Privacy Policy

Last updated: December 5, 2025

1. Introduction

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Varshava AI. We are committed to protecting your privacy and handling your data in accordance with applicable data protection laws.

We process personal data in accordance with the Federal Act on Data Protection (FADP) of Switzerland and the General Data Protection Regulation (GDPR) where applicable to users in the European Economic Area.

By registering in Varshava AI, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

The data controller responsible for your personal data is:

info@varshava.ai

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at the email address above.

3. Definitions

  • Varshava AI – the online software service available via web browser and mobile devices

  • Personal Data – any information that identifies or can be used to identify an individual

  • Data Subject – a natural person whose personal data is being processed (you)

  • Processing – any operation performed on personal data, such as collection, storage, use, or deletion

  • Consent – a clear and voluntary agreement to allow personal data to be processed

4. Personal Data We Collect

We collect the following categories of personal data:

Account Information:

  • Name and email address (required for registration)

  • Password (stored securely using encryption)

User-Generated Content:

  • Goals, tasks, and progress data you create

  • Messages and conversations with the AI coach

  • Personal context information you choose to share

  • Summaries and notes

Technical Data:

  • IP address and approximate location

  • Browser type and version

  • Device type and operating system

  • Date and time of access

Usage Data (with your consent):

  • Features used and actions performed

  • Session duration and page views

5. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the services you registered for (account data, user content, AI processing)

  • Consent: Processing based on your explicit consent, such as analytics cookies and marketing communications (you can withdraw consent at any time)

  • Legitimate Interest: Processing necessary for our legitimate interests, such as improving Varshava AI, preventing fraud, and ensuring security

  • Legal Obligation: Processing required to comply with legal requirements

6. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your account

  • To provide the AI coaching features and generate personalized responses

  • To store and display your goals, tasks, and progress

  • To send you important notifications (account security, service updates)

  • To process payments if you subscribe to a paid plan

  • To improve Varshava AI based on usage patterns (with your consent)

  • To respond to your support requests

7. AI Data Processing

Varshava AI uses artificial intelligence to provide personalized coaching. When you interact with the AI coach, your messages and relevant context are processed by OpenAI's language models.

What data is sent to OpenAI:

  • Your chat messages and conversation history

  • Goals and tasks relevant to the conversation

  • Personal context you have provided (if applicable)

OpenAI processes this data to generate responses. According to OpenAI's data usage policy, data sent through the API is not used to train their models. For more information, please review OpenAI's Privacy Policy.

8. Third-Party Services

We use the following third-party services to operate Varshava AI:

OpenAI

Purpose: AI-powered coaching and text generation. Data shared: Chat messages and user context. Privacy Policy

Google Analytics (with your consent)

Purpose: Understanding how users interact with Varshava AI. Data shared: Usage data, device information. Privacy Policy

Stripe

Purpose: Processing subscription payments. Data shared: Payment information (we do not store your card details). Privacy Policy

9. International Data Transfers

Your personal data may be transferred to and processed in countries outside of your country of residence, including the United States (where OpenAI and other service providers are located).

When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or reliance on the service provider's compliance with applicable data protection frameworks.

10. Data Retention

We retain your personal data for as long as necessary to provide our services:

  • Account data: Retained while your account is active and deleted upon account deletion

  • User content (goals, tasks, chats): Retained while your account is active and deleted upon account deletion

  • Technical logs: Retained for up to 90 days for security and debugging purposes

  • Analytics data: Retained according to Google Analytics retention settings (up to 14 months)

After account deletion, we may retain anonymized or aggregated data that cannot be used to identify you.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption of data in transit (HTTPS/TLS)

  • Secure password hashing

  • Regular security updates and monitoring

  • Access controls and authentication

While we take reasonable precautions, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

12. Your Rights

Under applicable data protection laws, you have the following rights:

  • Right to access: Request a copy of your personal data

  • Right to rectification: Request correction of inaccurate data

  • Right to erasure: Request deletion of your personal data

  • Right to restrict processing: Request limitation of how we use your data

  • Right to data portability: Request your data in a machine-readable format

  • Right to object: Object to processing based on legitimate interests

  • Right to withdraw consent: Withdraw consent at any time (this does not affect the lawfulness of processing before withdrawal)

13. How to Exercise Your Rights

You can exercise many of your rights directly within Varshava AI:

  • Update your data: Profile → Account → Contact Information

  • Delete your account: Profile → Account → Data Management → Delete Account

  • Manage consents: Profile → Account → Data Management → Consents

  • Delete chat history: Profile → Account → Data Management → Delete Chat History

For other requests, please contact us at info@varshava.ai. We will respond to your request within 30 days.

14. Cookies

We use cookies and similar technologies to operate Varshava AI. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

15. Supervisory Authority

If you believe that our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with a supervisory authority.

For users in Switzerland, the relevant authority is:

Federal Data Protection and Information Commissioner (FDPIC)
Website: edoeb.admin.ch

For users in the European Union, you may contact the supervisory authority in your country of residence.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page and notify you via email or in-app notification.

We encourage you to review this Privacy Policy periodically. Your continued use of Varshava AI after changes constitutes acceptance of the updated policy.