OnlyCEO Privacy Policy

    Last updated: 4 August 2026

    Atlas Lejon AB, org. nr 559446-0015, Drottninggatan 15, 702 10 Örebro, Sweden ("OnlyCEO", "we") is the data controller for personal data processed on the OnlyCEO platform. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR).

    Discretion is the foundation of this house. This policy is written to be read, not skimmed.


    1. What we collect

    Account and application data. Name, email, phone number, company, title, photograph, and the information you provide when applying for membership.

    Identity verification data. Verification is performed through Stripe Identity, which processes your identity document and a selfie (including biometric comparison) to confirm you are who you say you are. Stripe acts as our processor for this; we receive the verification *outcome* and limited document metadata, we do not store copies of your identity documents on our own systems. Stripe's processing is further described in Stripe's privacy documentation. We may additionally check your role against public sources and corporate registries.

    Content you create. Signals, Threads, Ideas and Questions, comments, event participation, saved items, and your profile.

    Messages, end to end encrypted. Your Messages are end-to-end encrypted. They are sealed on your own device before they leave it and can be opened only on devices you have approved. What our servers hold is ciphertext and no key. This is not a promise that we choose not to look: we have built the service so that we cannot read your Messages, and neither can our hosting provider, anyone who compels us, or anyone who steals a copy of our database.

    We do store, and can see, the fact that a conversation exists: who is talking to whom, and when. We cannot see what is said.

    Discussions in Rooms and other private spaces. Threads and discussions in Chambers, Rooms, Events and VIP Events are transmitted encrypted and stored encrypted at rest, but they are not yet end-to-end encrypted: technically we hold the keys. No one at OnlyCEO reads them. They are accessed by a human only if a participant reports a specific item, and then only the reported item, never the surrounding conversation. Every such access is logged. We are extending end-to-end encryption to these spaces and will say so here when it is done, rather than describing it before it is true.

    Encryption keys and recovery. To make the above work we store: the public key of each device you approve (a public key can seal a message to you, it cannot open one), a record of each device (an identifier, platform and last-used time) so you can see and revoke them, per-message sealed key blobs addressed to each participant, and, if you create one, an encrypted backup of your key protected by your recovery phrase. Your recovery phrase is generated on your device and shown to you once. We never receive it and we do not store it. The backup we hold is opaque to us: without your phrase it is unreadable, including by us.

    Butler and Privileges data. Requests you make to the Butler, and the details needed to fulfil them (for example travel dates or booking preferences), which are shared with the relevant Partner only when you confirm a request.

    Technical data. Log data, device and browser information, IP address, and security events, the minimum needed to run and protect the service. We do not use advertising trackers.

    2. Why we process it (purposes and legal bases)

    PurposeLegal basis
    Assessing your application and verifying identity and roleContract (Art. 6.1.b); legitimate interest in a verified community (Art. 6.1.f); consent for biometric verification where required (Art. 9.2.a)
    Operating the Platform, showing your content to the audiences you choose, delivering messages, running Chambers and EventsContract (Art. 6.1.b)
    Fulfilling Butler requests and Privileges via Partners, at your requestContract (Art. 6.1.b)
    Billing and invoicingContract (Art. 6.1.b); legal obligation (Art. 6.1.c, bookkeeping)
    Safety: handling reports, enforcing the Code of Conduct, preventing abuseLegitimate interest (Art. 6.1.f); legal obligation where reporting is mandated (Art. 6.1.c)
    Security, logging, fraud preventionLegitimate interest (Art. 6.1.f)
    Service communications (approval, receipts, changes to terms)Contract (Art. 6.1.b)

    We do not sell personal data, we do not use your data for third-party advertising, and we do not build advertising profiles. Members are never the product.

    3. Anonymity on the Platform

    Signals may be published anonymously. Anonymity applies toward other members, the connection between an anonymous Signal and its author exists in our systems, is access-restricted, and is used only for safety enforcement and legal obligations. We never reveal an anonymous author to other members.

    4. How a report reaches us

    Because we cannot read your Messages, a report about one cannot work by us going to look. When you report a message or a conversation, your device unlocks the last five messages of that conversation and sends them to us with the report, and the app tells you so before you confirm. That copy is preserved as evidence for the review and is retained as described in Section 7.

    Two consequences follow, and we would rather state them than let you discover them:

    • The only person who can hand us the contents of an encrypted conversation is a participant in it. If you are being mistreated in Messages, reporting is what lets us act.
    • Because the text comes from the reporter's device rather than from our own records, our moderators see it labelled as such, and weigh it accordingly.

    For content outside Messages (Signals, Threads, comments, Rooms), we take the snapshot ourselves at the moment of the report, so that later deletion cannot erase the case.

    5. Who we share data with

    Processors who run the service under contract with us: hosting and infrastructure providers, Stripe (identity verification and payments), email delivery, and error monitoring. Processors act only on our instructions.

    Partners, only when you ask the Butler to arrange something or claim a Privilege, and only the details needed to fulfil that specific request. Partners act as independent controllers for their own service.

    Authorities, where the law requires it (for example, content involving minors, or a valid order from police or courts). We disclose the minimum required and, where legally permitted, inform you.

    No one else. We do not share member lists, and we never confirm or deny anyone's membership publicly.

    6. International transfers

    We keep data in the EU/EEA where feasible. Where a processor transfers data outside the EEA (for example Stripe, to the United States), the transfer is protected by the European Commission's adequacy decisions or Standard Contractual Clauses.

    7. How long we keep data

    DataRetention
    Account and profileFor the life of your membership + 12 months
    Verification outcomeLife of membership; verification session data held by Stripe per its retention terms
    Content in shared spacesWhile published; deleted content is removed from view immediately and from backups on backup rotation
    Messages and RoomsUntil you delete them or your account is deleted
    Device records and public keysUntil you revoke the device or delete your account
    Encrypted key backupUntil you replace it or delete your account (unreadable to us throughout)
    Report and enforcement recordsDuration of the case + 90 days, then purged (longer only if law requires)
    Invoices and bookkeeping records7 years (Swedish Bookkeeping Act)
    Security logs12 months

    8. Your rights

    Under the GDPR you may: access your data; correct it; delete it; restrict or object to processing based on legitimate interest; receive a portable copy; and withdraw consent at any time where processing is based on consent. Write to privacy@onlyceo.app, we respond within 30 days.

    You may also complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se, or to your local authority if you are elsewhere in the EU.

    Note: deleting your account deletes your profile and private communications, and anonymizes or removes your contributions in shared spaces, except where we must retain records by law (Section 7).

    One limit is worth naming plainly. Your right of access and your right to a portable copy reach the data we hold. For Messages, what we hold is ciphertext, so the copy we can produce is the ciphertext and the conversation metadata, not the words. The readable copy of your Messages exists on your devices, where you can read and export it. We are not withholding it; we do not have it.

    9. Security

    All data is encrypted in transit (TLS) and at rest. Internal access follows least-privilege: private communications are inaccessible to staff except through the report-review process described above, and all such access is logged and auditable. We review access rights regularly and will notify you and IMY of any personal-data breach as the GDPR requires.

    Messages are protected by construction, not only by policy. They are sealed with modern public-key cryptography (X25519 key agreement with XSalsa20-Poly1305 authenticated encryption) on your device, addressed to each participant separately. A breach of our servers would expose ciphertext, and ciphertext without a key is not a disclosure of your words.

    Files and photographs you attach are stored in private storage and served only through short-lived signed links to members entitled to see them. They are not yet sealed end to end; we hold the keys to them. We will say so here when that changes.

    Your devices. Files, photographs, and every message you have read live in readable form on the devices you have approved. That is the necessary consequence of a design in which only your devices hold the keys, and it means your devices are the place where your correspondence can actually be compromised. Lock them, and remove any device you no longer control from Settings.

    10. Cookies

    The Platform uses only strictly necessary cookies (session, security). No advertising or third-party tracking cookies. If this changes, we will ask for consent first.

    11. Changes

    We will notify you of material changes to this policy before they take effect. The current version always lives at onlyceo.app/legal.

    12. Contact

    Atlas Lejon AB · Drottninggatan 15, 702 10 Örebro · Sweden · privacy@onlyceo.app


    AboutCode of ConductTerms of Use