Privacy Policy
1. Data we process
- Account data: email address, name, hashed password, plan and subscription status.
- Content you submit: chat messages, selection requirements, design briefs — processed to generate responses, and stored in your history until you delete them.
- Usage data: per-request module name, token counts, duration and timestamps — used for plan limits, abuse prevention and product improvement. Message content is never part of usage records.
- Payments: handled by Stripe; we never store card numbers.
2. Purposes and legal bases
- Providing the Service and account management — performance of a contract (art. 6(1)(b) GDPR).
- Billing and tax records — legal obligation (art. 6(1)(c)).
- Service security, abuse prevention, product improvement — legitimate interest (art. 6(1)(f)).
3. Processors and transfers
To generate AI responses, your prompts are transmitted to Anthropic, which operates the Claude models. If you sign in with Google or Microsoft, we receive your name and email address from that provider — nothing more. Database queries derived from your requests (e.g. element lists) are sent to open scientific APIs (Materials Project, OQMD, Open Materials Database, RepOD) — these queries contain no personal data. Hosting and data storage are provided by the hosting platform (application server and its database). Where processors are outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
4. Retention
- Account data: for the life of the account and up to 12 months after deletion (backups, claims).
- Conversations and saved results: until you delete them or your account.
- Billing records: as required by tax law (in Poland, 5 years).
5. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority (in Poland: PUODO, uodo.gov.pl). Exercise them via the support email shown in the app.
6. Cookies and local storage
The app uses strictly necessary storage only: the authentication session cookie and functional preferences kept in your browser (theme, panel state). No advertising or cross-site tracking cookies are used.
7. Security
Measures include TLS in transit, server-side-only API keys, input validation, rate limiting and least-privilege database access. See also the Terms of Service.