Privacy Policy
Version in effect from: May 16, 2026
This Privacy Policy (the "Policy") describes how personal data of users of the Yskra service, available at yskra.pl, is processed. The Policy is drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR), the Polish Act on the Protection of Personal Data of 10 May 2018, and the Act on Providing Services by Electronic Means.
§1. Data controller
The data controller is ••••••••••••••••• — a Polish limited liability company registered in the National Court Register (KRS) under no. ••••••••••, with registered seat at ••••••••••••••••••••••••, NIP: ••••••••••, REGON: •••••••••, share capital: •••••••• (the "Controller").
Data protection contact: contact@yskra.plor postal mail to the Controller's registered address.
§2. Data Protection Officer (DPO)
The Controller has not appointed a Data Protection Officer — given the nature, scope and purposes of processing, the obligation under art. 37(1) GDPR does not apply. All data-related matters are handled by the Controller personally at the e-mail address indicated in §1.
§3. Categories of data processed
Depending on how you use the Service, we may process the following categories of data:
- Account data: e-mail address, password (stored as a cryptographic hash), first name or nickname, optionally display name, external account identifier (Google/Apple).
- Date of birth (DOB): required at registration to verify that the user is 18+. Stored for compliance purposes (GDPR art. 8, minor-protection law) and in case of regulatory inspection (UOKiK, PUODO). Not displayed publicly.
- Technical data: IP address, session identifier, browser type, operating system, language, time zone, device identifiers, cookie identifiers.
- Behavioural data: chat history with AI characters, list of unlocked photos, Coin balance, last-activity timestamps, streak days, preferred characters.
- Payment data:transaction amount and date, transaction identifier at the payment provider, payment method (e.g. "card", "BLIK"). Full card data is NOT stored by the Controller — it is processed solely by the payment provider (Stripe).
- Billing data: if you request an invoice — first name, last name, address, NIP (if applicable).
- Contact-form data: e-mail address, message content.
- Push-subscription data (when consent was given): push subscription identifier, consent status, history of sent notifications.
§4. Purposes and legal bases for processing
a) Providing services (contract)
Purpose: conclusion and performance of the contract for the provision of services by electronic means (creating an Account, AI chat, payments, photo unlocks).
Legal basis: art. 6(1)(b) GDPR (contract).
Retention: for the duration of the contract and until claims become time-barred.
b) Accounting and tax obligations
Purpose: issuing invoices, archiving accounting documents.
Legal basis: art. 6(1)(c) GDPR in conjunction with the Accounting Act and the VAT Act.
Retention: 5 years from the end of the financial year of issuance.
c) Defence against and pursuit of claims
Purpose: establishing, pursuing and defending against claims.
Legal basis: art. 6(1)(f) GDPR (legitimate interest of the Controller).
Retention: until claims become time-barred (typically 6 years).
d) Security and content moderation
Purpose: protecting the Service against abuse, fraud, attacks; detecting content in breach of the Terms (CSAM, suicide crisis, violence); discharging duties under the Digital Services Act (DSA).
Legal basis: art. 6(1)(f) GDPR (legitimate interest) and art. 6(1)(c) GDPR (legal obligation — DSA, AI Act).
Retention: 12 months from the last Account activity.
e) Marketing communications and notifications
Purpose: sending newsletters and browser push notifications about new messages from AI characters or promotions.
Legal basis: art. 6(1)(a) GDPR (consent) together with the Polish Act on Providing Services by Electronic Means art. 10 (consent for commercial information).
Retention: until consent is withdrawn.
f) Analytics and quality improvement
Purpose: statistical analysis of traffic, user behaviour, AI answer quality, UX problem detection. Data is processed in an aggregated/anonymised manner where possible.
Legal basis: art. 6(1)(f) GDPR (legitimate interest) or consent for analytics cookies.
§5. AI conversations — specific information
- The content of your conversations with AI characters is transmitted to the language model provider (OpenRouter, Inc. and Anthropic, PBC) solely to generate a reply. We configure providers so that your conversations are not used to train models.
- Part of the conversation context may be stored on the Controller's side as summaries and embedding vectors to ensure continuity (character "memory"). This data is linked to your Account.
- A sample of conversations may be reviewed by authorised Controller personnel for safety moderation and quality purposes. The personnel is bound by confidentiality.
- We apply automated content moderation that may block or flag your messages. The moderation decision does not produce legal effects nor significantly affect you within the meaning of art. 22 GDPR; if an Account is blocked for moderation reasons, you have the right to appeal.
§6. Recipients of the data (processors and partners)
Personal data may be transferred to the following categories of recipients with whom the Controller has signed data processing agreements (under art. 28 GDPR):
- Cloud infrastructure provider (hosting): Hetzner Online GmbH (Germany) — server region: European Union.
- Payment processor: Stripe Payments Europe Ltd. (Ireland) together with Stripe, Inc. (USA) — card, BLIK, Apple Pay and Google Pay processing.
- AI language model provider: OpenRouter, Inc. (USA) and Anthropic, PBC (USA) — generation of AI character replies in chat based on user prompts.
- Transactional e-mail provider: Resend, Inc. (USA) — sending e-mails (registration, payment confirmations, password resets).
- Product analytics provider: PostHog, Inc. (EU region) — analysis of traffic and behaviour in the Service.
- Security and CDN provider: Cloudflare, Inc. (USA with EU points of presence) — DDoS protection, content delivery.
- Invoicing system: Fakturownia sp. z o.o. (Poland) — issuing VAT invoices.
- Public authorities— only on the basis of a legal obligation (e.g. requests from police, prosecutor's office, UOKiK, PUODO).
§7. Transfers outside the European Economic Area (EEA)
Some data recipients (e.g. Stripe Inc., OpenRouter, Cloudflare) have their seat in the United States. Transfers are made on the basis of:
- The European Commission decision of 10 July 2023 on the EU-US Data Privacy Framework (DPF) — for entities certified under DPF, or
- Standard Contractual Clauses (SCC) adopted by the European Commission, supplemented by additional safeguards (encryption, access control) — for entities not certified under DPF.
§8. Your rights
Under GDPR you have the following rights:
- Right of access to your data (art. 15 GDPR).
- Right to rectification (art. 16 GDPR).
- Right to erasure ("right to be forgotten", art. 17 GDPR).
- Right to restriction of processing (art. 18 GDPR).
- Right to data portability (art. 20 GDPR).
- Right to object to processing based on legitimate interest (art. 21 GDPR).
- Right to withdraw consent at any time, without prejudice to the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
To exercise any of these rights, contact us at contact@yskra.pl. We respond within 30 days of receiving the request.
§9. Cookies
- The Service uses cookies and similar technologies (localStorage, sessionStorage, pixel tags). Detailed information about the cookies used is available in the Cookies Policy.
- We distinguish: necessary cookies (basic functionality — always on), analytics (traffic statistics — consent required), and marketing (ad campaigns, retargeting — consent required).
- Consents are collected via the cookie banner displayed on first visit and can be modified in the privacy settings panel.
§10. Data security
- We apply appropriate technical and organisational measures (TLS/SSL, password hashing, restricted personnel access, backups, security monitoring, periodic audits).
- In the event of a personal data breach we notify the President of UODO and the Users, where required by art. 33–34 GDPR.
§11. Profiling and automated decisions
- We apply profiling to a limited extent — in particular, recommending AI characters matched to user behaviour and matching photos to conversation content. Profiling does not produce legal effects for the User nor significantly affect them within the meaning of art. 22 GDPR.
- Automated content moderation (detection of CSAM, violent content) may result in temporary restriction of Account functionality — in such cases the User has the right to human intervention and to express their own viewpoint.
§12. User age
The Service is intended solely for persons aged 18 years or older. We do not knowingly collect data of persons under 18. If a parent or legal guardian learns that a minor has provided us with their data, please contact us immediately — the data will be deleted.
§13. Changes to the Policy
The Policy may be updated in case of legal changes, new features or new providers. We inform about material changes by e-mail and via an in-Service notice. The current version of the Policy is always available at /prywatnosc. The date of the last update is shown at the top of the document.