Privacy Policy
What personal data DomaAI processes, why, for how long, who processes it on our behalf, and what rights you have under the GDPR.
Version 2026-07-13-v4 · Effective date: 13 July 2026
Language of the agreement. This is the English version of the document, provided for the convenience of international users. The language of the contract is Polish; in the event of any discrepancy between language versions, the Polish version prevails. The binding Polish original is available at madd.im/regulamin.html and in the document centre. Nothing in this translation limits consumer rights arising from mandatory provisions of Polish and EU law.
This Privacy Policy describes what personal data we process in connection with the use of the DomaAI application (iOS) and its web version available at madd.im, for what purpose, on what legal basis, for how long, and what rights the User has. It fulfils the information obligation under Articles 13 and 14 GDPR.
1. Data controller
The controller of personal data is Marcin Kisielinski, sole trader operating under the business name MADD Marcin Kisielinski (brands MADD / DomaAI), address for service: ul. Kajki 10-12, 10-547 Olsztyn, Poland, VAT ID (NIP) 7422297084, REGON 545106682 (entered in the CEIDG register).
Contact for data protection matters: [email protected] or [email protected].
The controller has not appointed a Data Protection Officer (DPO) - all data protection matters are handled at the e-mail addresses above.
2. What data we process
2.1. Account and identity data
- e-mail address,
- password - stored only as a hash (bcrypt), never in plain text,
- display name (full name) and an optional avatar,
- for Sign in with Apple - the Apple identifier (
apple_user_id); the e-mail address may be provided in anonymised (relay) form depending on Apple ID settings, - e-mail verification status and technical data of the verification / password reset process (one-time codes stored as hashes, temporarily),
- recorded consents and their versions (acceptance of the Terms of Use, the Privacy Policy, confirmation of being 16+, acknowledgement of the AI notice) and the marketing communication preference (opt-out).
2.2. Content and activity in the Application
- conversation history: the content of the User's prompts and AI responses, including group chats,
- voice conversation history and related recordings/transcripts,
- vector representations (embeddings) of conversation fragments and remembered facts („memory”) used to personalise responses,
- files uploaded by the User and files/artifacts created in the Application (including project files),
- generated images and videos together with the prompts they were created from,
- project and workspace data and long-running tasks (the instruction, the result, an optional notification e-mail address),
- calendar events and reminders synchronised at the User's request (title, date, description, location, recurrence) - see section 5,
- content published in the social module (posts, comments, likes, display name, avatar) - see the Publishing Policy,
- audio recordings and transcripts of meetings (the meeting notes feature) - including the statements of other meeting participants, with speaker labelling; processed solely at the request of the User who invites the bot to the meeting; the User is responsible for informing meeting participants about the recording/transcription and for the lawfulness of such recording,
- public-procurement monitoring criteria (keywords, filters) and the notification e-mail address - if the User uses the tender monitoring feature.
2.3. Payment and subscription data
- information about the plan, subscription and Credit balance,
- in the iOS app - Apple In-App Purchase transaction identifiers (including
original_transaction_id,product_id, Sandbox/Production environment) and decoded App Store notifications (for billing and audit purposes), - in the web version - Stripe customer, transaction and subscription identifiers and billing data (e.g. billing address, country) provided to Stripe,
- We do not process payment card data - it is handled solely by Apple (iOS) or Stripe (web).
2.4. Technical and security data
- IP address - processed on an ad-hoc basis for rate limiting and anti-bot protection and, in persistent form, only in support/audit panel logs (record of activities),
- basic technical request data necessary for the service to operate,
- fingerprints of prompts sent to media generation - solely for abuse detection (no plain-text storage),
- error diagnostics data (Sentry monitoring) - with personal data (PII) transmission disabled by default, and masking of e-mail addresses, passwords, tokens and authentication headers.
2.5. Integrations at the User's request
- credentials for social-media integrations (OAuth tokens) - stored in encrypted form (Fernet); the configuration of other integrations (e.g. MCP servers) is excluded from data export.
3. Purposes and legal bases of processing
| Purpose | Scope of data | Legal basis (GDPR) |
|---|---|---|
| Providing the Service (account, conversations, content generation, integrations) | account, content and activity data | Art. 6(1)(b) - performance of a contract |
| Billing, subscriptions, refund handling | payment/subscription data | Art. 6(1)(b) and (c) - legal obligations (incl. accounting) |
| Security, abuse prevention, moderation | technical data, IP, fingerprints, content submitted for moderation | Art. 6(1)(f) - legitimate interest |
| Personalising responses (memory, embeddings) | embeddings, remembered facts | Art. 6(1)(b) and (f) |
| Handling requests, complaints and contact | contact data, content of the request | Art. 6(1)(b)/(f) |
| Compliance with legal obligations (GDPR, AI Act, accounting) | account data, consents, billing, audit | Art. 6(1)(c) |
| Marketing communication (newsletter, product news) | e-mail address | Art. 6(1)(a) - consent; consent may be withdrawn at any time in Account settings or via the link in the message |
4. Data recipients and AI model providers (sub-processors)
4.1. To provide the Service we use external providers acting as processors. Conversation content and prompts may be transmitted to AI model providers solely in order to generate a response.
4.2. We do not sell personal data. Data is not used to train providers' AI models - details in the AI data and model training policy. Prompts are sent to LLM providers in commercial API mode, without the content being used for training; where available, a zero-retention mode is applied.
4.3. The current list of sub-processors (name, purpose, location, transfer basis outside the EEA) is available in the list of sub-processors. They include: OpenAI (language models, realtime voice, moderation), Anthropic (Claude language models), xAI/Grok (language models; image/video generation, editing and animation), Cartesia (speech synthesis), Tavily and SteadyAPI (web search/content retrieval), Apify (monitoring of public procurement notices), Google (maps and trip planning, Gemini model), Open-Meteo (weather), OVHcloud (server hosting), Apple (sign-in, iOS payments, EventKit), Stripe (web payments), inFakt (invoicing, KSeF), Sentry (error monitoring), an e-mail provider (transactional e-mails), Cloudflare (anti-bot protection).
4.4. Transfers outside the EEA. Some providers (including in the USA) may process data outside the European Economic Area. In such cases the transfer is based on standard contractual clauses (SCCs) or other mechanisms compliant with Chapter V GDPR. A copy of the safeguards applied (e.g. the standard contractual clauses) or information on where they are available can be obtained by contacting us at the addresses given in section 1. Accounts, conversation history and files are stored on servers in the European Union (hosting: OVHcloud, EU data centre).
5. Calendar, reminders and on-device data
5.1. Calendar and reminder features work through the Apple system integration (EventKit) on the User's device. Access to the calendar/reminders requires permission granted in iOS and may be revoked at any time in system settings.
5.2. At the User's request, event and reminder data (including title, date, description, location) is synchronised with our backend so that the Agent can manage it. Deletion of an event uses a „tombstone” model (a deletion marker) that keeps the device in sync.
6. Files, code and the Agent's browser
6.1. Files uploaded by the User and files created in the Application are stored on the server or in the database (depending on type) and linked to the Account.
6.2. Code executed by the Agent runs in an isolated environment (sandbox) with no network access inside the sandbox; the Agent's browser uses network traffic filtered for security. Data produced during the Agent's work (workspace) is linked to the Account and is deleted together with it.
7. Retention periods
| Category | Retention period |
|---|---|
| Account data and content | for as long as the Account exists |
| Account after deletion (soft delete) | 30 days (recovery window), then permanent erasure; with an active subscription, no earlier than 7 days after the end of the paid period (Art. 17(3)(b) GDPR) |
| Artifacts (files created by the Agent) | up to 30 days from last use (quantity limit per Account) |
| Embeddings / vector memory | up to 90 days (quantity limit per Account) |
| Conversation trash | up to 90 days |
| ReAct plans/tasks | up to 30 days |
| Calendar deletion markers (tombstones) | 7 days |
| Technical logs | maximum 12 months |
| Backups (GPG-encrypted) | 14-day rotation |
| Billing / accounting data | 5 years from the end of the tax year in which the tax obligation arose (Art. 86 § 1 of the Tax Ordinance, Art. 74 of the Accounting Act) |
| Consent and claims data | until limitation periods expire (as a rule 6 years, Art. 118 of the Civil Code) |
Permanent deletion of an Account is carried out by a recurring process that erases files, data in all tables linked to the User, and the Account itself; the deletion is recorded in the audit log.
8. User rights
Under the GDPR the User has the right to:
- access the data and obtain a copy of it (Art. 15),
- rectification of the data (Art. 16),
- erasure of the data - the „right to be forgotten” (Art. 17),
- restriction of processing (Art. 18) - implemented in the Application among others through the account freeze feature,
- data portability (Art. 20) - the Application offers a data export in ZIP format (the „Download my data” feature),
- object to processing based on legitimate interest, including direct marketing (Art. 21),
- withdraw consent at any time (without affecting the lawfulness of processing carried out beforehand),
- lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
Most rights can be exercised directly in the Application (export, deletion, freezing/unfreezing the Account, profile editing, marketing opt-out) or by contacting [email protected] or [email protected].
Is providing data voluntary? Providing an e-mail address and password (or using Sign in with Apple) is a condition of concluding and performing the contract - without that data we cannot create an Account. Providing other data (e.g. display name, avatar, conversation content, calendar data) is voluntary and serves to enable the relevant features.
Sources of data. We obtain data directly from the User and, in addition: from Apple Inc. - the Apple account identifier and (possibly hidden/relay) e-mail address when using Sign in with Apple, and App Store transaction notifications; from Stripe - payment and subscription statuses (Art. 14 GDPR).
9. Automated processing and AI
9.1. The Application uses artificial intelligence to generate responses and content. AI Content may be wrong - it should not be treated as binding advice (see the Terms of Use, section 3).
9.2. The Application does not take automated decisions producing legal effects or similarly significant effects concerning the User within the meaning of Article 22 GDPR. Content moderation serves only security and legal compliance. Personalisation of responses (memory, embeddings) constitutes profiling within the meaning of Article 4(4) GDPR but does not lead to decisions referred to in Article 22 GDPR; the User can manage and delete memory in the Application and object (Art. 21 GDPR).
9.3. In accordance with Article 50 of the AI Act we inform the User that they are interacting with an AI system; acknowledgement of this notice is recorded (versioned).
10. Security
We apply technical and organisational measures appropriate to the risk, including: encryption of connections (TLS), password hashing (bcrypt), encryption of integration credentials (Fernet) and of backups (GPG AES-256), isolation of the Agent's execution environment, anti-bot protection, data minimisation in logs (masking/fingerprints) and personal data breach response procedures. In the event of a breach likely to result in a high risk to the User's rights and freedoms, we will notify them in accordance with Article 34 GDPR.
11. Cookies
The rules on cookies and similar technologies are set out in a separate document: the Cookie Policy.
12. Changes to this Policy
This Policy may be updated. We will give notice of material changes in the Application or by e-mail. The current version is available in the Application and at madd.im.
Related documents: Terms of Use, AI data and model training policy, List of sub-processors, Data Processing Agreement (DPA).