Privacy Policy

In plain terms (summary). This box is a plain-language summary to help you understand the key points. It is not a substitute for the full policy below, which is what legally applies.

  • We're an EU company and we host and run the AI models on EU-based compute, so your prompts stay in the EEA.
  • We don't train models on your data, and we apply a zero-retention policy to your prompts.
  • We sign you in with Google — we get your name, email, and picture, never your password.
  • We don't sell your data or use advertising/tracking cookies.
  • You have full GDPR rights (access, deletion, portability, and more) — just contact us.
01

1. Privacy Overview

At SAMNIS Solutions s.r.o. (BACR), your privacy is extremely important to us. We are a European company serving European users, and we are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws. Transparency is central to how we operate, and we use your data only to provide the best possible service. Importantly, we earn revenue exclusively from subscriptions, not from selling or otherwise monetizing your data.

A key part of our privacy commitment is our infrastructure: BACR hosts and serves the AI models on EU-based compute, so your prompts stay in the EEA. See Section 4a for details.

02

2. Who We Are

The data controller for your personal data is SAMNIS Solutions s.r.o. (BACR), registered and based in Prague, Czechia. If you have any questions about this Privacy Policy or would like to exercise your rights, you can contact us.

03

3. What Data We Collect

We may collect and process the following categories of personal data to provide and improve our services:

  • Account & Authentication Data: We use Google OAuth (Sign in with Google) to authenticate you. When you sign in, Google shares a limited set of profile information with us — typically your name, email address, and profile picture — and a unique account identifier. This information originates from your Google account (the source of the data). We never receive or store your Google password. This data is used to create and secure your account and manage your subscription.
  • Prompt & Content Data: The prompts, messages, and inputs you submit to interact with the AI. These are handled under a strict Zero-Data-Retention approach (see Section 4a).
  • Security Data: Information related to usage and access logs, used to protect the integrity and security of the service.
  • Communication Data: Emails and support interactions to provide better customer service.
  • Payment Data: Billing and transaction information, processed on our behalf by third-party payment providers. We do not store full card details on our systems.
04

4. How and Why We Use Your Data

The purposes for which we collect and use your data include:

  • Providing the Services you request: To deliver AI-based functionality and support.
  • Improving our Services: For troubleshooting, technical improvements, and security monitoring.
  • Communication: Sending updates about your account, billing, and product changes (you can opt out of non-essential communications).
  • Compliance: Meeting legal, regulatory, and compliance obligations.

We process your personal data on the following legal bases:

  • Performance of a contract: To provide the services you’ve subscribed to.
  • Consent: When you explicitly agree (e.g., for customer service requests).
  • Legitimate interests: To prevent abuse, operate our services, and enhance security.
  • Legal compliance: To meet legal obligations, such as financial audits or fraud prevention.
05

4a. AI Models, Prompts & EU Hosting (Zero-Data-Retention)

Unlike many AI services that forward your prompts to third-party model providers, BACR hosts and serves the AI models itself on EU-based compute. This gives us direct control over how your data is handled:

  • Processed in the EEA: Your prompts and inputs are processed on compute located within the European Economic Area.
  • No external model providers: We do not transmit your prompts to external, non-EU AI model providers for inference.
  • Zero-Data-Retention: We apply a strict Zero-Data-Retention policy to prompt content. BACR does not retain your prompts after generating a response. Where limited monitoring logs are technically necessary for security and reliability, they are retained on a rolling basis for up to 1 year and then deleted.
  • No training on your data: We do not use your prompts, inputs, or content to train AI models.
06

4b. Automated Decision-Making & Profiling

BACR does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. While our service uses AI to generate responses to your prompts, these outputs do not constitute automated decisions about you, and we do not use your personal data for profiling to make such decisions.

05

5. Data Retention

We retain your personal data only for as long as it is necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, and contractual obligations. Below is a breakdown of our retention periods:

Prompt & Content Data

  • Purpose: Processed on our EU-based compute to generate AI responses.
  • Retention Period: Not retained after a response is generated, under our Zero-Data-Retention policy (see Section 4a). Limited security/monitoring logs, where technically necessary, are retained on a rolling basis for up to 1 year.

Account Data

  • Purpose: Required for managing your subscription and resolving disputes.
  • Retention Period:
    • Active Users: Stored for the duration of your registration.
    • After Account Termination: Retained for up to 1 year after the end of your subscription for evidentiary and legal compliance purposes, after which it is securely deleted.

Security Data

  • Purpose: Stored to monitor system integrity, detect fraud, and prevent unauthorized access.
  • Retention Period: Retained for up to 1 rolling year, then deleted automatically.

Payment Data

  • Purpose: Processed securely by third-party payment providers for billing and fraud prevention.
  • Retention Period: Follows the retention period required by financial and tax regulations, usually 5 to 7 years, depending on your country of residence.

Communication Data

  • Purpose: Manage customer support inquiries and improve service delivery.
  • Retention Period: Retained for up to 2 years from the date of your last interaction, unless deletion is requested earlier.

If required by law, we may retain certain data beyond the retention periods outlined above, but only to the extent necessary to comply with applicable laws (e.g., tax regulations or court orders).

06

6. Data Sharing

We may disclose your Personal Data to third parties when necessary to provide the services we offer. Any such disclosure is limited to what is needed for the purposes described above. BACR may share your Personal Data with the following categories of third parties:

  • Third-party Service Providers:
    To operate and deliver our services, we use trusted providers, including payment processors, and Cloud vendors. These providers are bound by contractual agreements to process your data only for the agreed purposes, in compliance with privacy laws.

  • Compliance with Laws:
    We may disclose your data if required to do so by law, a court order, or other legal processes.

We do not sell or share your data for advertising purposes.

07

7. Data Security

We have robust measures in place to protect data against unauthorized access, loss, destruction, or alteration. These include:

  • Encryption: Data in transit is encrypted. We use secure infrastructure, including PostgreSQL and Google Cloud Platform.
  • Regular Audits: We periodically review our systems and data-handling processes for vulnerabilities and ensure security updates are applied promptly.
08

8. International Data Transfers

As we are a European company serving European users, your personal data is processed and stored within the European Economic Area (EEA), including your prompts (see Section 4a).

A limited number of operational subprocessors (for example, payment processing) may involve transfers outside the EEA. Where such transfers are necessary, we ensure they are done under adequate safeguards, such as through Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the European Commission.

09

9. Your Rights

If you are located in the EEA, the UK, or another jurisdiction with comparable privacy protections, you may have the following rights under the GDPR and similar privacy regulations:

  • Right to Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You can request corrections or updates to your data if it’s inaccurate or incomplete.
  • Right to Erasure (Right to Be Forgotten): You can request deletion of your data, subject to specific retention requirements under the law.
  • Right to Restrict Processing: You can request that we limit the processing of your data in certain situations.
  • Right to Objection: You can object to the processing of your data where we rely on legitimate interests as a legal basis.
  • Right to Data Portability: You have the right to request your data in a portable format for reuse elsewhere.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.

You can exercise any of these rights by contacting us at the email address listed in Section 12. We will respond to your request without undue delay and, in any event, within one month of receipt, as required under Article 12(3) GDPR (this period may be extended by up to two further months for complex or numerous requests, in which case we will inform you). If you believe we have not adequately addressed your request, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

10

10. Cookies and Tracking

We use cookies to authenticate your sessions, including sessions established through Google OAuth (Sign in with Google).

  • Types of Cookies:
    • Essential Cookies: Necessary for the operation of our services (authentication, session management, language selection).

We do not use advertising or third-party tracking cookies.

11

11. Changes to Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or industry standards. Notice of significant changes will be provided by email or within the service itself. Please check this page periodically for updates.

Last Updated: 22-07-2026

12

12. Contact Us

For questions, concerns, or requests regarding this Privacy Policy — including to exercise any of your data protection rights — you can contact us at:

Email: contact [at] bacr [dot] app

Please indicate that your message concerns a privacy or data protection request so we can route it appropriately.

The BACR Team

We aim to deliver exceptional AI services while protecting your privacy at every step. Thank you for trusting us with your data.