This Privacy Policy describes how odnoga ("we"), as data controller for marketing and account data and as data processor for Customer Data, handles personal data when you visit odnoga.com or use the odnoga platform.
1. Controller and contact
Controller: odnoga, Poland. Privacy contact: privacy@odnoga.com.
2. Our data pledges
- We never sell personal data. Period.
- We never use Customer Data, prompts or completions to train any model — ours or vendors'. Where vendors offer a zero-retention / no-training mode (OpenAI, Anthropic, Google), we enable it by default.
- Your data stays in the EU (Supabase EU region) unless you explicitly route requests to a non-EU model provider.
- Full GDPR compliance: lawful bases declared, DPA available, sub-processor list published, SCCs for any transfer outside the EEA.
3. What we collect
Account data
- Name, email, workspace, role.
- Authentication metadata (hashed password, 2FA factors, login timestamps, IP).
Phone number (signup anti-abuse only)
- Collected once during signup to verify you are a real person and prevent one user from creating many accounts. We will never call or text you for marketing.
- After SMS verification we discard the raw number and keep only a salted SHA-256 hash. It is never shared with any third party and is deleted when you delete your account.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — fraud prevention and one-account-per-person enforcement.
Usage data
- API request metadata: model, tokens, cost, latency, prompt slug / version, end-user identifier you send.
- Raw prompts and completions only if you explicitly enable raw capture.
Billing data
- Company name, VAT ID, billing address — processed by Stripe as our payment processor.
Website data
- Strictly necessary cookies for session and security.
- With consent: analytics and marketing cookies. See Cookie Policy.
3. Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b)): operating the Service, billing, support.
- Legitimate interest (Art. 6(1)(f)): security, abuse prevention, product analytics, direct marketing to existing customers.
- Consent (Art. 6(1)(a)): non-essential cookies, marketing emails to prospects.
- Legal obligation (Art. 6(1)(c)): tax records, AML, lawful disclosure requests.
4. Who we share it with
We use a small set of carefully selected sub-processors: hosting (Supabase / AWS), email (Resend), payments (Stripe), error monitoring, AI providers you route to. The full list lives on the Sub-processors page.
5. International transfers
Some sub-processors are located outside the EEA. Transfers rely on the EU Standard Contractual Clauses (2021/914) and additional safeguards where required.
6. Retention
- Account data: while your account is active, then 30 days.
- Usage and billing metadata: configurable per workspace, default 90 days for request logs; 5 years for invoices (tax law).
- Raw prompts/completions (if enabled): default 24 hours, configurable per workspace.
- Security logs: 12 months.
7. Your rights (GDPR)
- Access, rectification, erasure, restriction, portability, objection.
- Withdraw consent at any time (does not affect prior processing).
- Lodge a complaint with your supervisory authority (in Poland: UODO).
- Workspace admins can export or erase workspace data from Security & data in the app.
- Organisation admins can export all workspace data from Tenant admin for full portability.
To exercise your rights, use the in-app controls or email privacy@odnoga.com. We respond within 30 days.
8. Security
TLS in transit, AES-256 at rest, least-privilege RLS in our database, hardware-backed 2FA support, secret rotation, vendor key vault. We never use Customer Data to train models.
9. Children
odnoga is not directed to children under 16.
10. Changes
We will notify you of material changes at least 30 days in advance.