Privacy Policy
Last updated: 4 August 2026
Atlas Lejon AB, org. nr 559446-0015, Drottninggatan 15, 702 10 Örebro, Sweden (OnlyCEO, we) is the data controller for personal data processed on the OnlyCEO platform. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR). Discretion is the foundation of this house. This policy is written to be read, not skimmed.
1. What we collect
Account and application data
Name, email, phone number, company, title, photograph, and the information you provide when applying for membership.
Public website, Enter the House form
When you write to us via the application form on onlyceo.app, we collect your name, company, title, corporate email, a one-line statement of interest, and limited technical data (hashed IP address and user agent) solely to review that application and prevent abuse. This is not marketing data. Declined applications are deleted after twelve months. Notices go to our desk at hello@onlyceo.app; we do not auto-reply to the address you submit.
Identity verification data
Verification is performed through Stripe Identity, which processes your identity document and a selfie (including biometric comparison) to confirm you are who you say you are. Stripe acts as our processor for this; we receive the verification outcome and limited document metadata, we do not store copies of your identity documents on our own systems. Stripe's processing is further described in Stripe's privacy documentation. We may additionally check your role against public sources and corporate registries.
Content you create
Signals, Threads, Ideas and Questions, comments, event participation, saved items, and your profile.
Messages, end to end encrypted
Your Messages are end-to-end encrypted. They are sealed on your own device before they leave it and can be opened only on devices you have approved. What our servers hold is ciphertext and no key. This is not a promise that we choose not to look: we have built the service so that we cannot read your Messages, and neither can our hosting provider, anyone who compels us, or anyone who steals a copy of our database.
We do store, and can see, the fact that a conversation exists: who is talking to whom, and when. We cannot see what is said.
Discussions in Rooms and other private spaces
Threads and discussions in Chambers, Rooms, Events and VIP Events are transmitted encrypted and stored encrypted at rest, but they are not yet end-to-end encrypted: technically we hold the keys. No one at OnlyCEO reads them. They are accessed by a human only if a participant reports a specific item, and then only the reported item, never the surrounding conversation. Every such access is logged. We are extending end-to-end encryption to these spaces and will say so here when it is done, rather than describing it before it is true.
Encryption keys and recovery
To make the above work we store: the public key of each device you approve (a public key can seal a message to you, it cannot open one), a record of each device (an identifier, platform and last-used time) so you can see and revoke them, per-message sealed key blobs addressed to each participant, and, if you create one, an encrypted backup of your key protected by your recovery phrase. Your recovery phrase is generated on your device and shown to you once. We never receive it and we do not store it. The backup we hold is opaque to us: without your phrase it is unreadable, including by us.
Butler and Privileges data
Requests you make to the Butler, and the details needed to fulfil them (for example travel dates or booking preferences), which are shared with the relevant Partner only when you confirm a request.
Technical data
Log data, device and browser information, IP address, and security events. The minimum needed to run and protect the service. We do not use advertising trackers.
2. Why we process it
| Purpose | Legal basis |
|---|---|
| Assessing your application and verifying identity and role | Contract (Art. 6.1.b); legitimate interest in a verified community (Art. 6.1.f); consent for biometric verification where required (Art. 9.2.a) |
| Operating the Platform, showing your content to the audiences you choose, delivering messages, running Chambers and Events | Contract (Art. 6.1.b) |
| Fulfilling Butler requests and Privileges via Partners, at your request | Contract (Art. 6.1.b) |
| Billing and invoicing | Contract (Art. 6.1.b); legal obligation (Art. 6.1.c, bookkeeping) |
| Safety: handling reports, enforcing the Code of Conduct, preventing abuse | Legitimate interest (Art. 6.1.f); legal obligation where reporting is mandated (Art. 6.1.c) |
| Security, logging, fraud prevention | Legitimate interest (Art. 6.1.f) |
| Service communications (approval, receipts, changes to terms) | Contract (Art. 6.1.b) |
We do not sell personal data, we do not use your data for third-party advertising, and we do not build advertising profiles. Members are never the product.
3. Anonymity on the Platform
Signals may be published anonymously. Anonymity applies toward other members. The connection between an anonymous Signal and its author exists in our systems, is access-restricted, and is used only for safety enforcement and legal obligations. We never reveal an anonymous author to other members.
4. How a report reaches us
Because we cannot read your Messages, a report about one cannot work by us going to look. When you report a message or a conversation, your device unlocks the last five messages of that conversation and sends them to us with the report, and the app tells you so before you confirm. That copy is preserved as evidence for the review and is retained as described in Section 7.
Two consequences follow, and we would rather state them than let you discover them:
- The only person who can hand us the contents of an encrypted conversation is a participant in it. If you are being mistreated in Messages, reporting is what lets us act.
- Because the text comes from the reporter's device rather than from our own records, our moderators see it labelled as such, and weigh it accordingly.
For content outside Messages (Signals, Threads, comments, Rooms), we take the snapshot ourselves at the moment of the report, so that later deletion cannot erase the case.
5. Who we share data with
Processors who run the service under contract with us: hosting and infrastructure providers, Stripe (identity verification and payments), email delivery, and error monitoring. Processors act only on our instructions.
Partners, only when you ask the Butler to arrange something or claim a Privilege, and only the details needed to fulfil that specific request. Partners act as independent controllers for their own service.
Authorities, where the law requires it (for example, content involving minors, or a valid order from police or courts). We disclose the minimum required and, where legally permitted, inform you.
No one else. We do not share member lists, and we never confirm or deny anyone's membership publicly.
6. International transfers
We keep data in the EU/EEA where feasible. Where a processor transfers data outside the EEA (for example Stripe, to the United States), the transfer is protected by the European Commission's adequacy decisions or Standard Contractual Clauses.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | For the life of your membership + 12 months |
| Enter the House applications (onlyceo.app form) | Deleted 12 months after submission if not progressed to membership |
| Verification outcome | Life of membership; Stripe Identity artifacts we hold are wiped when account deletion finalizes (no grace). Session data held by Stripe follows Stripe’s retention terms |
| Content in shared spaces | While published. On account deletion: authorship becomes “A former member” by default; optional purge soft-deletes your posts. Deleted content leaves backups on normal rotation |
| Messages and Rooms | Until you delete them. On account deletion the other party keeps their copy; you appear as departed |
| Device records and public keys | Until you revoke the device or delete your account |
| Encrypted key backup | Until you replace it or delete your account (unreadable to us throughout) |
| Moderation snapshots (report contentSnapshot / authorSnapshot) | Up to 12 months after the case, for safety and dispute review (legitimate interest) |
| Report and enforcement records | Duration of the case + 90 days, then purged (longer only if law requires) |
| Invoices and bookkeeping records | 7 years (Swedish Bookkeeping Act / Bokföringslagen); permitted under GDPR Art. 17(3)(b) |
| Security logs | 12 months |
8. Your rights
Under the GDPR you may: access your data; correct it; delete it; restrict or object to processing based on legitimate interest; receive a portable copy; and withdraw consent at any time where processing is based on consent. Write to privacy@onlyceo.app. We respond within 30 days.
You may also complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se, or to your local authority if you are elsewhere in the EU.
You can delete your account in the product at Settings → Account → Delete account (see also Delete Your Account). The account becomes invisible immediately; after a 14-day grace period we finalize automatically. By default we anonymize authorship rather than destroy shared threads; you may opt to also remove what you wrote. We retain only what Section 7 discloses (bookkeeping, moderation snapshots, security logs).
One limit is worth naming plainly. Your right of access and your right to a portable copy reach the data we hold. For Messages, what we hold is ciphertext, so the copy we can produce is the ciphertext and the conversation metadata, not the words. The readable copy of your Messages exists on your devices, where you can read and export it. We are not withholding it; we do not have it.
9. Security
All data is encrypted in transit (TLS) and at rest. Internal access follows least-privilege: private communications are inaccessible to staff except through the report-review process described above, and all such access is logged and auditable. We review access rights regularly and will notify you and IMY of any personal-data breach as the GDPR requires.
Messages are protected by construction, not only by policy. They are sealed with modern public-key cryptography (X25519 key agreement with XSalsa20-Poly1305 authenticated encryption) on your device, addressed to each participant separately. A breach of our servers would expose ciphertext, and ciphertext without a key is not a disclosure of your words.
Files and photographs you attach are stored in private storage and served only through short-lived signed links to members entitled to see them. They are not yet sealed end to end; we hold the keys to them. We will say so here when that changes.
Your devices. Files, photographs, and every message you have read live in readable form on the devices you have approved. That is the necessary consequence of a design in which only your devices hold the keys, and it means your devices are the place where your correspondence can actually be compromised. Lock them, and remove any device you no longer control from Settings.
10. Cookies
The Platform uses only strictly necessary cookies (session, security). No advertising or third-party tracking cookies. If this changes, we will ask for consent first.
11. Changes
We will notify you of material changes to this policy before they take effect. The current version always lives at onlyceo.app/legal.