Privacy Policy
What personal data DomaAI processes, why, for how long, who processes it on our behalf, and what rights you have under the GDPR.
Version 2026-10-16-v9 · Effective date: 16 October 2026
This is the new version (v9), which takes effect on 16 October 2026. Until 15 October 2026 version v8 applies. List of changes (in Polish).
Language of the agreement. This is the English version of the document. The Polish version is the source version and the other language versions are translations of it; where you are a consumer, the version in the language in which the contract was concluded with you prevails, and no translation may worsen your position. The binding Polish original is available at madd.im/regulamin.html and in the document centre. Nothing in this translation limits consumer rights arising from mandatory provisions of Polish and EU law.
This version takes effect on 16 October 2026. Until 15 October 2026 inclusive, version 2026-09-12-v8 applies. We publish it on 2 October 2026, together with the new version of the Terms of Use; the list of changes compared with v8 (in Polish) is at madd.im/prywatnosc-zmiany-v9.html.
This Privacy Policy describes what personal data we process in connection with the use of the DomaAI application (iOS) and its web version available at domaai.pl (the same Service is also available at the existing address madd.im), for what purpose, on what legal basis, for how long, and what rights the User has. It fulfils the information obligation under Articles 13 and 14 GDPR.
1. Data controller
The controller of personal data is Marcin Kisielinski, sole trader operating under the business name MADD Marcin Kisielinski (brands MADD / DomaAI), address for service: ul. Kajki 10-12, 10-547 Olsztyn, Poland, VAT ID (NIP) 7422297084, REGON 545106682 (entered in the CEIDG register).
Contact for data protection matters: [email protected] or [email protected].
The controller has not appointed a Data Protection Officer (DPO) - all data protection matters are handled at the e-mail addresses above.
2. What data we process
2.1. Account and identity data
- e-mail address,
- password - stored only as a hash (bcrypt), never in plain text,
- display name (full name) and an optional avatar,
- for Sign in with Apple - the Apple identifier (
apple_user_id); the e-mail address may be provided in anonymised (relay) form depending on Apple ID settings, - e-mail verification status and technical data of the verification / password reset process (one-time codes stored as hashes, temporarily),
- recorded consents and their versions (acceptance of the Terms of Use, the Privacy Policy, confirmation of being 16+, acknowledgement of the AI notice) and the marketing communication preference (opt-out),
- phone number - when the User links their WhatsApp number to the Account (a conversation with the assistant on WhatsApp; the number comes from the message the User sent to the DomaAI number, passed to us by Meta, and is used solely to link the conversation to the Account) or connects a business number to a Bot (Terms, section 13a.9),
- Automation agent settings: notification language and the preference for details in push notifications.
2.2. Content and activity in the Application
- conversation history: the content of the User's prompts and AI responses, including group chats,
- voice conversation history and related recordings/transcripts,
- vector representations (embeddings) of conversation fragments and remembered facts („memory”) used to personalise responses,
- files uploaded by the User and files/artifacts created in the Application (including project files),
- generated images and videos together with the prompts they were created from,
- project and workspace data and long-running tasks (the instruction, the result, an optional notification e-mail address),
- calendar events and reminders synchronised at the User's request (title, date, description, location, recurrence) - see section 5,
- content published in the social module (posts, comments, likes, display name, avatar) - see the Publishing Policy,
- audio recordings and transcripts of meetings (the meeting notes feature) - including the statements of other meeting participants, with speaker labelling; processed solely at the request of the User who invites the bot to the meeting; the User is responsible for informing meeting participants about the recording/transcription and for the lawfulness of such recording,
- public-procurement monitoring criteria (keywords, filters) and the notification e-mail address - if the User uses the tender monitoring feature.
2.3. Payment and subscription data
- information about the plan, subscription and Credit balance,
- in the iOS app - Apple In-App Purchase transaction identifiers (including
original_transaction_id,product_id, Sandbox/Production environment) and decoded App Store notifications (for billing and audit purposes), - in the web version - Stripe customer, transaction and subscription identifiers and billing data (e.g. billing address, country) provided to Stripe,
- We do not process payment card data - it is handled solely by Apple (iOS) or Stripe (web).
2.4. Technical and security data
- IP address - processed on an ad-hoc basis for rate limiting and anti-bot protection and, in persistent form, only in support/audit panel logs (record of activities),
- basic technical request data necessary for the service to operate,
- trusted device data used to confirm sign-ins and protect against account takeover: a hash of the device secret, the browser/OS „family” (User-Agent) and the prefix of the IP address (/24 for IPv4, /48 for IPv6 - not the full address); you can review your trusted devices and revoke their trust in Account settings,
- fingerprints of prompts sent to media generation - solely for abuse detection (no plain-text storage),
- error diagnostics data (Sentry monitoring) - with personal data (PII) transmission disabled by default, and masking of e-mail addresses, passwords, tokens and authentication headers,
- product events (our own telemetry) - a closed list of events about use of the Application (first launch, guest sign-in screen shown, sign-up completed, first message, first media generation, purchase screen shown, purchase, generation error) with minimal technical context (error type, source); no conversation content, no advertising identifiers and no third-party analytics SDKs - the events go only to our servers, and while you are not signed in they are recorded anonymously (not linked to an Account).
2.5. Integrations and connectors at the User's request
The User may connect their own accounts in external services ("Connectors") to the Application. As at the publication of this version of the Policy the following can be connected: Gmail, Google Calendar, GitHub and WhatsApp Business; the Google Ads and Shopify connectors are currently not available for connection, and the Meta connector (ad account, Facebook Page, Instagram) is visible in the Application, but until Meta grants the Application the required permissions an attempt to connect it is refused; the rules below apply to them from the moment connecting them becomes possible. The connectors and their connection status are shown in the Application (Account → Connectors). The connection is made through the provider's official authorisation mechanism (OAuth 2.0), and for WhatsApp Business and Telegram Bots - through an access token issued by the provider (in the Meta dashboard or via @BotFather) and pasted by the User, or by confirming the number with a code sent by Meta; the Application never asks for the password to those services, and the User chooses the scope of access and may revoke it at any time in the Application (Account → Connectors) or in the provider's settings.
- access tokens for connected services - stored only in encrypted form (Fernet, key kept outside the database); disconnecting a connector deletes the token on our side, and when the last Google connector is disconnected we also revoke the token with Google (revocation covers all of the User's Google connectors),
- identifier and name of the connected account (e.g. Google account e-mail, GitHub login, Shopify store address) and the granted scopes,
- the Agent's action log (in conversations and in automations): tool, time, status, object identifier and a shortened preview of the arguments (up to 500 characters) and of the result (up to 200 characters) with credentials masked; the content of messages sent is recorded in this log only as its length, and previews of results of tools reading a mailbox or conversations - as a character count. The log is visible to the User in the Application,
- the connector activity log (in conversations and in automations): connector, type of action (e.g. sending a message, creating an event, asking for approval), who performed it (the Agent in a conversation or an automation), time, outcome, object identifier and data describing the action - e.g. recipients (including CC) and subject of an e-mail, title and guests of an event, title of a document or issue, short fragments of text searched for and replaced in a document; without the content of messages sent. The User can see this log in the Application for the given connector,
- data retrieved from the service at the User's instruction (e.g. e-mail content, calendar events, repository content, Bot conversations) - processed ad hoc, solely to carry out the specific instruction given in a conversation or recorded in an Automation agent's Task; it is not copied into a separate database nor indexed. Excerpts may remain in the conversation history, in the result of a Run and in the content of an Approval (section 2.6) - for the periods in section 7; the User may delete them earlier,
- the configuration of other integrations (e.g. MCP servers) is excluded from data export.
Data from Google services (Gmail, Google Calendar, Google Ads). The Application's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide and improve user-facing features of the Application (carrying out the User's instruction); we do not use it for advertising, do not sell it, do not train AI models on it (neither our own nor providers' general models), and humans on our side do not read it unless the User gives consent, it is necessary for security purposes (e.g. investigating abuse), or the law requires it. Message or event content may be passed to a language-model provider (section 4) solely to generate the answer to the User's instruction, via a commercial API with no training. Automation agents use Gmail and Google Calendar data solely to carry out a Task defined by the User, within the permissions the User granted; every action is recorded in the log, and the connection can be revoked at any time. Google's verification of the Application is in progress - until it is completed Google may show a warning when connecting that the app has not been verified.
Irreversible actions. Sending an e-mail, publishing a post, inviting guests to an event, changing a store product or enabling an advertising campaign is performed by the Agent in a conversation only after the User's explicit consent - the consent mechanism is built into the Application and cannot be bypassed by the model. In automations, whether a given action requires approval (Ask mode, Approvals inbox), is performed on its own (Auto mode) or is unavailable (Never mode) is decided by the User when granting permissions to an Automation agent (Terms, section 13a.2); Auto mode for actions marked as requiring confirmation requires a separate confirmation, and enabling ad budget spend and changing store products never work in Auto mode.
2.6. Automation agents, Bots and third-party data
What we process. When the User creates an Automation agent (Terms, section 13a) or a WhatsApp or Telegram Bot, we process:
- the agent's configuration: name, role, instructions, selected AI model, Credit limit, permission modes (Auto / Ask / Never) and the recorded confirmations of Auto mode,
- Tasks: the instruction, the schedule or the webhook address together with the data sent to the webhook (e.g. form content), the delivery method,
- Run history: result (text), status, Credits charged, time,
- the agent's action log and the connector activity log (section 2.5),
- Approvals: the content of the action prepared by the agent (recipients, subject and body of a message, attachments, parameters), its preview, the User's decision and its time, and any edits made by the User,
- the Bot's configuration (instructions, greeting, number or identifier, and for a public Bot - its name in the „Start @name” link) and the conversations the Bot holds with third parties,
- the assignment of a contact's number to a public Bot on the DomaAI WhatsApp number (the contact's number and the Bot they are talking to),
- the opt-out register (STOP): the number of a contact who wrote „STOP” to a WhatsApp Bot, with the time - so that the Bot and agents send them no further messages until they write „START”,
- push notifications: by default the title and body contain no recipients or message content (e.g. only that an agent asks for approval to send an e-mail), and details are fetched when the Application is opened; if the User enables "Action details in notifications" in the Approvals tab, the body contains the description of the action - including the recipient and subject of a message - and is delivered to Apple in that form (section 4.3).
Third-party data (Art. 14 GDPR). This data may include data of persons other than the User: e-mail correspondents (senders and recipients), Bot contacts (WhatsApp number, Telegram identifier, conversation content), event guests, people submitting a form connected to a webhook and persons mentioned in documents. The source of this data is the services connected by the User (section 2.5) and the content those persons sent to the User or the User's Bot. We process it solely on the User's instruction, to carry out the User's Task or conversation, and never for our own purposes (in particular not for advertising and not for model training).
Our role. Towards the User we are the controller of the User's Account data. Where a User acting as a business instructs us to process data of their customers, contractors or contacts (a Bot on a business number, an agent answering customer enquiries), the User is the controller of that data and we are the processor under the data processing agreement contained in the Terms (section 13a.10). In that case the duty to inform those persons rests with the User; on request sent to [email protected] we provide a template notice.
People writing to the DomaAI WhatsApp number. On the DomaAI number:
- Users chat with their own assistant after linking their phone number to the Account - for those conversations we are the controller (sections 2.1 and 2.2);
- public Bots of businesses operate - a person who starts a conversation from a „Start @name” link shared by a User talks to that User's Bot: the messages are processed by the AI model chosen by the User, and the contact's number, the conversation content and the assignment of the number to the Bot are stored like Bot conversations (section 7); our role regarding that data is set out in the paragraph „Our role” (for a business User we are the processor). The assignment to the Bot ends when the contact writes „menu” or when the Bot is deleted; the Bot identifies itself as an AI system in its first reply;
- if a person whose number is neither linked to an Account nor assigned to a public Bot writes, we use their number and message solely to reply once with instructions on how to link a number to an Account: we do not store the message content, and we keep the number for up to 24 hours (so as not to repeat that reply) and in masked form in technical logs (Art. 6(1)(f) GDPR - handling contact).
Processing without the User present. An Automation agent carries out Tasks on our servers on a schedule, when a webhook is called or on demand - also when the Application is closed and the User is not present. It makes no decisions about the User within the meaning of Art. 22 GDPR; it carries out the User's instructions within the permissions granted.
Recipients. Content needed to carry out a Task or for a Bot to reply (including fragments of e-mails, conversations and documents, and therefore also third-party data) is sent to the provider of the AI model the User selected for the agent or Bot (e.g. OpenAI, Anthropic, xAI, Google - USA; Mistral AI - France) solely to generate the result, via a commercial API with no training (section 4). Push notifications are delivered by Apple (APNs). WhatsApp messages sent and received by Bots and agents pass through Meta Platforms Ireland Ltd (WhatsApp Cloud API); for the DomaAI number and numbers registered in our WhatsApp Business account (hosted numbers) Meta acts as our processor, and for a number the User registered in their own WhatsApp Business account - as an independent controller. Telegram Bot messages pass through Telegram, acting as an independent controller. E-mails sent by an agent leave from the User's Gmail account (Google LLC).
Labelling. Bots identify themselves to the contact as an AI system in their first reply. E-mails and WhatsApp messages sent by an agent on the User's behalf are currently not automatically labelled as prepared with AI (Terms, section 3.4(e)).
Control. The User may at any time switch off a Task, pause all Tasks, delete an agent, disable or delete a Bot, delete a Task's history or a single Run, reject an Approval, turn off details in notifications and disconnect a connector; this data is also covered by data export and Account deletion (section 8).
3. Purposes and legal bases of processing
| Purpose | Scope of data | Legal basis (GDPR) |
|---|---|---|
| Providing the Service (account, conversations, content generation, integrations) | account, content and activity data | Art. 6(1)(b) - performance of a contract |
| Billing, subscriptions, refund handling | payment/subscription data | Art. 6(1)(b) and (c) - legal obligations (incl. accounting) |
| Security, abuse prevention, moderation | technical data, IP, fingerprints, content submitted for moderation | Art. 6(1)(f) - legitimate interest |
| Personalising responses (memory, embeddings) | embeddings, remembered facts | Art. 6(1)(b) and (f) |
| Handling requests, complaints and contact | contact data, content of the request | Art. 6(1)(b)/(f) |
| Compliance with legal obligations (GDPR, AI Act, accounting) | account data, consents, billing, audit | Art. 6(1)(c) |
| Automation agents and Bots (carrying out Tasks, Bot conversations, Approvals, log, notifications) | agent and Bot configuration, Tasks, Run history, Approvals, log, Bot conversations, third-party data under section 2.6 | Art. 6(1)(b) - performance of a contract (Terms, section 13a); third-party data processed on the instruction of a business User - as a processor (Art. 28 GDPR); third-party data where the User does not act as a business - Art. 6(1)(f) (legitimate interest: carrying out the User's instruction towards their correspondents and contacts); logs, limits and abuse prevention - Art. 6(1)(f); opt-out register (STOP) - Art. 6(1)(f) (respecting an objection to further messages, including under WhatsApp Business rules) |
| Marketing communication (newsletter, product news) | e-mail address | Art. 6(1)(a) - consent; consent may be withdrawn at any time in Account settings or via the link in the message |
4. Data recipients and AI model providers (sub-processors)
4.1. To provide the Service we use external providers acting as processors. Conversation content and prompts may be transmitted to AI model providers solely in order to generate a response.
4.2. We do not sell personal data. Data is not used to train providers' AI models - details in the AI data and model training policy. Prompts are sent to LLM providers in commercial API mode, without the content being used for training; where available, a zero-retention mode is applied.
4.3. The current list of sub-processors (name, purpose, location, transfer basis outside the EEA) is available in the list of sub-processors. They include: OpenAI (language models, realtime voice, moderation; DPA concluded with OpenAI Ireland Ltd), Anthropic (Claude language models; DPA concluded with Anthropic Ireland Ltd), Mistral AI (language models, processing in the EU), Google (Gemini models, Veo video, Nano Banana images; maps and trip planning), xAI/Grok (language models; image/video generation, editing and animation), Cartesia (speech synthesis), Tavily and SteadyAPI (web search/content retrieval), Apify (monitoring of public procurement notices), Open-Meteo (weather), OVHcloud (server hosting), Apple (sign-in, iOS payments, EventKit), Stripe (web payments), inFakt (invoicing, KSeF), Sentry (error monitoring), Apple (APNs push notification service - device token and the title and body of the notification; by default without recipients or message content, and with a description of the action, e.g. the recipient and subject of an e-mail, only if the User enables details in notifications), Meta Platforms Ireland Ltd (WhatsApp Cloud API - for the DomaAI number and numbers registered in our WhatsApp Business account), an e-mail provider (transactional e-mails), Cloudflare (anti-bot protection). Providers of services connected at the User's request (section 2.5) - Google LLC (Gmail, Calendar, Google Ads), GitHub Inc., Shopify International Ltd, Meta Platforms Ireland Ltd (ad account, Page, the User's own WhatsApp Business number), Telegram (Telegram Bots) - are not our processors: they act as independent controllers of the User's data in their own services, and we obtain access only to the extent and for the time indicated by the User.
4.4. Transfers outside the EEA. Some providers (including in the USA) may process data outside the European Economic Area. In such cases the transfer is based on standard contractual clauses (SCCs) or other mechanisms compliant with Chapter V GDPR. A copy of the safeguards applied (e.g. the standard contractual clauses) or information on where they are available can be obtained by contacting us at the addresses given in section 1. Accounts, conversation history and files are stored on servers in the European Union (hosting: OVHcloud, EU data centre).
5. Calendar, reminders and on-device data
5.1. Calendar and reminder features work through the Apple system integration (EventKit) on the User's device. Access to the calendar/reminders requires permission granted in iOS and may be revoked at any time in system settings.
5.2. At the User's request, event and reminder data (including title, date, description, location) is synchronised with our backend so that the Agent can manage it. Deletion of an event uses a „tombstone” model (a deletion marker) that keeps the device in sync.
6. Files, code and the Agent's browser
6.1. Files uploaded by the User and files created in the Application are stored on the server or in the database (depending on type) and linked to the Account.
6.2. Code executed by the Agent runs in an isolated environment (sandbox) with no network access inside the sandbox; the Agent's browser uses network traffic filtered for security. Data produced during the Agent's work (workspace) is linked to the Account and is deleted together with it.
7. Retention periods
| Category | Retention period |
|---|---|
| Account data and content | for as long as the Account exists |
| Account after deletion (soft delete) | 30 days (recovery window), then permanent erasure; with an active subscription, no earlier than 7 days after the end of the paid period (Art. 17(3)(b) GDPR) |
| Artifacts (files created by the Agent) | up to 30 days from last use (quantity limit per Account) |
| Embeddings / vector memory | up to 90 days (quantity limit per Account) |
| Conversation trash | up to 90 days |
| ReAct plans/tasks | up to 30 days |
| Calendar deletion markers (tombstones) | 7 days |
| Technical logs | maximum 12 months |
| Connector access tokens (section 2.5) | until the User disconnects the connector or deletes the Account; Google tokens are revoked with the provider when the last Google connector is disconnected |
| Agent action log (conversations and automations: tool, status, shortened preview of arguments and result) | 90 days; earlier on deletion of the Run or the Account |
| Connector activity log (type of action, object identifier, e.g. recipients and subject of a message, title and guests of an event - without the content of messages sent) | until the Account is deleted; entries created in an Automation agent's Run - also when that Run is deleted |
| Automation Run history (result, cost, status) | 180 days from the Run; the last 20 Runs of each Task - until the Task or Account is deleted; the User may delete earlier |
| Run input data sent via a webhook (e.g. form content) | 24 hours from the Run (a note that it was deleted remains) |
| Automation Approvals | action content (arguments) - 30 days from the decision or expiry; remaining Approval data (status, time, tool, description and a preview of the action without message content, e.g. recipients and subject) - 90 days from the creation of the Approval |
| Agent, Task and Bot configuration, Auto-mode confirmations, notification settings | until deleted by the User or on Account deletion |
| Bot conversations with third parties (WhatsApp/Telegram, including conversations of public Bots on the DomaAI number) | until deleted by the User, on deletion of the Bot or on Account deletion |
| Assignment of a contact's number to a public Bot on the DomaAI number | until the contact writes „menu”, on deletion of the Bot or on Account deletion |
| Opt-out register (STOP) - number of a WhatsApp Bot contact | until the contact writes „START”, on deletion of the Bot or on Account deletion |
| Phone number linked to the Account (WhatsApp) | until the number is unlinked or the Account deleted |
| Number of a person without an Account writing to the DomaAI number (not assigned to a public Bot) | up to 24 hours; in technical logs - in masked form |
| Data retrieved from a connected service at the User's instruction | ad hoc, for the duration of the instruction; any excerpts in conversation history - as account data and content |
| Backups (GPG-encrypted) | 14-day rotation |
| Billing / accounting data | 5 years from the end of the tax year in which the tax obligation arose (Art. 86 § 1 of the Tax Ordinance, Art. 74 of the Accounting Act) |
| Consent and claims data | until limitation periods expire (as a rule 6 years, Art. 118 of the Civil Code) |
Permanent deletion of an Account is carried out by a recurring process that erases files, data in all tables linked to the User, and the Account itself; the deletion is recorded in the audit log.
8. User rights
Under the GDPR the User has the right to:
- access the data and obtain a copy of it (Art. 15),
- rectification of the data (Art. 16),
- erasure of the data - the „right to be forgotten” (Art. 17),
- restriction of processing (Art. 18) - implemented in the Application among others through the account freeze feature,
- data portability (Art. 20) - the Application offers a data export in ZIP format (the „Download my data” feature),
- object to processing based on legitimate interest, including direct marketing (Art. 21),
- withdraw consent at any time (without affecting the lawfulness of processing carried out beforehand),
- lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
Most rights can be exercised directly in the Application (export, deletion, freezing/unfreezing the Account, profile editing, marketing opt-out) or by contacting [email protected] or [email protected].
Is providing data voluntary? Providing an e-mail address and password (or using Sign in with Apple) is a condition of concluding and performing the contract - without that data we cannot create an Account. Providing other data (e.g. display name, avatar, conversation content, calendar data) is voluntary and serves to enable the relevant features.
Sources of data. We obtain data directly from the User; from providers of services connected by the User (Google, GitHub, Shopify, Meta) - the account identifier and the data the User asks the Agent for; and, in addition: from Apple Inc. - the Apple account identifier and (possibly hidden/relay) e-mail address when using Sign in with Apple, and App Store transaction notifications; from Stripe - payment and subscription statuses; from Meta - the User's phone number from the message sent to the DomaAI number; for Automation agents and Bots - third-party data described in section 2.6, coming from those persons' messages to the User or the User's Bot, from services connected by the User and from forms connected to a webhook (Art. 14 GDPR).
9. Automated processing and AI
9.1. The Application uses artificial intelligence to generate responses and content. AI Content may be wrong - it should not be treated as binding advice (see the Terms of Use, section 3).
9.2. The Application does not take automated decisions producing legal effects or similarly significant effects concerning the User within the meaning of Article 22 GDPR. Content moderation and the safety gates (legal-risk and abuse) serve only security and legal compliance: they may automatically refuse a single instruction and flag a conversation for review, but a decision on a measure against the Account (warning, restriction, suspension, termination - sections 8.6 and 11.3 of the Terms) is taken by a human, not by the system. Personalisation of responses (memory, embeddings) constitutes profiling within the meaning of Article 4(4) GDPR but does not lead to decisions referred to in Article 22 GDPR; the User can manage and delete memory in the Application and object (Art. 21 GDPR). An Automation agent acts on the User's instruction and within the permissions the User granted; its actions are not decisions taken about the User within the meaning of Article 22 GDPR.
9.3. In accordance with Article 50 of the AI Act we inform the User that they are interacting with an AI system; acknowledgement of this notice is recorded (versioned).
9.4. Marking of AI-generated content (Article 50(2) of the AI Act). Content generated in the Application is marked in a machine-readable format, as far as technically feasible for the format concerned:
- images - file metadata (EXIF in JPEG/WebP:
ImageDescription,Software,Artist,CopyrightandUserCommentcarrying the data as JSON; in PNG, the corresponding text fields) and a visible watermark „AI · DomaAI” in the bottom-right corner of every image generated or modified by AI, - video files - container tags (including
title,description,copyrightandcommentcarrying the same data as JSON) and a visible watermark „AI · DomaAI” in the frame, - hosted websites (built by the Agent and published at an address in the domaai.pl domain) -
<meta name="generator">,<meta name="ai-generated">and<meta name="ai-disclosure">tags in the page code and a visible footer stating that the content was prepared with AI, - text in conversations - the notice in the Application's interface that you are talking to an AI system, and the „Generated in DomaAI” notice when a conversation is shared by link,
- synthesised speech in voice mode is streamed in real time, with no resulting file on our side - file tags cannot be attached to such a stream, so the information that you are talking to an AI system is given in the Application's interface (section 9.3).
The metadata marking identifies content as AI-generated; it is not a cryptographic signature and can be removed by any metadata-editing tool, including outside our control; the visible watermark can be removed by cropping or retouching, which the Terms of Use (sections 3.4(d) and 8.5) prohibit. A separate disclosure obligation rests with a User who publishes content depicting existing persons, places or events (deep fake) - see section 3.4 of the Terms of Use.
10. Security
We apply technical and organisational measures appropriate to the risk, including: encryption of connections (TLS), password hashing (bcrypt), encryption of integration credentials (Fernet) and of backups (GPG AES-256), isolation of the Agent's execution environment, anti-bot protection, data minimisation in logs (masking/fingerprints) and personal data breach response procedures. In the event of a breach likely to result in a high risk to the User's rights and freedoms, we will notify them in accordance with Article 34 GDPR.
Data at rest (the database, uploaded and generated files and the Agent's working files) is stored on an encrypted volume (LUKS, AES-XTS). Vulnerability disclosure: security researchers may report vulnerabilities to [email protected] (see /.well-known/security.txt at madd.im and domaai.pl); good-faith reports are not pursued and the reporter receives an acknowledgement and information about the fix.
11. Cookies
The rules on cookies and similar technologies are set out in a separate document: the Cookie Policy.
12. Changes to this Policy
This Policy may be updated. We will give advance notice of material changes in the Application or by e-mail; the previous version is available on request at [email protected]. The current version is available in the Application and at madd.im.
Related documents: Terms of Use, AI data and model training policy, List of sub-processors, Data Processing Agreement (DPA).