Privacy policy

Version 1.2Effective 22 September 2026

This Privacy Policy explains how CobaltAI OÜ (registry code 17561613, Männimäe/1, Pudisoo küla, Kuusalu vald, Harju maakond 74626, Estonia) — operating the cobalt12 service at cobalt12.com and app.cobalt12.com — collects, uses, discloses, and protects personal data.

We are the data controller for personal data described in this Policy, except where we act as a processor on your behalf (see Section 9).

Privacy contact: [email protected]


1. Personal Data We Collect

1.1 Data you provide

CategoryExamplesWhy
Account dataname, email address, password hash, company name, countryto create and secure your account
Download delivery emailemail address you provide to receive a download link for files generated without an accountto deliver the files you requested
Billing databilling name, address, VAT/tax ID, last four digits and card brand, invoicesto charge for the Service and meet accounting obligations
Content dataproduct photographs, product descriptions, brand details, specifications, files you uploadto generate Output
Communicationssupport tickets, emails, chat messages, feedbackto respond to you and improve the Service

We do not collect full payment card numbers. Card data is collected and processed directly by our payment processor.

1.2 Data from your connected marketplace account

If you connect a marketplace account (for example, Amazon Seller Central via the Selling Partner API), we access data through that connection strictly as needed to provide the Service. This may include seller and business identifiers, catalogue and listing data, product attributes, images, and related metadata.

We access marketplace data only with your authorisation, only for the purposes you request, and only for the scopes you approve. We do not request or process customer personally identifiable information (such as buyer names, shipping addresses, or order-level PII) unless a feature you explicitly enable requires it, in which case we will notify you and handle it under the applicable marketplace data protection requirements.

You may revoke this authorisation at any time in your marketplace account settings or by disconnecting the integration in the Service.

1.3 Data collected automatically

Technical and usage data: IP address, browser and device type, operating system, language, referring URLs, pages viewed, features used, timestamps, generation and error logs, and cookie identifiers. See our Cookie Policy.

Product analytics (which pages are viewed, which buttons are pressed, which steps of a flow are completed) is measured with PostHog, which processes the data on our behalf. The analytics profile is pseudonymous: for signed-in accounts it carries the account identifier but not your name or email address. Screens and sessions are not recorded. Where the law requires consent, analytics runs only after you give it in the cookie banner; elsewhere you can switch it off at any time. See our Cookie Policy and Sub-processors.

1.4 Data from third parties

Limited data from authentication providers (if you sign in with a third-party identity provider), our payment processor (transaction status), and publicly available marketplace listing data used for competitive analysis features.


2. How and Why We Use Personal Data

PurposeLegal basis (GDPR Art. 6)
Provide the Service, generate Output, operate integrationsperformance of a contract (Art. 6(1)(b))
Deliver download links for files you generate without an accountperformance of a contract / steps taken at your request (Art. 6(1)(b))
Create, authenticate, and manage your accountperformance of a contract
Process payments, issue invoices, keep accounting recordscontract; legal obligation (Art. 6(1)(c))
Provide support and respond to enquiriescontract; legitimate interests (Art. 6(1)(f))
Secure the Service, prevent fraud and abuse, enforce our termslegitimate interests
Monitor performance, debug, and improve the Servicelegitimate interests
Analytics and product measurement (PostHog, see Section 1.3)consent where required, otherwise legitimate interests
Measuring and delivering our own advertising (Meta, Google)consent (Art. 6(1)(a)), in every country
Marketing emails about our own similar serviceslegitimate interests, subject to opt-out; consent where required
Comply with law and respond to lawful requestslegal obligation
Establish, exercise, or defend legal claimslegitimate interests

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights. You may object at any time (Section 7).

We do not sell personal data. We share data for advertising in one case only: if you explicitly accept marketing in the cookie banner, the Meta Pixel and the Google Ads tag receive a browser identifier, the pages you view and three events (demo started, account created, purchase), so that we can measure our own ads and show them to people who visited the site. This never includes your name, email address, account identifier or anything you upload. You can withdraw at any time in "Cookie settings"; a Global Privacy Control signal is treated as a refusal. See the Cookie Policy.


3. Artificial Intelligence Processing

3.1 To generate Output, your Input is transmitted to and processed by third-party AI model providers acting as our sub-processors under contractual terms that restrict their use of the data.

3.2 We do not use your Input or Output to train generative models, and our AI sub-processors are contractually engaged on terms that do not permit use of your content for training their general-purpose models.

3.3 Do not upload personal data that is not necessary for generating listing content. In particular, do not upload photographs of identifiable individuals unless you have a lawful basis and the necessary consents or releases to do so, and do not upload special category data (Art. 9 GDPR).

3.4 We use automated processing to generate content. This does not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR, and no decisions about you are made solely by automated means.


4. Disclosure of Personal Data

We disclose personal data only to:

  • Service providers (sub-processors) — cloud hosting, storage and databases, AI model providers, payment processing, transactional email delivery, product analytics, and mailbox hosting for support correspondence. Each is bound by a written contract and may process data only on our instructions. A current list is available at cobalt12.com/subprocessors or on request to [email protected].
  • Marketplaces — where you instruct us to publish content, we transmit that content to the marketplace you selected.
  • Professional advisers — lawyers, accountants, auditors, and insurers, under confidentiality obligations.
  • Authorities — where required by law, court order, or a valid legal request, or to establish, exercise, or defend legal claims.
  • Corporate transactions — an acquirer or successor in a merger, acquisition, or sale of assets, subject to this Policy.

5. International Transfers

We are established in Estonia (EU). Some sub-processors are located outside the European Economic Area, including in the United States and other third countries.

Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one applies, or on the European Commission's Standard Contractual Clauses together with a transfer risk assessment and supplementary technical measures (including encryption in transit and at rest). A copy of the relevant safeguards is available on request to [email protected].


6. Retention

DataRetention period
Account datafor the life of the account, then up to 90 days after closure
Download delivery email (no account created)up to 12 months from collection, unless you create an account or request earlier deletion
Content data (Input and Output)for the life of the account; deletable by you at any time; removed from active systems within 30 days of deletion
Marketplace connection data and tokensuntil you disconnect or close the account, then deleted promptly
Billing and accounting records7 years (Estonian Accounting Act)
Support communications3 years from last contact
Security and access logsup to 12 months
Backupsencrypted, rotating, deleted within 90 days

We retain data longer only where required by law or where necessary to establish, exercise, or defend legal claims.


7. Your Rights

Under the GDPR you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests, including profiling; withdraw consent at any time without affecting prior lawful processing; and lodge a complaint with a supervisory authority.

To exercise these rights, contact [email protected]. We will respond within one month, extendable by two further months for complex requests. We may need to verify your identity. These rights are free of charge unless a request is manifestly unfounded or excessive.

Supervisory authority (Estonia): Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, 10134 Tallinn, [email protected], www.aki.ee. You may also complain to the authority in your country of residence.

7.1 Residents of California and other US states

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with comprehensive privacy legislation, you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, to opt out of sale or sharing and of targeted advertising, and not to be discriminated against for exercising these rights.

We do not sell or share personal information for cross-context behavioural advertising and we do not use it for targeted advertising. To exercise your rights, contact [email protected]. You may use an authorised agent. If we deny a request you may appeal by replying to our decision.


8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, access controls and least-privilege permissions, secure credential and token storage, logging and monitoring, regular dependency updates, and vendor due diligence.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and notify affected users without undue delay where the risk is high.

Report a suspected vulnerability or incident to [email protected].


9. When We Act as a Processor

Where your Input or your marketplace data contains personal data for which you determine the purposes and means (for example, data relating to your own customers, staff, or suppliers), you act as controller and we act as processor on your behalf. In that case our Data Processing Addendum applies and governs that processing. To request a signed copy, contact [email protected].


10. Children

The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.


11. Changes

We may update this Policy. The "Last updated" date will change, and for material changes we will notify you by email or in-product notice at least 30 days before they take effect.


12. Contact

CobaltAI OÜ · Registry code 17561613 Männimäe/1, Pudisoo küla, Kuusalu vald, Harju maakond 74626, Estonia [email protected] (legal and privacy) · [email protected] (general support)

We have not appointed a Data Protection Officer as we are not required to do so; privacy enquiries are handled at the address above. Privacy requests should include "PRIVACY REQUEST" in the subject line so that they are routed and answered within the statutory deadline.