LEGAL INFORMATION

Privacy Policy

This policy explains how MyBubble handles personal data. MyBubble is for people aged 18 and over and is private by default.

1. Who may use MyBubble

MyBubble is intended only for adults aged 18 or over. Accepting the current Terms declares that you meet the 18+ requirement. An optional age signal is stored only as a minimum status, method, version and time; we do not store a birth date, identity document, age band or full provider response. Absence of a shared signal does not by itself restrict ordinary features. A known minor or a state where Google requires verification remains restricted.

2. Data and purposes

We process only data needed for the service you request, account and security operations, legal compliance, and optional choices you enable.

  • Account data: email, internal user ID, authentication/session state, language and necessary security metadata.
  • Your Bubbles: notes, images, PDFs, private originals, filenames or storage paths, extracted text, meanings, corrections, tags, actions and reminders.
  • AI requests and results: request identity, requested feature, minimum relevant content, answer, sources, provenance, authorization linkage, usage and content-minimal diagnostics.
  • Optional Plus Web Enrichment: a minimized public entity or offer query, the last safely observed supported coarse system region for public market results, bounded public facts and source provenance. The original Bubble is not used as the web-search query.
  • Device market context: MyBubble automatically reads the supported coarse region from your device's operating-system settings and keeps the last valid value in your profile for localized public results. This setting is not your physical location. Missing or unsupported regions are not guessed from language and do not erase a previously valid value. Reading these local settings uses no GPS, precise location, IP-derived location or background physical-location tracking and adds no external vendor.
  • Notifications: installation ID, push token, schedule, delivery state and a generic preview without Bubble content on the lock screen.
  • Privacy operations: export, deletion, acknowledgement, authorization and withdrawal evidence.
  • Plan and payment data when Plus is activated: entitlement, provider customer/subscription references, payment status and necessary accounting records. MyBubble does not collect card details directly.
  • Optional product analytics only if you enable it; passive inferred profiling and long-term learning are off at launch.

3. Legal bases

We use data necessary to provide and secure the service and perform our contract (GDPR Article 6(1)(b)); comply with legal duties (Article 6(1)(c)); and pursue proportionate legitimate interests such as abuse prevention, reliability and legal claims (Article 6(1)(f)). Optional product analytics uses your separate consent (Article 6(1)(a)). We do not describe necessary processing or this Privacy acknowledgement as consent.

One separate explicit consent under Article 9(2)(a) covers one purpose: AI processing of sensitive personal information you intentionally provide about yourself for MyBubble's organisation and understanding features. It is opt-in, versioned and withdrawable at any time. It does not cover another person's sensitive data or Article 10 data.

4. Private save, other people and external AI

Information for a person whose data may have been supplied by another user (GDPR Article 14): the controller is Karel Vodrážka / MyBubble with the contacts in section 1, and the source is a MyBubble user. The data may include identifying or contact details and information in private notes, documents, images, reminders or derived fields. It is used for private storage, organisation, search, reminders and only within the supported scope for user-requested AI; it is not used to advertise to, market to or profile the third party.

Recipient categories, any processing outside the EEA and the safeguards used are in Providers; retention is in Retention; and deletion is in Export, deletion and backups. Known third-party sensitive data and Article 10 data are not sent to AI. Content is private and not shared publicly by default.

If you believe another user has uploaded your data, contact [email protected]. You may request access, correction, erasure or restriction, object where applicable, and complain to the Czech supervisory authority; details are in Your rights. We verify and handle the request proportionately without improperly revealing the user's identity or private content, and restrict, correct or delete data where required.

A real non-AI save path stores your note or original without sending it to an AI provider. AI runs only after your explicit request through a smart feature. Immediately before external provider I/O, the server rechecks your current session, current Terms eligibility, deletion and account restrictions, authoritative known-minor or mandatory-verification states, the AI disclosure and, for declared own special-category mode, the exact feature authorization. Absence of a shared age signal is not treated as a minor signal.

For Plus, OpenAI Web Search may run in the background after Deep processing only for a clearly public non-person entity. The query is limited to public entity or offer terms and the last safely observed supported coarse system region; it excludes the original Bubble, account identity, GPS, precise location and IP-derived location. Automatic Web Enrichment is disabled for Bubbles classified as your own special-category data.

Do not deliberately submit another person's special-category data or criminal-conviction/offence data to AI. MyBubble does not use an automatic sensitive-data classifier and cannot guarantee detection. Remove the material and contact [email protected] if this happens.

5. AI provenance, correction and withdrawal

AI-derived text is labelled in the interface and carries structured provenance in storage, APIs and exports where meaningful. AI can be wrong; verify consequential dates, amounts and facts against the original. You can correct generated fields without changing the private original.

Withdrawing the sensitive-AI consent stops future covered provider calls immediately and removes linked AI-derived state where no separate basis applies. Private originals and user-authored corrections remain. Minimal versioned accountability evidence may be retained where objectively needed. A withdrawn consent never reactivates automatically.

6. Providers and recipients

Supabase provides authentication, database, private file storage and server functions. OpenAI provides requested AI processing and the hosted Web Search capability used for bounded public Web Enrichment; no separate direct search vendor is added. Expo and Google Firebase Cloud Messaging deliver mobile notifications. Cloudflare provides the public web service. The recovery runner is off and not configured for public launch; future activation requires DPIA reassessment and every documented prerequisite. Stripe processes Plus checkout, subscription and payment records only after billing is activated.

We use providers only for the stated service purpose and require appropriate contractual, security and transfer safeguards. Some processing may occur outside the EEA. Where required, we rely on an adequacy decision or approved transfer safeguards such as Standard Contractual Clauses, together with supplementary measures. Provider-account evidence is checked before activation and periodically thereafter; we do not promise an unverified location, zero-retention setting, EU-only processing, or absence of provider-managed onward processing.

7. Retention

Primary Bubbles, originals, messages, actions and explicit settings remain until you delete them, delete the account, or a future clearly communicated product rule applies. Grounded request/answer cache: 24 hours. Web-context snapshots use a 24-hour freshness boundary and remain with the Bubble until deletion or applicable withdrawal; content-free Web fair-use/replay records are retained for 400 days. Grounded replay tombstones and terminal usage-reservation history: 400 days. Detailed AI usage/model telemetry: 90 days. Optional product analytics: 180 days. Failed/cancelled terminal processing and terminal reminder delivery history: 30 days after terminal state. Local capture recovery: at most an absolute 7 days and removed for that account on sign-out. Export artifact: about 86,100 seconds; signed download URL: 300 seconds; remote push TTL: 3,600 seconds.

Complete encrypted backup snapshots are retained for the documented recovery period. Deletion removes active MyBubble account content. Limited copies may remain temporarily in access-restricted provider logs or backups for the stated retention or legal period and are not used for ordinary service. Statutory accounting, tax, dispute, consent/acceptance and completed-deletion evidence is retained only for the applicable legal or accountability need, then deleted or anonymised.

8. Export, deletion and backups

You can request a portable authenticated export and delete a Bubble or your account. Account deletion removes database and private Storage content first and the Auth identity last. Limited records may remain only where a legal obligation or objective accountability need applies. An older recovery snapshot is not put into service until all applicable deletion directives have been reapplied and non-resurrection has been verified. If that evidence is unavailable, cutover does not occur.

9. Your rights

Subject to applicable conditions, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Use [email protected]. You may complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, https://uoou.gov.cz.

10. Security and incidents

We use owner-scoped database controls, private buckets, short-lived signed links, bounded workers, encryption and content-minimal production logs. No system is risk-free. Report a suspected vulnerability to [email protected] without sending credentials or unnecessary private content.

11. Changes

Material changes receive a new version and are presented before ordinary continued use when acceptance is required. Privacy acknowledgement is recorded separately and is not a substitute for a legal basis or optional consent.

Product-guidance emails and optional feedback

Product-guidance emails are on by default unless you previously made an explicit choice. They may follow your first useful result, first photo or PDF, the explicit activation or end of a Plus trial, or invite optional feedback. We send at most two such emails in seven days, at least 48 hours apart. These are not advertising newsletters.

Turn these emails off in Settings or through the unsubscribe link in each message without losing your account. An explicit opt-out is never changed automatically. Security, sign-in and necessary billing messages are a separate category.

These messages use your account email, language, preference, product milestone and minimal delivery record. They do not include Bubble content, filenames, amounts or diagnoses. We do not use tracking pixels. Product analytics still requires separate consent; unsubscribe and survey links cannot sign you in.

Optional survey answers are private account-linked data, not anonymous responses. Free text is not sent to analytics. Answers are included in account export and deletion. Preferences and product-milestone records remain until account deletion; expired limited-purpose links are removed under the retention rules.