SeenByAI — Privacy Policy

Version 1.0 · effective 24 August 2026 · ← seenbyai.uk

1. Controller and contact

The controller of your personal data is Rafał Kawecki, a natural person carrying on unregistered business activity (działalność nierejestrowana) under Polish law, operating the SeenByAI service. Contact on any data protection matter: [email protected]. No data protection officer has been appointed — the law does not require one here; write to the address above.

2. What we process, why, and on what basis

References are to the GDPR (Regulation (EU) 2016/679).

We do not sell data, we do not profile for marketing purposes, and we do not send unsolicited mail. There is no automated decision-making producing legal effects for you.

3. Who we share data with

4. Where data is stored and transfers outside the EEA

The application server and the production database run in the EU (Oracle Cloud, Frankfurt, Germany). Database backups are transferred daily over an encrypted connection to a private server in Poland, where they are kept for 7 days. Transfers to the providers based in the United States listed above take place on the basis of Standard Contractual Clauses or of the EU–US Data Privacy Framework, as applied by each of those providers.

5. How long we keep data

6. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Two of these are immediate and self-service in the product: data export (JSON) and permanent account deletion — panel, account section. Deletion removes your brands, results, history, subscriptions and free-check records, and is confirmed by email. For anything else, write to [email protected]. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).

7. Cookies and local storage

We use one strictly necessary cookie: the sign-in session cookie (geo_session, HttpOnly, SameSite=Lax, sent over HTTPS only). Cloudflare Turnstile, which protects the forms against bots, may set its own technical identifiers. The site also stores your theme and language preference in your browser's local storage — this never leaves your device and is not used to identify you. There are no analytics or marketing cookies and no third-party trackers, which is why the site shows no consent banner.

8. Security

Sign-in is passwordless: there is no password to leak. Sessions live server-side and are revocable, traffic runs over HTTPS through Cloudflare, and access to the production server is restricted to the controller. No service can promise absolute security, but if a breach ever affects your rights we will notify you and the supervisory authority as the GDPR requires.

9. Changes to this policy

Version 1.0 of 24 August 2026. © 2026 SeenByAI · Terms of Service