My Ai

Privacy Policy

Last updated: 19 September 2026

This Privacy Policy informs you about how we process personal data when you use our apps, the associated online services and our websites. It applies to all apps that Valery Mironov offers under the name “Klarfold”, currently Ai Notes Studio and My Ai.

Part A contains the information that applies to all offerings. Part B describes our websites, Part C the processing operations that take place in the same way in all apps, Part D the specifics of Ai Notes Studio and Part E the specifics of My Ai.

Part A – General information

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Valery Mironov Behringstraße 20 12437 Berlin Germany Email: [info@klarfold.com](mailto:info@klarfold.com) Phone: +49 30 45024505

2. Data protection officer

We are not obliged to appoint a data protection officer and have not appointed one. If you have any questions about data protection, please contact us directly using the contact details given above.

3. Legal bases

We only process personal data if there is a legal basis for doing so. For each processing operation, we state the relevant legal basis:

4. Recipients

We do not sell personal data and do not use it for third-party advertising. If you allow notifications, we may inform you in the apps about new features and offers (Sections 28 and 40). Only Valery Mironov, as the operator, has access to our systems. We use service providers that process data on our behalf (processors pursuant to Art. 28 GDPR) or that act under their own responsibility for certain purposes. We name the individual recipients in Parts B to E.

Beyond that, we only disclose data if we are legally obliged to do so, for example to authorities or courts, or if this is necessary for the establishment, exercise or defence of legal claims.

5. Transfers to third countries

Some service providers process data outside the European Union and the European Economic Area, in particular in the USA. We only transfer data to such a third country if

An appeal against the adequacy decision on the EU-US Data Privacy Framework is pending before the Court of Justice of the European Union (Case C-703/25 P). Should the decision be set aside, we will base transfers to the USA on Standard Contractual Clauses.

In countries without an adequate level of data protection, for example in the People’s Republic of China, authorities may under certain circumstances access data without effective legal remedies against this being available to you. We only transfer data to providers in such countries if you expressly select a model from that provider and have expressly consented after being informed of the risks (Art. 49(1)(a) GDPR). Neither of our apps selects such a model on its own. In My Ai this concerns models from DeepSeek as well as the image and video models Seedance and Kling (Section 37); in Ai Notes Studio it concerns only your own keys on the PRO API plan (Section 25).

6. Storage period

We only store personal data for as long as this is necessary for the respective purpose or statutory retention obligations exist. We state specific periods for the individual processing operations. Deleted data may still be contained in backups until the periods stated in Section 20 have expired; we use these copies exclusively for recovery after an incident.

7. Your rights

Subject to the statutory requirements, you have the right to

Right to object (Art. 21 GDPR): Insofar as we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You can exercise many rights directly in the apps, for example by editing or deleting content, withdrawing a consent or deleting your account. Otherwise, a message to [info@klarfold.com](mailto:info@klarfold.com) is sufficient. To protect your data, we may ask you to prove your identity, for example by sending a message from the email address of your account.

8. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information) Alt-Moabit 59–61 10555 Berlin Germany

9. Data security

We protect your data by means of technical and organisational measures. These include in particular encrypted transmission (TLS) between the apps, the websites and our servers, the operation of our servers in a data centre in Germany (Frankfurt am Main), access to the servers exclusively with cryptographic keys, access controls that restrict an account to its own content, encrypted storage of API keys, two-factor authentication for the administration interfaces and regular backups. AI-assisted tools that we use during development only receive source code, configurations and aggregated metrics; they are not permitted to access personal data from live operation. Details are described in Annex III of our data processing agreement.

10. Minors

Our apps are intended for persons aged 18 and over. We do not knowingly process data of minors. If we learn that a minor has created an account, we will delete the account.

11. No automated decision-making

We do not make any decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Answers, summaries and other content that AI models generate for you are not such decisions.

12. Obligation to provide data

You are under no statutory or contractual obligation to provide us with personal data. However, without an email address or a sign-in with Apple or Google, we cannot create an account, and without transmitting your content to AI providers we cannot provide the apps — it is their core (Section 21).

13. Changes to this Privacy Policy

We adapt this Privacy Policy when our processing operations or the legal situation change. You can find the current version in the apps and on our websites. We will inform you of material changes in the app.

Part B – Websites

14. Visiting our websites

Our website klarfold.com presents our apps and contains our legal texts. We operate our websites on our servers at Hostinger (Section 20). When you visit them, the web server processes technically necessary data: IP address, date and time, the address requested, the amount of data transferred, status code, the previously visited page and the information provided by your browser (User-Agent). The purpose is the delivery of the pages and the security of our systems, in particular defence against attacks. The legal basis is Art. 6(1)(f) GDPR. The logs are continuously overwritten as soon as they reach a defined size and are deleted after 14 days at the latest; we retain them for longer only in the event of a specific security incident.

Our websites do not use cookies or any analytics or advertising services. Fonts, scripts, images and videos are delivered from our own server; the websites do not load any content from third-party providers. Links to the App Store or to TestFlight only take you to Apple when you click them; Apple’s privacy policy then applies.

The klarfold.com website stores two entries in your browser and does not transmit them to us:

This storage is strictly necessary for the functions you have requested (Section 25(2) no. 2 TDDDG).

15. Contact

If you contact us by email or phone, we process your details, for example your name, email address, phone number and the content of your enquiry, in order to deal with your request. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is related to a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). We use an email provider as a processor for our email inbox. We delete enquiries as soon as they have been dealt with and no statutory retention obligations prevent this, and we review this at least once a year.

Part C – Common processing operations in our apps

16. App Store and TestFlight

You obtain our apps via the Apple App Store, which Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, operates under its own responsibility. For downloads and purchases, Apple processes data such as your Apple ID, payment data and device data; Apple’s privacy policy applies.

From Apple, we receive aggregated usage statistics as well as crash reports from persons who have agreed on their device to the sharing of analytics data with app developers. If you take part in tests via TestFlight, Apple additionally provides us with the device model, the operating system, the number of sessions and crashes, the feedback and the screenshots that you send and, if you were invited by email, your name and your email address; testers who join via a public link are shown to us without a name. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable apps) or, for TestFlight, Art. 6(1)(b) GDPR.

17. Purchases in the apps

We sell subscriptions and packages exclusively via the Apple App Store. Apple handles the payment; we do not receive credit card or bank details. After a purchase, a renewal, a refund or a cancellation, we receive signed transaction data from Apple, in particular transaction identifiers, product, purchase and expiry date, country of the store, price and currency, environment (test or production) and the identifier of your account in the respective app, which the app passes to Apple with every purchase. We use this data to unlock the services purchased, to restore purchases, to prevent abuse and to keep our books. The legal bases are Art. 6(1)(b) and (c) GDPR and Art. 6(1)(f) GDPR (defence against abuse and legal claims).

We can query the status of individual transactions from Apple via the App Store Server and receive notifications about changes. After your account has been deleted, we retain transaction and balance records without any link to your name or your email address for as long as this is necessary for obligations under tax and commercial law or for defence against legal claims, for a maximum of ten years.

18. Notifications

If you allow notifications, we store the device token assigned by Apple together with the app version, the environment and the time of the last update; in My Ai, we additionally store the language and the time zone of your device. We send notifications via the Apple Push Notification Service (Apple Inc., USA). The legal basis is your consent, which you give in the iOS notification dialog (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can turn notifications off completely at any time in the iOS Settings. The switch in Ai Notes Studio only hides notifications inside the app; the device token remains stored. In My Ai, the switch in the settings stops us from sending them. We delete the tokens when you sign out, delete your account or the token becomes invalid.

19. Support

If you write to us from an app, we process your message and the information you send along with it. The support email from Ai Notes Studio is prefilled with the email address of your account, an identifier derived from it, the version and build number of the app, the iOS version and the device model; you can remove this information before sending. We store support requests that you send in My Ai with the subject, the topic, your plan, the app version, the version of the operating system, the language set in the app and up to four attachments. The legal bases are Art. 6(1)(b) and (f) GDPR. The storage period is governed by Section 15 or, for My Ai, by Section 41.

20. Hosting, logs and data backup

Our servers are operated by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, as a processor in a data centre in Germany (Frankfurt am Main). The accounts, content and settings of both apps are stored there. Hostinger uses its own sub-processors; the Standard Contractual Clauses apply to transfers outside the EEA.

Our servers log technical events, including IP addresses, times, the interfaces called and error messages, in order to ensure operation and to detect disruptions and attacks (Art. 6(1)(f) GDPR). These logs are continuously overwritten as soon as they reach a defined size and are deleted after 14 days at the latest; this also applies to the operating system logs.

We create backups daily. For Ai Notes Studio, we keep them on the server for seven days. For My Ai, we keep the 14 most recent daily backups; in addition, a weekly backup of the entire database server, of which we keep the two most recent copies, may contain data from My Ai. Before changes to the database we additionally create a backup and delete it after seven days at the latest. We keep backups exclusively on the same server in Germany; we do not create copies outside this server. The legal basis is Art. 6(1)(f) GDPR (protection against data loss).

We send emails, for example confirmation codes, codes for resetting your password and invitations, via an outgoing mail server from Hostinger.

21. Principles of AI processing

Both apps use AI models from external providers. The following applies:

The following providers may – depending on the app and feature – receive content:

Sections 25 and 37 describe which providers the individual apps actually use.

Part D – Ai Notes Studio

22. Account

Ai Notes Studio uses its own account, which is separate from the accounts of our other apps. We store your email address, an irreversibly encrypted password (hash) if you sign in with email, the sign-in method (email, Apple or Google) with the identifier transmitted by Apple or Google, your name and an optional profile picture, as well as the times of registration, of the last sign-in and of the last use of the app.

When you sign in with Apple, Apple transmits to us an identifier and, if you wish, your name and your email address or a forwarding address generated by Apple. So that we can revoke your sign-in with Apple when your account is deleted, we store the token issued by Apple for this purpose in encrypted form. When you sign in with Google, the app connects directly to Google; Google Ireland Limited (Section 20) then transmits to us your Google identifier, your name, your email address, whether it has been verified and, if available, the address of your Google profile picture.

For each signed-in session, we store the IP address and the identifier of the app (User-Agent) and log sign-in events in order to protect your account against unauthorised access. On your device, we keep the sign-in encrypted in the keychain.

The legal bases are Art. 6(1)(b) GDPR, for the security logs Art. 6(1)(f) GDPR and for storage on your device Section 25(2) no. 2 TDDDG. We store account data until you delete your account. We delete logs of sign-in events after 90 days. We delete registrations whose email address is not confirmed after 30 days; we finally remove a deleted sign-in account 30 days after the deletion.

23. Notes, recordings and settings

We store the content you create in the app: notes with title, text, transcripts, AI results, translations and mind maps, photos in photo notes, folders, custom agents with their instructions, agents for the keyboard, your dictation dictionary, rules for automatic filing and your settings, for example language, appearance and notifications. We store audio recordings in protected storage on our server. So that the app also works without a connection, it additionally stores content on your device and synchronises it with our server.

Your content may contain information about other people, for example in meeting notes. In this regard, please note Sections 6.2 and 6.3 of the Terms of Use.

The legal basis is Art. 6(1)(b) GDPR. We store your content until you delete it or delete your account. We automatically remove audio recordings of deleted notes from our server after 30 days at the latest.

24. Speech recognition on the device

During a recording, the app displays a live transcription. For this, it uses Apple’s speech recognition and passes it the entries in your dictation dictionary as hints. If your device supports recognition of the selected language locally, the audio recording remains on the device; otherwise, Apple processes the speech data on its servers in accordance with its own terms. If our server does not transcribe a recording, the app converts the saved recording in the same way with Apple’s speech recognition. Text in photos is recognised by an AI provider via our server (Section 25). The legal basis is Art. 6(1)(b) GDPR; speech recognition requires that you allow it in iOS.

25. AI features in Ai Notes Studio

With your consent to AI processing (Section 21), we transmit the following content to AI providers for the respective feature:

For transcription, we use Groq, OpenAI or Google, and for text features and text recognition, OpenAI or Google; if a provider fails, the next one takes over. Models via OpenRouter and from NVIDIA may be added in future (Section 21). With OpenAI, we switch off the storage of requests in our account, and with Groq we use processing without data retention; the storage for abuse detection under Section 21 remains unaffected. Via OpenRouter, we only request providers that, according to OpenRouter, do not store inputs. This does not allow us to rule out use for training (Section 21). On the PRO API plan, we exclusively use the providers for which you store your own API keys: OpenAI, Anthropic, Google, Groq, OpenRouter, xAI or DeepSeek. In this case, the provider processes the content on the basis of your own contract with it; its terms determine how long it stores content and whether it uses it for training, for example with free-of-charge access. If you choose to use purchased PRO Minutes on the PRO API plan, we process the requests concerned with our providers as on the PRO plan. With OpenRouter, we only request providers that, according to OpenRouter, do not store inputs. We store your API keys in encrypted form on our server and use them exclusively for your requests.

We store the results with the respective note. For each AI request, we also store, without content, which task, which provider and which model was used, whether your own key or ours was used, whether the request was successful or a replacement provider stepped in, and the duration; we record consumption in your plan (Section 26).

Import via a YouTube link. If you import a video via its link, the app determines the video’s identifier on your device and sends only this to our server. Our server uses it to retrieve the subtitle track from YouTube (Google); we do not transmit any information about you in the process, and YouTube sees the IP address of our server, not yours. In the note, we store the title of the video as well as the link and the full subtitle text. This text is then processed like a transcript: the selected agent receives it and, if you use filing rules, so does automatic filing.

Connections for external AI clients. On the paid plans, you can set up a connection through which an external AI client – such as ChatGPT or Claude – accesses your notes. For this we generate an access token and store only an irreversible checksum of it, the name you assign and the times of creation and last use. A connected client can list and search your notes – in each case with the full text – and create new text notes; it cannot change or delete anything. What the client does with the retrieved content is governed by the terms of its provider; we are not responsible for this. You can revoke each connection individually in the app; all connections cease when your account is deleted. The legal basis is Art. 6(1)(b) GDPR.

26. Plans, quotas, usage data and administration

In order to implement plans, quotas and limits, we store your plan, the periods and levels of your quotas, entries for minutes and units, plans and gifts granted by us, and the information on AI requests stated in Section 25. To protect against overload, we count requests per account in short time windows and limit sign-in requests per IP address. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (protection against abuse and cost control). We delete counter values for time windows after two days and the remaining usage data together with your account; Section 17 applies to purchase data.

To look after the service, we see in an administration interface protected by two-factor authentication your email address, your name, the times of registration and of the last sign-in, your plan, quotas, consumption and purchases, the status of your consents, the status of processing operations including error messages, the providers of your own AI routes, invitations and crash reports; we do not see the content of your notes or your API keys there. Changes that we make there, for example gifts, credits, invitations or the deletion of an account, are logged with the time and the details. The legal basis is Art. 6(1)(f) GDPR (proper and secure operation). We retain the logs for three years.

27. Invitations and offers

We may invite people we know to Ai Notes Studio by email. We only give plans as gifts or offer discounts to people who already have an account with us. For this purpose, we store the email address, the name, the content of the offer (title, message, discount and period of validity), the status of the invitation and a prepared sign-in account; the invitation is also recorded in the administration log (Section 26). The invitation email loads images from our server; in doing so, your IP address is processed as described in Section 14. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in personally inviting people we know) and, after acceptance, Art. 6(1)(b) GDPR. We delete unaccepted invitations together with the prepared sign-in account and the offer after twelve months; we delete accepted invitations together with your account.

28. Notifications in Ai Notes Studio

The app can notify you when a note has finished processing or something changes in your plan. The notification about a finished note contains its title; it is transmitted via Apple (Section 18) and may be visible on the lock screen. Section 18 applies to device tokens; we automatically delete tokens that have not been updated for 180 days.

29. Crash and diagnostic reports

If you turn this on in the settings, the app transmits reports on crashes and hangs generated by iOS to our server. A report contains the app version and build number, the iOS version, the device model, the processor architecture, the type and code of the error, for exceptions their name, for hangs their duration, the reason for termination, the period in which the error occurred and the program flow at the time of the error, but no account identifier and no content of your notes. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time by turning it off; reports that have not yet been sent are then deleted. We delete reports after 90 days.

30. Keyboard extension

The optional keyboard extension inserts texts that you have prepared in the app. It does not itself establish a network connection; your input is neither stored nor transmitted. It only needs “full access” in order to read the prepared texts from the app.

31. Account deletion in Ai Notes Studio

You can delete your account in the app under “Account” → “Delete account”. We then delete your audio recordings, notes, folders, agents, settings, encrypted API keys, consents, quotas, usage data, device tokens, connections for external AI clients, invitations and offers, and revoke your sign-in with Apple if you have used it. Your sign-in account is irrevocably deactivated. We retain purchase records and entries for minutes and units in accordance with Section 17 without any link to your name or your email address. We delete logs of sign-in events (Section 22) and entries in the administration log (Section 26) after the periods stated there. A record of the deletion prevents old sign-ins from continuing to be used; we delete this record after twelve months. We keep the evidence of your consent to AI processing for three years without any link to your account (Section 21). The data disappears from backups once the periods in Section 20 have expired. A subscription with Apple does not end as a result of the deletion; please cancel it in the settings of your Apple Account.

Part E – My Ai

32. Account and profile

My Ai uses a sign-in service (Supabase Auth) that we operate ourselves on our server (Section 20) and also use for other services of our own. When you sign in, the app connects directly to this sign-in service. It stores your email address, an irreversibly encrypted password (hash) if you sign in with email, the sign-in method with the identifier and the name transmitted by Apple or Google, and the times of registration and of the last sign-in. Other services of ours keep their own accounts in the same sign-in database; an account in My Ai does not grant access to the other services, and the content of the apps is stored separately. We send confirmation and password codes by email (Section 20). Section 22 applies accordingly to Apple and Google.

In your profile, you can voluntarily provide your first name, last name, date of birth, gender and a profile picture and choose settings such as language, appearance, voice, haptic feedback, notifications and the Memory feature. We also store which versions of our legal texts you have acknowledged and when.

For each signed-in session, the sign-in service stores the IP address and the identifier of the app (User-Agent) and logs sign-in events. On your device, we keep the sign-in encrypted in the keychain.

The legal bases are Art. 6(1)(b) GDPR, for security logs Art. 6(1)(f) GDPR and for storage on your device Section 25(2) no. 2 TDDDG. We store account data until you delete your account; we delete logs of sign-in events after 90 days.

33. Chats, assistants and projects

We store your chats with titles and messages, including the model used and the consumption, custom assistants with name, description, instructions, image, emoji and suggested questions, and projects with their source files and the text extracted from them. Images and files that you attach to a message are only transmitted to the AI model for that message; we do not store them and only note that the message had an attachment. The app additionally stores chats, messages and drafts on your device, as well as files and documents that you have opened; this data is deleted when you sign out.

The legal basis is Art. 6(1)(b) GDPR. We store the content until you delete it or your account. We automatically delete temporary chats seven days after the last message.

34. Memory

On the PRO plan, My Ai can save information that you mention in chats to Memory so that later answers are better suited to you. The feature is switched off by default. For this purpose, an AI model regularly analyses the most recent messages of the chat, including the transcripts of voice conversations. The saved information cannot be displayed in the app. If you turn the feature off in the settings, we delete the saved information; deleting your history also deletes it. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by turning the feature on and withdraw by turning it off.

35. Files, documents, images and videos

If you upload files to a chat or a project, we extract the text in an isolated environment on our server without network access and add it to the request. Images and scanned PDFs that you add to a project are additionally transmitted to OpenAI, Anthropic or Google when they are uploaded, so that the text in them can be recognised. When documents are created or converted, we store the request and the result until you delete your account; we delete the source files and the working data of a job when it is finished, at the latest after 24 hours. For documents, our server can search for suitable free images via the search interface of Wikimedia Commons, retrieve routes and maps via the Google Maps Platform and use the web search (Section 37). We only transmit the search terms or addresses required for this, not your IP address; addresses that you specify appear in the finished document together with a link to Google Maps. Wikimedia Foundation, Inc., 1 Sansome Street, Suite 1895, San Francisco, CA 94104, USA, and Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, each process these requests as an independent controller. We store generated images and videos together with the request used; a photo that you upload as a template is not stored.

The legal basis is Art. 6(1)(b) GDPR and, for AI processing, Section 21. Generated images, videos and documents remain stored until you delete your account, including when you delete the chat in which they were created.

36. Voice features

In voice conversations, we transmit your speech to the AI provider in real time via our server. Together with the conversation, the model receives the instructions of the selected assistant and the most recent messages of the chat. If a provider is not available when the conversation starts, the app may use the other provider. We do not store the audio data; we store the transcripts as messages in the chat. A voice conversation that you start outside a chat creates a new chat, and its first sentence is used for the chat title. For each session, we store the model and the provider, including the providers tried, the start and the end, technical audio diagnostics of your device, such as sample rate, audio route and microphone level, and the identifier of the app (User-Agent); we delete this information after 90 days, at the latest together with your account. Dictation is converted by Apple’s speech recognition (Section 24 applies accordingly). For reading aloud, we transmit the text of the message to the AI provider and do not store the audio.

37. AI features in My Ai

With your consent to AI processing (Section 21), we transmit to the respective model the system text of the selected assistant, the text of the sources of a project, your new message with attachments and extracted file text, the last 20 messages of the chat, web search results and, if you have provided them in your profile, your first and last name, your age, calculated from your date of birth, and your gender. On the PRO plan with Memory turned on, the information saved to Memory, the names of your assistants and projects and the number of your chats, project files and creations are added. We do not transmit your email address or your account identifier.

Depending on the feature, we use:

If you expressly select a model from DeepSeek, processing takes place in the People’s Republic of China (Sections 5 and 21); we ask you for a separate consent beforehand. We do not use DeepSeek in the automatic features. Models via OpenRouter and from NVIDIA may be added in future (Section 21). Results to which providers apply moderation filters may be rejected; we do not carry out any moderation of your content ourselves, but we review reports and complaints and may restrict use (Section 6.4 of the Terms of Use). If your use is very high, the app can switch to lower-cost models in order to keep it within the fair use of your plan. For each AI request, we store, without content, the type, model, provider, consumption, costs and status.

38. Plans, credits and referrals

In order to implement plans, quotas and credits, we store your plan and your subscriptions, quotas and reserved consumption, entries for credits, welcome, streak and promotional credits, your referral code and referrals made through it, and records of redeemed offers. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (protection against abuse, in particular of credits granted). Section 17 applies to purchase data. After your account has been deleted, we retain usage and balance records without any link to your name or your email address for as long as this is necessary for defence against abuse and legal claims, for a maximum of ten years.

39. Usage analytics in My Ai

If you agree, the app records which steps are completed during setup and use, for example opening the plan overview or completing registration. For this purpose, it stores a random installation identifier on your device and transmits the event, step, plan, language and app version to our server; after you sign in, we link this information to your account. We use the analysis exclusively to improve the app and do not pass it on to third parties. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time in the settings. We delete the events after 90 days; if your account is deleted, we remove the link immediately. Independently of this consent, we analyse in aggregated form what is stored for operations anyway, such as the number of registrations, purchases and cancellations (Sections 37 and 38); no additional data about you is created in the process.

40. Notifications in My Ai

My Ai can notify you when an image or a video is ready, when we answer a support request, when your plan or your credits change, when a referral is credited and about news and offers in My Ai; for this purpose, we may select recipients according to plan, language and use of the app. If you open a template for images or videos without creating anything, we store the template, its type, the price shown and the time for seven days, for example in order to remind you of it. Section 18 applies to device tokens. We store which notifications have been sent to your device until you delete your account.

41. Support and reports in My Ai

We store requests and reports that you send in the app with your messages, attachments and the information stated in Section 19; for complaints, we also store a copy of the answer complained about. The legal bases are Art. 6(1)(b) and (f) GDPR. We delete them three years after the request has been closed; when you delete your account, we close open requests.

42. Administration

To look after the service, we see in an administration interface protected by two-factor authentication email addresses, first and last names, the language, plans, consumption, subscriptions, credit entries with our own notes, names of project files, support requests with their attachments, copies of the answers complained about, technical diagnostics of voice conversations and error lists with account identifiers; we do not see the content of your chats there. Changes that we make there are logged with the time and IP address. The legal basis is Art. 6(1)(f) GDPR (proper and secure operation). We retain the logs for three years.

43. Account deletion in My Ai

You can delete your account in the app under “Settings” → “Profile” → “Delete account”. We then delete your chats and messages, the information saved to Memory, projects with source files, custom assistants, generated images, videos and documents, voice sessions, device tokens and the record of the notifications sent, notes about templates you have opened and your profile information, terminate ongoing jobs with AI providers insofar as they allow this, delete or anonymise your sign-in data and revoke your sign-in with Apple if you have used it. We retain closed support requests in accordance with Section 41, and purchase, usage and balance records in accordance with Sections 17 and 38 without any link to your name or your email address. We retain records of the acknowledgement of the legal texts for three years; events of the usage analysis remain stored without a link to your account (Section 39). The data disappears from backups once the periods in Section 20 have expired. If you sign in again later with the same Apple or Google account, a new and empty account is created. A subscription with Apple does not end as a result of the deletion; please cancel it in the settings of your Apple Account.

v7 · 2026-09-19