Sign in ↗

Legal

Privacy Policy

This policy explains what personal data Phases processes, why we process it, who receives it, how long we keep it, and the choices and rights available to you.

Effective
15 September 2026
Last updated
15 September 2026

1. Who controls your personal data

Aerobase Innovations AB, organisation number 559260-9340, is the controller for personal data processed to operate Phases, manage accounts, secure and improve the Service, and provide direct support. Our address is Kompanivägen 35, LGH-1803, 974 44 Luleå, Sweden.

If your employer or another organisation provides Phases under its own agreement and determines why and how your workspace data is used, that organisation may be the controller and Aerobase may act as its processor. Contact your organisation first for requests about that workspace; we will assist it as required by our agreement and law.

2. Personal data we process

Depending on how you use Phases, we process:

  • Account and identity data: name, email address, internal user identifier, authentication status, login provider, and account-security events. Password authentication is handled by our identity provider; Aerobase does not receive your social-login password.
  • Workspace and collaboration data: workspace name, membership, role, invitations, settings, and feature access.
  • User content: prompts, chats, uploaded or authored material data, simulation inputs, model configurations, generated results and artifacts, shared-chat settings, custom simulator definitions, and instructions sent through integrations.
  • Feedback and support data: ratings and the related prompt and response, bug-report descriptions, incident references, and—only when you select the respective options—bounded browser diagnostics (browser identifier, language, timezone, and viewport size) and permission to contact your confirmed account email.
  • Technical and usage data: IP address, approximate location derived from it, request browser identifier, request and event timestamps, session and run identifiers, tool and model usage, token counts, logs, errors, security signals, and service-performance data.
  • Cookie and local-storage data: authentication tokens, interface preferences, and bounded reconnect cursors as described in our Cookie Policy.

We receive most data directly from you, your workspace administrator, your device, or a service you choose to connect. We may also receive identity data from an authentication provider and operational data from providers that host or secure the Service.

3. Why we process data and our legal bases

PurposeTypical dataLegal basis under the GDPR
Provide accounts, workspaces, chat, simulations, storage, and integrationsIdentity, workspace data, user content, technical identifiersPerformance of a contract or steps requested before a contract
Authenticate users, prevent abuse, protect tenants, and investigate incidentsAccount, IP, security events, logs, bounded incident dataLegitimate interests in operating a secure and reliable service; legal obligations where applicable
Maintain, diagnose, and improve product quality and capacityUsage, performance, errors, feedback, and service interactionsLegitimate interests in improving and administering the Service
Respond to support and bug reportsContact and report data, optional diagnosticsPerformance of a contract, legitimate interests, and consent where we explicitly ask for it
Send workspace invitations and essential service messagesName, email, workspace and delivery dataPerformance of a contract and legitimate interests in service administration
Meet tax, accounting, legal, and regulatory requirements; establish or defend claimsRelevant account, transaction, audit, and communication dataLegal obligations and legitimate interests in legal protection

Where we rely on legitimate interests, we assess those interests against your rights and reasonable expectations. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out lawfully.

4. AI models, simulations, and automated processing

To answer a request, Phases may send your prompt, relevant conversation context, tool descriptions, and necessary result context to the AI model provider configured for the Service. Simulation tools separately process the material and process inputs needed to perform the run. Google separately receives up to the first 2,000 characters of the first message in a conversation to propose its title, including when Anthropic or OpenAI handles the chat. When you explicitly use a web-research feature, its query is sent to a Google-grounded search service. Do not submit personal data or confidential information that is not necessary for your engineering task.

Phases uses automated systems to generate text, select tools, and run calculations. Aerobase does not use Phases to make decisions about you that produce legal or similarly significant effects. You remain responsible for qualified review of engineering outputs.

5. When we share data

We disclose personal data only as needed to:

  • service providers acting for us, including Supabase for identity, database, and object storage; Google Cloud for hosting and execution; the configured AI model provider (which may include Google, Anthropic, or OpenAI); Google separately for conversation title generation and optional grounded search; Resend for transactional email; ip-api.com for best-effort approximate location derived from a public IP address; and tightly scoped operational providers used for security or service diagnostics;
  • members and administrators of a workspace according to their role and the product's access controls;
  • people you choose to share content with, including anyone who has an active shared-chat link; shared pages require no login and may be discovered or indexed, so treat an enabled link as public;
  • an external integration when you authorise and use it; or
  • authorities, advisers, a buyer or successor, or another party when required by law or reasonably necessary to protect rights, safety, and the integrity of the Service.

We do not sell personal data and do not use it for third-party behavioural advertising. Manual bug-report descriptions and opted-in diagnostics are restricted to authorised administrator triage and are not automatically copied to GitHub. Sanitised technical incidents may be relayed to a configured GitHub issue tracker without prompts, tool arguments, credentials, or user identity.

6. International transfers

Providers and their support personnel may process data outside Sweden or the European Economic Area. When personal data is transferred to a country without an adequacy decision, we take steps designed to use a lawful transfer mechanism. Depending on the provider and destination, this may include the European Commission's Standard Contractual Clauses and supplementary measures. Contact us for information about the mechanism relevant to your Service configuration.

7. How long we keep data

We retain account, workspace, chat, run, artifact, and material data while needed to provide the Service and until it is deleted through product controls, by an authorised workspace administrator, or in response to a valid request. Active work, shared resources, backups, and deletion queues may require a limited period to complete removal.

Deleting a session removes its content through a guarded cleanup process. A minimal tombstone containing retired identifiers and prior ownership or workspace scope may remain to prevent deleted work from being recreated and to preserve system integrity; it does not retain the deleted conversation or result artifacts.

Security, audit, usage, feedback, support, and transaction records are kept only as long as reasonably necessary for the purpose collected, applicable limitation periods, dispute resolution, and legal or contractual requirements. We may retain irreversibly anonymised or aggregated information because it no longer identifies you. Where we act for your organisation, its retention instructions may apply.

8. Security

We use technical and organisational measures designed to protect personal data, including authenticated access, workspace and owner checks, role-based administration, private artifact storage, encryption for core browser and application traffic, restricted service credentials, and security logging. Some ancillary provider requests, including the current best-effort IP geolocation endpoint, may not offer encrypted transport. No online service can guarantee absolute security. Please use a unique password, protect shared links and credentials, and report suspected misuse promptly.

9. Your privacy rights

Subject to the GDPR and applicable exceptions, you may ask us to:

  • confirm whether we process your data and provide access to it;
  • correct inaccurate or incomplete data;
  • delete data or restrict how it is used;
  • provide data you supplied in a portable format;
  • object to processing based on legitimate interests, including direct marketing; and
  • withdraw consent where consent is the legal basis.

You can delete individual chats and runs using available product controls. For an account-level request, email support@aerobase.se from your account address and describe the request. We may need to verify your identity and authority, and we will explain if an exception applies. If your organisation controls the workspace, we may direct the request to it.

10. Children

Phases is designed for professional and educational engineering use, not for children acting on their own behalf. A person who lacks legal capacity to agree to the Terms must not create an account. Contact us if you believe a child has provided personal data without appropriate authorisation.

11. Changes to this policy

We may update this policy when the Service, our providers, or legal requirements change. We will publish the new version here, update the date above, and provide additional notice where a change materially affects your rights.

12. Contact and complaints

Send privacy questions or requests to support@aerobase.se, or write to Aerobase Innovations AB, Kompanivägen 35, LGH-1803, 974 44 Luleå, Sweden.

You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or the data protection authority where you live or work. You can find IMY at imy.se.