AI4AV
DevicesArticlesNewsContributeSponsors
Sign in

Last updated 2026-05-20

Privacy Policy

This page explains what AI4AV processes, why it is processed, who helps process it, and how to contact the controller.

Draft pending legal review

This policy is an engineering draft for GDPR transparency. It must be reviewed by a qualified privacy professional before AI4AV claims GDPR compliance publicly.

Controller

AI4AV is operated by Vesa Laasanen as an individual controller. Contact: email ai4avofficial, followed by @gmail.com. See also the Legal page.

Data AI4AV processes

  • Account data through Clerk: email, name, OAuth profile, sessions, and sign-in metadata.
  • API key data: token prefix, token hash, scopes, owner identifier, and timestamps. Raw API keys are never stored.
  • Security and rate-limit data: pseudonymous salted IP buckets in Convex. Raw IP is not stored in Convex rate-limit rows.
  • Error telemetry through Sentry: errors, stack traces, runtime metadata, URL paths, and incidental diagnostic data.
  • Analytics: Google Analytics 4 with first-party analytics cookies. Pseudonymous usage measurement only — no advertising features, no Google Signals, no cross-site identity. Consent Mode v2 keeps all ad-related storage and signals denied.
  • Newsletter data: email address, consent text/version, confirmation and unsubscribe timestamps, and delivery metadata.
  • Public contributions: GitHub issues and pull requests are public on GitHub.

Purposes and legal bases

  • Account and API-key features: contract or steps requested by the user.
  • Security, rate limiting, abuse prevention, logs, and error monitoring: legitimate interests.
  • Pseudonymous usage analytics (first-party cookies, no advertising features): legitimate interests in understanding which pages are read and which devices/browsers reach the site.
  • Newsletter: consent. Consent can be withdrawn at any time through unsubscribe.

Processors and recipients

AI4AV uses Clerk, Convex, Vercel, Sentry, Google Analytics, Resend, and, when enabled, Cloudflare Turnstile. GitHub is an independent public platform for repository contributions. The working processor inventory is maintained in the Sprint 47 processor register.

International transfers

Convex production data is hosted in the EU. Several processors are US or global services. Resend's EU sending region affects dispatch location only; Resend account data, email metadata, logs, and API records remain US-stored. Transfer mechanisms and DPAs are tracked in the processor register and must be confirmed before legal review.

Retention

  • Account data is kept until account deletion, subject to provider audit/security retention.
  • API token hashes are kept until revoked, expired, or the account is deleted.
  • Rate-limit records expire through the 24-hour cleanup path.
  • Sentry, Vercel, Google, Clerk, Resend, and Cloudflare retention settings must match the processor register before launch.
  • Newsletter subscriptions remain active until unsubscribe. Unsubscribe keeps a minimal suppression and consent-withdrawal record unless erasure is requested and legally approved.

Cookies and tracking

Clerk session cookies are necessary for signed-in account features. Google Analytics 4 sets first-party analytics cookies (_ga, _ga_*) used to count page views, distinguish browsers, and group activity into sessions. Consent Mode v2 keeps ad_storage, ad_user_data, and ad_personalization denied — no advertising cookies are set and no data is shared with Google Ads or Google Signals. PostHog is inactive when its public key is missing or set to the placeholder value. Sentry is used for error telemetry, not session replay.

Your rights

You can request access, rectification, erasure, restriction, portability, objection, or withdrawal of consent by emailing ai4avofficial, followed by @gmail.com. AI4AV aims to respond within one month. Identity verification may be required before account data is exported or deleted. You may also complain to your local supervisory authority.

Children and changes

AI4AV is not directed at children under 16. Material policy changes will update this page and, for newsletter subscribers, may be sent by email where appropriate.

AI4AV© 2026
AboutDevicesArticlesContributeSponsorsNewsletterPrivacyLegal