Privacy Policy
Information about data needed for the account, trial, payments, and voluntary AI features. Document version: 2026-09-15.1. Approval date in configuration: 2026-09-01T16:15:07Z.
- Seller
- Artur Starosz AS Project
- Address
- ul. Franciszka Klimczaka 17/111, 02-797 Warszawa, Polska
- Registration / tax ID
- NIP 1132637775; REGON 388527577
- office@asproject.pl
- Phone
- +48607327549
- Document version
- 2026-09-15.1
- Approval date
- 2026-09-01T16:15:07Z
1. Controller and contact
The data controller is the seller identified in the business details on the document page. Questions, GDPR requests, and privacy matters may be sent to office@asproject.pl.
2. Data processed and abuse prevention
We process the email address and account language, link and session identifiers, trial, entitlement and feature-usage information, order data, amount, currency and tax evidence, and the content of support or Privacy Center requests. We do not store card numbers. We do not store a raw IP address; to enforce the one-trial rule, we retain a non-reversible HMAC of network data for 180 days. This identifier is used only to prevent abuse.
3. Recordings and data stored on the device
Standard Speaking recordings, answers, and progress may be stored locally in the user's browser or device. Unless AI analysis is selected, a Speaking recording is not sent to OpenAI. The application does not retain the raw Speaking recording file in its database.
4. OpenAI and voluntary AI features
The fixed Listening recordings were generated before publication as synthetic OpenAI audio output and contain no user data. When a user deliberately starts an optional AI feature, answers, written texts, exercise or task content, data needed for the prompt and — for Speaking analysis — the selected recording may be sent to OpenAI. OpenAI processes this data to generate transcription, assessment, feedback, or a report returned to the user.
5. Purposes and legal bases
We process data to enter into and perform the agreement, operate the account, provide the trial and purchased features, handle payments and complaints, fulfil data requests, and comply with tax and accounting duties. Security, abuse prevention, and the establishment or defence of claims rely on the controller's legitimate interests. A voluntary user action starts the processing needed to provide the selected AI feature. We do not sell data or use the sign-in form for marketing.
6. Providers, processing agreements, and transfers
We use OpenAI ChatGPT Sites and Cloudflare to host the application, Neon/Postgres for the database, Resend for transactional email, Stripe for payments, taxes and payment documents, and OpenAI for fixed Listening audio and voluntary AI operations. Each provider receives only the data needed for its role. We use required data-processing agreements with providers acting as processors. Where data is transferred outside the EEA, we use transfer mechanisms available in the provider's configuration and documentation, in particular an adequacy decision or Standard Contractual Clauses with appropriate safeguards.
7. Retention periods
We keep account data while the account is active and for 12 months after the account is closed or the last access expires. One-time-link and session records are deleted within 30 days after expiry or revocation. Feature-usage data is kept for 400 days. The network-data HMAC used against trial abuse is kept for 180 days; the record that an email address used a trial is retained while the account exists to enforce the one-trial rule. Orders and tax evidence are retained for 5 years from the end of the calendar year in which the tax payment deadline passed. Support cases and privacy requests are kept for 3 years after closure. Data connected with an ongoing dispute, proceeding, or claim may be kept longer until final resolution and expiry of the applicable limitation period.
8. Rights and Privacy Center
A user may use the Privacy Center to download an export of their data or submit a request to erase the account and data. They may also write to office@asproject.pl and, depending on the legal basis, request access, correction, erasure, restriction or portability and object to processing. We may ask for identity verification. Erasure does not cover data we must retain for tax, accounting, or ongoing-claim purposes. The user may complain to the President of the Polish Personal Data Protection Office or another competent authority.
9. Cookies and security
The platform uses an essential secure session cookie for sign-in and access control. We apply access restrictions, cryptographic hashes, retention controls, and provider controls appropriate to the data. Marketing analytics is not currently enabled.