MODLANE PRIVACY POLICY
Closed Beta
Version 1.0 | Effective 23 July 2026
At a glance
MODLANE processes account data, user requests and files to provide an AI workspace. Chat history is currently stored locally in the user’s browser. Optional PostHog analytics is off unless the user consents. MODLANE does not sell personal data or use it for targeted advertising.
Controller: Aleksandr Boiko, current operator of MODLANE in Ireland
Contact: office@modlane.app
Website: modlane.app
1. Scope and controller
This Privacy Policy applies when an invited user visits modlane.app, creates or uses a MODLANE account, submits text, documents or images, receives AI-generated output, changes privacy settings or communicates with MODLANE.
MODLANE is currently an early-stage, non-commercial project and is not yet operated through a registered company or other separate legal entity. Aleksandr Boiko is the current operator and data controller for the processing described in this Policy.
- Controller: Aleksandr Boiko, current operator of MODLANE in Ireland.
- Privacy contact: office@modlane.app.
- Website: modlane.app.
This Policy should be read with the MODLANE Cookie Policy, Beta Terms of Service and Privacy & Data Controls page. Third-party providers also publish their own privacy information for processing they perform under their own responsibilities.
2. Eligibility and age
MODLANE is intended only for users aged 18 or over and is not directed to children. MODLANE may suspend access and delete an account if it reasonably determines that the user is under 18, subject to legal, security and provider-retention requirements.
3. Personal data processed
- Account and authentication data: full name, email address, internal Supabase user ID, email-verification status, account creation and update timestamps, last sign-in time, cryptographic password hash and authentication or recovery records.
- User content: prompts, instructions, necessary conversation context, AI responses, chat titles, feedback and other text submitted to or generated through the Service.
- Documents and images: files and images submitted for a task, temporary conversion data and text extracted or recognised from them.
- Local browser data: chat history, AI responses, chat titles, converted document text, authentication state, cookie preferences and optional analytics identifiers stored in the current browser.
- Optional analytics data: page views, page exits, URLs and screen paths within MODLANE, timestamps, browser and device characteristics, web-performance information, permitted clicks and feature interactions, and an account identifier or email where used to identify a PostHog person profile.
- Infrastructure and security data: request path, timestamp, status, size, duration, error information, user agent, IP address where transiently or operationally processed by a provider, and related technical or security metadata.
- Email and support data: sender and recipient addresses, subject, message content, attachments, timestamps, message ID, delivery status and the history of the support, privacy or security matter.
MODLANE does not currently request a telephone number during registration and does not sell personal data or use it for targeted advertising.
4. Sources of data
- Directly from the user, including registration details, prompts, files, feedback and support messages.
- From the user’s browser or device when the website, authentication, local history or optional analytics features are used.
- From MODLANE service providers through authentication, delivery, security, analytics, API and infrastructure records.
- From authorised MODLANE administrators when they record an access decision, support action, privacy request or security investigation.
5. Data you must and may provide
- An email address, password and name are required to create and secure an account. Without them, MODLANE cannot provide registered access.
- A text request is required for MODLANE to perform the requested AI task. The request should contain only information reasonably necessary for that task.
- Uploading a document or image is optional. Without the file, MODLANE cannot perform a task that depends on its contents.
- Optional PostHog analytics is not required. Rejecting analytics does not prevent access to the core Service.
- Feedback and support communications are voluntary, although additional information may be necessary to investigate a specific problem or exercise a legal right.
6. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage an account | Name, email, authentication and account records | Performance of a contract or steps requested before entering a contract — Article 6(1)(b) GDPR. |
| Provide AI responses, routing and file processing | Prompts, necessary context, files, images, extracted text and AI output | Performance of the Beta Terms — Article 6(1)(b). |
| Maintain security, prevent abuse and operate infrastructure | Account, request, device, log, error and security data | Legitimate interests in protecting MODLANE, users and providers — Article 6(1)(f). |
| Provide support and manage access | Account details, correspondence and support history | Contract — Article 6(1)(b), and legitimate interests in support and beta administration — Article 6(1)(f). |
| Send transactional and service email | Email address, account and delivery data | Contract — Article 6(1)(b), and legitimate interests in secure service communication — Article 6(1)(f). |
| Operate optional product analytics | PostHog identifiers and permitted usage events | Consent — Article 6(1)(a). |
| Handle rights requests, complaints and legal duties | Identity, account, correspondence and request records | Legal obligation — Article 6(1)(c), and legitimate interests in legal claims and accountability — Article 6(1)(f). |
7. AI routing and file processing
MODLANE analyses a request and automatically selects one or more third-party AI providers. Users do not manually select the provider, and the provider used for a request may not be displayed.
- DeepSeek may receive the MODLANE system instruction, an ordinary text request and the necessary portion of prior conversation context for classification or a simple response.
- OpenAI or Anthropic may receive a request, necessary conversation context and any document or image content required for a more complex task.
- Uploaded files and images are not intentionally sent to DeepSeek under the current configuration.
- Files are received in Vercel serverless memory and may be temporarily converted into text by MarkItDown on Railway. The temporary Railway file is deleted at the end of the same HTTP request. MODLANE does not intentionally save the original binary file in a chat database, Vercel Blob, persistent Vercel disk or Railway volume.
- Converted text may remain in localStorage as part of the user’s local chat history.
MODLANE does not currently train its own AI model on user prompts or responses. Third-party AI providers process data under their own business/API terms and retention controls.
8. Cookies, local storage and analytics
MODLANE uses strictly necessary browser storage for authentication, cookie preferences and user-requested local chat functionality. Optional PostHog analytics is disabled unless the user gives a separate affirmative consent.
- Rejecting analytics keeps optional PostHog capture and browser persistence disabled and does not restrict the core Service.
- Users can change the choice through Cookie Settings and Settings > Privacy & Data.
- Session Replay and advertising cookies are not used.
- MODLANE does not use cookieless PostHog tracking after rejection.
Chat history is currently stored in localStorage on the user’s browser rather than in a MODLANE server-side chat database. Clearing history or deleting an account on one device does not remotely clear another browser or device.
Further details, including observable cookie-name patterns and retention periods, appear in the Cookie Policy.
9. Service providers and recipients
| Provider | Role |
|---|---|
| Supabase | Account authentication, session management and standard Auth records. MODLANE does not currently store chats, prompts or files in public application tables. |
| Vercel | Website hosting, Next.js API routes and serverless processing. Uploaded files are handled in memory and are not intentionally written to persistent Vercel storage. |
| Railway / MarkItDown | Temporary document conversion. A temporary file is deleted at the end of the same request. |
| OpenAI | Complex text processing, vision and related AI tasks. |
| Anthropic | Complex text processing, image analysis and fallback AI tasks. |
| DeepSeek | Ordinary text classification and simple answers. Files and images are not intentionally sent. |
| PostHog EU Cloud | Optional product analytics after consent. Session Replay is disabled and client IP data is configured to be discarded from stored events. |
| Resend | Account-confirmation and other transactional email delivery. |
| Zoho Mail EU | Support, privacy requests, security reports and general communications through office@modlane.app. |
10. International transfers
Some providers may process personal data outside the European Economic Area, including in the United States and China. The location may depend on the service, endpoint, routing decision and provider infrastructure.
Where required and available, MODLANE uses provider data-processing terms, Standard Contractual Clauses, adequacy decisions or other lawful safeguards. Users may contact office@modlane.app for information about the safeguards relevant to their data.
DeepSeek may process ordinary text in China. MODLANE limits its use to ordinary text classification and simple responses and does not intentionally send it files or images. Do not submit secrets, credentials, payment data, trade secrets or other highly confidential content in ordinary text prompts.
11. Retention
| Category | Retention |
|---|---|
| Supabase account data | For the life of the account, then active deletion. MODLANE does not have access to scheduled restorable project backups on its current Free Plan; provider security or internal records may follow separate lifecycles. |
| Local chat history | Until deleted by the user, cleared by the browser or removed by account deletion on that device. |
| Original uploaded files | Processed for the request and not intentionally stored in a MODLANE server-side file store. Temporary Railway files are deleted at the end of the request. |
| Vercel and Railway technical records | For the period made available or retained by the provider under the current plan and security requirements. |
| OpenAI API data | Generally up to 30 days for abuse and safety monitoring under standard API controls, subject to endpoint and account configuration. |
| Anthropic API inputs and outputs | Generally deleted within 30 days under standard commercial API retention, subject to safety, legal and policy-enforcement exceptions. |
| DeepSeek API data | A fixed general API retention period has not been confirmed in the information available to MODLANE. Context caching may persist for hours or days. |
| PostHog analytics | Up to 12 months where analytics consent was given, unless deleted earlier where available. |
| Resend transactional email records | Generally up to 30 days under the current service configuration, subject to provider security or legal retention. |
| Ordinary support and feedback email | 12 months after the matter is closed. |
| Privacy and GDPR request records | 3 years after the final response. |
| Security incidents and legal disputes | Until the matter is resolved and any relevant claims or limitation period has expired. |
| Spam, test and irrelevant email | Deleted immediately or within 30 days. |
12. Account deletion and full erasure
Delete Account and a full GDPR erasure request are different processes.
- Delete Account removes the active Supabase Auth account, signs the user out and clears MODLANE localStorage on the current browser and device.
- It does not remotely clear localStorage on another browser or device and does not automatically erase historical records held in PostHog, Zoho Mail, Resend, infrastructure logs or AI-provider systems.
- A Full Erasure Request asks MODLANE to search relevant systems and delete or de-identify identifiable personal data where the GDPR right to erasure applies and deletion is technically and legally available.
Requests can be submitted through Settings > Privacy & Data or by emailing office@modlane.app. Some information may be retained for legal obligations, security, fraud prevention, legal claims or the rights of another person.
13. Privacy rights
Subject to the conditions and exceptions in applicable law, users may request access, correction, erasure, restriction, portability, objection and information about international-transfer safeguards. Consent may be withdrawn at any time without affecting processing carried out before withdrawal.
MODLANE normally responds without undue delay and within one month. The period may be extended by up to two additional months where permitted because of complexity or the number of requests. Requests are normally free, although a reasonable fee may be charged or action refused where a request is manifestly unfounded or excessive and the law permits it.
MODLANE uses the least intrusive reasonable identity verification. A signed-in request or confirmation through the registered email address will normally be sufficient.
Detailed controls and instructions appear on the Privacy & Data Controls page.
14. Sensitive data and information about others
MODLANE does not require and is not designed for passwords, API keys, authentication tokens, payment-card details, private keys, trade secrets, special-category personal data, criminal-conviction data or information that the user is not authorised to disclose.
The Beta Terms prohibit submitting security credentials and unlawfully obtained or unauthorised personal data. MODLANE may block, restrict or delete content where necessary to protect users, providers or systems or to comply with law.
A user who submits information about another person is responsible for having a lawful basis and any permissions needed to disclose it for processing through MODLANE and its providers.
15. Security and authorised access
MODLANE uses measures appropriate to the current closed beta, including restricted administrator access, environment-variable storage for API credentials, established cloud providers, temporary-file deletion, limited provider routing and avoidance of intentional prompt or file-body logging in MODLANE application code.
Aleksandr Boiko and Vladimir Boiko may access account, analytics, infrastructure, email or support information where reasonably necessary to operate, secure and support MODLANE. Local-only chat history is not ordinarily available to them.
No internet service can guarantee absolute security. Users should use a unique password, protect access to their email account and report suspected compromise to office@modlane.app.
16. Automated processing
MODLANE uses automated processing to classify requests and select an AI provider. This routing is used to provide the Service and is not intended to make a decision about a user that produces legal or similarly significant effects.
MODLANE does not use personal data for advertising profiling or fully automated high-impact decisions about users.
17. Email communications
MODLANE sends account-confirmation, security, access-status, service and support messages. These communications are necessary to operate the account or respond to the user.
MODLANE does not currently send marketing newsletters. If marketing is introduced, MODLANE will provide the required notice, lawful basis and unsubscribe method.
18. Changes, contact and complaints
MODLANE may update this Policy when the Service, providers, settings, legal requirements or data flows change. The published version will show the current effective date, and material changes will be highlighted where appropriate.
- Controller: Aleksandr Boiko, current operator of MODLANE in Ireland.
- Privacy email: office@modlane.app.
- Website: modlane.app.
Users may complain to the Irish Data Protection Commission at dataprotection.ie or to another competent EEA supervisory authority, including the authority in the country of habitual residence, place of work or place of the alleged infringement.