Privacy Policy
Last updated: August 13, 2026
1. Overview
This Privacy Policy explains how El Yazid Tebbaa ("we", "us", or "our"), doing business as qwelto, collects, uses, and protects information when you use our website, AI-assisted brand identity tools, and related services.
2. Information we collect
We may collect account information such as your email address, Google sign-in details, product preferences, project inputs, generated brand assets, saved designs, support messages, and Founder Pass entitlement status. For security and service delivery, hosting providers necessarily process request information such as IP address, browser type, and request time. Qwelto does not place raw IP addresses, full user-agent strings, or full referring URLs in its analytics records.
3. Payment information
Payments are processed by Paddle, our Merchant of Record and payment provider. We do not store full payment card numbers on our own servers. Paddle may collect billing information, tax details, payment method details, and transaction data needed to process orders, issue receipts, handle refunds, prevent fraud, and comply with legal obligations. We store limited payment metadata such as transaction IDs, customer email, product, status, and audit events so we can activate access and provide support.
4. How we use information
We use information to provide and improve qwelto, authenticate users, save projects, generate brand assets, process payments, prevent abuse, analyze performance, respond to support requests, and comply with legal requirements.
Where applicable, our legal bases are performance of the service contract for requested product and payment functions, consent for optional browser analytics and 30-day browser attribution, legitimate interests for identifier-free aggregate campaign measurement, limited same-visit partner credit, and proportionate service security, and legal obligation for tax, accounting, and regulatory records. You may object to legitimate-interest processing by contacting us.
5. AI processing
Your prompts, project choices, and design preferences may be processed by AI systems to generate logos, banners, brand directions, and related outputs. Do not submit confidential, sensitive, or third-party information unless you have the right to use it.
6. Cookies and analytics
Qwelto uses necessary first-party storage for sign-in, session continuity, product state, payment access, security, and remembering your privacy choice. These functions do not depend on optional analytics consent.
Without optional analytics consent, a visit carrying campaign parameters may increment a daily aggregate counter containing only the date, event name, page path, campaign source, medium, campaign label, device category, and total count. It contains no browser or user identifier, IP address, user agent, referrer, email, event ID, or account data. It measures page loads rather than unique people and cannot follow a browser across pages.
A growth-partner link may also be exchanged for a signed proof that contains the selected partner, a random nonce, and a two-hour expiry. Qwelto keeps this proof only in the current qwelto.online page address and same-site links. It does not place it in a cookie or browser storage, does not contain an email, account ID, IP address, or browser identifier, and is not sent to external links. It may remain in your browser history until you remove that entry. If checkout starts before it expires, it allows the resulting purchase, refund, dispute, and commission to be assigned to that partner even when optional analytics is refused. It does not measure unique visits or recognize a later return.
If you choose Allow, Qwelto may store low-cardinality campaign context and once-only product milestones in first-party browser storage. If you arrive through a growth-partner link, Qwelto may also create a pseudonymous 30-day browser identifier and a signed, HttpOnly attribution cookie. The backend stores only a keyed hash of that identifier, limited campaign fields, page paths, referring domains, and automated abuse-risk results. Raw IP addresses and full user-agent strings may be processed transiently to create rotating one-way security fingerprints, but are not stored in referral records. This allows Qwelto to measure qualified visits, purchases, refunds, disputes, and partner commissions. Partners receive only aggregate traffic and non-identifying conversion references.
You can refuse optional analytics without losing core functionality, or withdraw consent at any time below or in Studio Settings. Withdrawal deletes optional analytics and persistent referral identifiers from your browser and expires the attribution cookie. It does not remove a short-lived same-visit proof already visible in the current page address; you can remove the qj parameter or close the page, and it expires automatically. Historical aggregate counters and lawfully retained commission or fraud-audit records are not rewritten.
Optional analytics
No persistent analytics profile. Partner links can still credit a purchase made during the current visit.
7. Sharing information
We may share information with service providers that help us operate qwelto, including Google for sign-in, Paddle for payments and tax handling, Vercel for website hosting, Hugging Face for backend hosting, and infrastructure providers used for AI-assisted generation and system operations. Qwelto does not send analytics to a third-party analytics provider. We may also disclose information if required by law, to protect users, to enforce our terms, or to prevent fraud and abuse.
8. Data retention
We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and enforce agreements. Optional browser attribution expires after 30 days; your analytics choice may be remembered for up to one year. Aggregate analytics counters are retained as non-identifying business statistics. Temporary generation sessions may be cleaned up after about 30 days. Saved designs and taste preferences are kept until you delete them or delete your account. Payment and audit records may be retained for longer when needed for tax, accounting, refund, fraud-prevention, chargeback, and legal reasons. When account deletion is requested, we delete user-owned project data and redact retained payment events where possible.
9. Security
We use reasonable technical and organizational measures to protect information. However, no internet service can guarantee absolute security.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. To make a request, contact us using the email below from the email address connected to your Qwelto or Paddle account. We may need to verify your identity before acting on a request.
11. Children
qwelto is not intended for children under 13. We do not knowingly collect personal information from children under 13.
12. Changes to this policy
We may update this Privacy Policy as qwelto evolves. The updated version will be posted on this page with a new “Last updated” date.
13. Contact
Privacy questions or requests can be sent to: support@qwelto.online.