reporting (Sentry) runs to keep the app working (legitimate interest): if the app crashes or errors, a technical report (stack trace, device model, OS and app version) is sent so we can fix it. It is configured to carry no personal content — no conversations, no memory, no analytics of your behavior — and reports are associated only with an internal account identifier, never your email.
Our marketing website (sevenchairs.ai) is live, and it measures traffic without cookies. It runs Vercel Web Analytics — page views, referrers and countries, no cookies — and PostHog, configured for that site with no cookies and no browser storage, so there is no cross-visit identifier: a visitor is a visitor for one visit. Autocapture is off, session recording is off, and the events are which parts of the page were read and whether someone joined the waitlist. That is why the site carries no cookie banner. If we ever turn on cross-visit tracking or session replay there, a consent notice ships with it.
10. Security
- Every user's data is isolated with row-level security — your account can only ever read its own rows, enforced in the database itself.
- Data is encrypted in transit (TLS) and at rest.
- Secrets and service credentials are never shipped in the app and never logged; privileged server credentials are restricted to server-side use.
- Server logging is deliberately PII-safe by design: conversations and memory are excluded from logs.
- Payment webhooks are authenticated; unauthenticated calls are rejected.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by law (including the 72-hour GDPR standard and Israeli breach-reporting requirements).
11. Your rights and controls
Built into the app (fastest):
- See and edit everything the AI remembers: You → Your memory — view, edit, or delete any item.
- Your metrics and goals are editable in the app.
- Sign out clears device-local settings.
- Delete your account: in the App, You → Account → Delete account. It asks twice, then deletes your account and everything your team remembers. Our account deletion page explains what goes, what the law makes us keep, and the email route if you prefer it.
Under the GDPR / UK GDPR (if you are in the EEA/UK) you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time (for anything based on consent, like optional analytics). You may lodge a complaint with your local supervisory authority.
Under Israel's Protection of Privacy Law, you have the right to inspect information held about you and to request correction or deletion, and you may complain to the Privacy Protection Authority.
Under the CCPA/CPRA (California): you have the rights to know, delete, correct, and to opt out of "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We will never discriminate against you for exercising your rights. (Categories collected, per the CCPA taxonomy: identifiers; commercial information; internet/electronic activity; and the user content described in Section 3.2 — for the purposes in Section 5, from the sources in Section 3, disclosed only to the service providers in Section 6.)
To exercise any right, email support@sevenchairs.ai from the address linked to your account (or include enough information for us to verify you). We respond within 30 days (45 for CCPA, extendable as the law allows). You may use an authorized agent where the law provides for one.
12. Do Not Sell or Share
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is no advertising in Seven Chairs.
13. Children
Seven Chairs is a business tool for adults. It is not directed to anyone under 18, and you may not use it if you are under 18. We do not knowingly collect data from children; if you believe a child has provided us personal data, contact us and we will delete it.
14. Automated decision-making
We do not make automated decisions about you that produce legal or similarly significant effects. The AI generates suggestions and analysis for you to evaluate — you decide. Message allowances and rate limits are applied automatically as part of the service you signed up for, and are not profiling.
15. Changes to this policy
We will post any changes here and update the date above. For material changes, we will tell you in the app or by email before they take effect. Continued use after the effective date means the updated policy applies.
16. Contact
Questions, requests, or complaints: support@sevenchairs.ai. We read everything.
This policy is provided in English. Summaries in other languages, if any, are for convenience — the English version controls.