Privacy policy
Effective · 12 July 2026
Your notes can be personal. This policy explains what Conspecto processes, why it is needed, and which services help us provide the app.
1. Controller and contact
The GDPR controller is Egor Mitin, Bastiengasse 4, 1180 Wien, Österreich. For privacy requests, email support@conspecto.org. We have not appointed a data protection officer because we do not currently consider one legally required.
2. Data we process
| Category | What it includes |
|---|---|
| Account | Name, email, password hash, account preferences, verification and reset records, login and session identifiers |
| Study content | Notes, folders, tags, files and source links, prompts, questions, answers, AI outputs, review results, and spaced-repetition schedules |
| Usage and security | Feature events, pseudonymous analytics ID, account ID when signed in, timestamps, page or product context, IP address, device/browser details, logs, and rate-limit or security events |
| Billing | Plan, subscription status, book balance and ledger, Stripe customer and checkout references, invoices, payment status, and limited transaction metadata. Conspecto does not receive or store full card numbers. |
| Messages | Support requests, feedback, and related correspondence |
Some billing status comes from Stripe webhooks, and hosting/security metadata may come from our infrastructure providers rather than directly from you.
3. Why we use it
- Provide the service — accounts, notes, AI generation, reviews, books, and subscriptions: performance of our contract or steps you request before contracting, Article 6(1)(b) GDPR.
- Keep Conspecto safe and reliable — authentication, logs, rate limits, fraud and abuse prevention, debugging: our legitimate interests in security and service reliability, Article 6(1)(f).
- Understand and improve the product — first-party usage analytics and aggregated product performance: our legitimate interest in improving Conspecto, Article 6(1)(f), subject to any consent required for browser storage.
- Process payments and keep records — our contract and legal accounting, tax, and fraud-prevention duties, Article 6(1)(b), (c), and where applicable (f).
- Answer you — contract support or our legitimate interest in responding to requests. Marketing email is sent only where we have a lawful basis, including consent where required.
4. AI and your note content
When you ask for an AI feature, we send only the content reasonably needed for that request — for example note text, selected files or images, prompts, questions, and answers — to the configured AI API provider. Our current providers include OpenAI and Google Gemini. They are service providers/processors for Conspecto; their own vendors may act as subprocessors.
Provider processing can include technical and abuse-monitoring metadata under the relevant API terms. We do not permit providers to use API content to train general models where our contracted settings prohibit that use. Provider and retention settings can change, so we review them before enabling a provider in production.
Please do not put unnecessary health, political, religious, biometric, or other sensitive information — or another person’s private information — into Conspecto. Using an AI feature does not make generated material automatically correct.
5. Services that receive data
| Recipient | Purpose |
|---|---|
| Hosting and infrastructure providers | Application hosting, databases, object storage, delivery, backups, and security |
| OpenAI and Google | AI processing only when the corresponding AI feature is used |
| Stripe | Checkout, payment processing, subscriptions, invoices, and fraud prevention. Stripe processes data for us in parts of this flow and may act independently where payment or regulatory law gives Stripe its own purposes. |
| PostHog | Product analytics, EU-hosted in Frankfurt. It receives the first-party usage events described above, but no note content. |
| Email and support providers | Account messages, receipts, service notices, and support correspondence |
We do not sell personal data. We may disclose it where law requires, to protect legal rights and security, or as part of a business transfer with appropriate safeguards.
6. International transfers
Some providers may process data outside the EU/EEA, including in the United States. Where required, we rely on an adequacy decision such as the EU–US Data Privacy Framework for an actively certified recipient, the European Commission’s Standard Contractual Clauses, and supplementary safeguards. You may ask us for information about the applicable transfer mechanism.
7. Retention
- Account and study content — while your account or content remains active, then until deletion completes from live systems and routine backups, unless a dispute or legal duty requires longer retention.
- Sessions and security records — for their configured lifetime and then as reasonably needed to investigate incidents or abuse.
- Usage analytics — retained in identifiable or pseudonymous form only as long as needed to evaluate product use, then deleted or aggregated.
- Billing and tax records — for the applicable statutory period, generally seven years for Austrian accounting records, and longer only where legally required.
- Support correspondence — while needed to resolve the request and establish or defend legal claims.
We use these criteria where an exact period depends on backup cycles, security needs, provider settings, or legal limitation periods.
8. Cookies and browser storage
Conspecto uses essential session storage to sign you in, protect the account, and remember requested interface preferences. We also currently store a random first-party analytics ID in local storage to understand visits and feature use; it is not an advertising ID, is not shared with ad networks, and analytics events are not sent when your browser’s Do Not Track signal is enabled. Where law requires consent for non-essential browser storage, that storage should be used only after consent.
9. Your choices and rights
Depending on the circumstances, you can ask for access, correction, deletion, restriction, or portability of your data; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. Email support@conspecto.org. We may need to verify your identity and normally respond within one month.
You may also complain to the Austrian Data Protection Authority at dsb.gv.at or to another competent EU/EEA supervisory authority.
10. Required data and automated decisions
Account and login data is needed to create an account; study content is needed only for the features you choose; relevant note content is needed when you request AI generation; and billing data is needed for a paid purchase. Without it, that part of the service cannot be provided. Conspecto does not make decisions about you that produce legal or similarly significant effects solely by automated means.
11. Security, age, and changes
We use proportionate safeguards such as encrypted transport, access controls, secure session handling, backups, and logging. No online service can promise perfect security. Conspecto is intended for people aged 16 or older and we do not knowingly provide accounts to children under 16.
We will update this policy when our data use changes and give appropriate notice of material changes. The current version is always linked from Conspecto. The contractual rules for the service are in our Terms.