Privacy policy
What data we collect, what for, how long we keep it — and which rights you can exercise.
Last updated: 3 September 2026
1. Data controller
The controller of your personal data is [DO UZUPEŁNIENIA], registered office in [DO UZUPEŁNIENIA], VAT ID [DO UZUPEŁNIENIA].
For matters concerning personal data, write to the email address given on the contact page.
2. What we collect
We collect only what the Service needs:
- account data — email address, name, password stored as a hash;
- billing data — invoice details and payment history;
- technical data — IP address, browser and system, screen resolution, visit time;
- content you put into the tools and the results of operations;
- activity records needed to account for limits and detect abuse.
3. Why, and on what basis
Account data and content are processed to perform the contract — to provide the service you ordered (Art. 6(1)(b) GDPR).
Billing data is processed because tax and accounting law requires it (Art. 6(1)(c) GDPR).
Technical data and activity records are processed in our legitimate interest: security, abuse detection and improving the Service (Art. 6(1)(f) GDPR).
Marketing messages are sent only with your consent, which you may withdraw at any time (Art. 6(1)(a) GDPR).
4. How long we keep it
Account data and content — for the duration of the contract and thirty days after it ends, so you can retrieve your material.
Billing data — five years from the end of the tax year, as required by law.
Technical data — twelve months.
After those periods we delete the data permanently or strip it of anything that identifies you.
5. AI models
Some operations require sending content to an AI model provider. We send only the material needed for that operation.
We work with providers who have undertaken not to use the content we send to train their models.
We do not take decisions about you based solely on automated processing that would produce legal effects.
6. Who receives the data
Data goes only to parties the Service depends on:
- server infrastructure providers;
- AI model providers — to the extent described above;
- the payment operator — billing data only;
- our accountants — accounting documents only.
7. Transfers outside the EEA
Some AI providers operate outside the European Economic Area. Transfers are made under standard contractual clauses approved by the European Commission or an adequacy decision.
8. Your rights
You have the right to:
- access your data and receive a copy;
- have incorrect data corrected;
- have data erased where there is no basis for further processing;
- restrict processing;
- port your data to another controller;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting processing before withdrawal;
- lodge a complaint with the President of the Personal Data Protection Office.
9. Cookies
We use cookies necessary for the Service — they keep you signed in and remember your language and theme. These cannot be switched off without losing basic functions.
Analytics cookies, which help us understand how you use the Service, are set only after you agree. You may withdraw that in your browser settings or the consent panel.
10. Security
The connection to the Service is encrypted. Passwords are stored only as hashes, and mailbox and key credentials are encrypted.
Only people who need it for their work have access to the data, and every such access is logged.
If a data breach were likely to result in a high risk to your rights, we will tell you without undue delay.