AIMIKAby deFIN
Draft for review. Have this checked by a lawyer (GDPR/CCPA) and complete the bracketed details before launch.

Privacy Policy

Last updated: July 27, 2026

1. Controller

The data controller is [legal entity name], [address]. For privacy questions or to exercise your rights, contact [contact email].

2. Data we collect

  • Account data: email, name, password hash, and profile preferences.
  • Usage data: prompts and inputs you submit, generated outputs, and generation history.
  • Billing data: handled by our payment processor (Stripe); we receive limited subscription/transaction info, not full card details.
  • Technical data: IP address, device/browser info, cookies needed for sessions.

3. How we use it

To provide and improve the Service, generate AI outputs, manage your account and subscription, secure the Service and prevent abuse, comply with legal obligations, and (with your consent where required) send service communications.

4. Legal bases (GDPR)

Performance of our contract with you, our legitimate interests (security, improvement), your consent (where applicable), and compliance with legal obligations.

5. Sharing and sub-processors

We share data with service providers acting on our behalf: AI providers (to generate outputs), hosting (Vercel), database/storage (Supabase, Cloudflare R2), email (Resend), and payments (Stripe). They process data under contract. We do not sell your personal data.

6. International transfers

Your data may be processed in countries outside your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Retention

We keep personal data for as long as your account is active and as needed for the purposes above or to meet legal obligations. You can delete your account, after which we delete or anonymize data within a reasonable period.

8. Workspace: data about your clients

Workspace lets you store details about the people you work for - names, companies, contacts, notes, jobs and payments. That information is about other people, so it is treated differently from the rest of your account:

  • For this data you are the controller and we act as a processor on your instructions. You decide what to store and why.
  • We never use it to train or improve AI models, and we never send it to our AI provider on our own. Our in-product assistant sees counts only - how many clients, how many jobs, how much is outstanding - never names, job titles, notes or contacts.
  • The one exception is when you ask for it. If you press "Write a message" on a client or "Case" on a job, we send that record - the name, the jobs and the notes you wrote - to our AI provider so it can draft the text you asked for. The screen tells you exactly what will be sent before you press it, and contact details are never included. Do not use that button if you would rather those details stayed with us.
  • "Let AI write it about me" is not that exception. It sends only your own details - your profession, the services you list and the titles of your cases - and nothing about your clients.
  • The CV builder is the same: when you ask the AI to write your CV, we send the answers you typed about your own work and the titles of your cases - never your clients' names, notes or contacts. Your answers are stored with your account so you do not have to repeat them. If you paste a job ad to tailor your CV to it, that text goes to our AI provider too, together with the CV you saved.
  • Your public page is the one part of Workspace that anyone can open without signing in, and only after you switch it on. It shows what you typed there: your description, your services, your cases, your gallery and your testimonials. Your clients, jobs, payments and notes are never on it.
  • A testimonial publishes someone else's name, role, photo and link. Ask them first - we cannot check that you did, and on that page you are the one publishing. Deleting the testimonial removes it and its photo from us.
  • Nobody else using AIMIKA can see it. It is deleted together with your account, and you can export all of it at any time from Workspace.
  • You are responsible for having a lawful basis to store your clients' details and for answering their requests about that data. We will help you with export and deletion.

9. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. EU/UK users may complain to a supervisory authority; California users have rights under the CCPA/CPRA. To exercise rights, contact [contact email].

10. Cookies

We use cookies strictly necessary for sign-in/sessions. [If you add analytics or marketing cookies, describe them and add a consent banner.]

11. Changes

We may update this policy; material changes will be notified. The "last updated" date above shows the latest revision.

Join free - get 100 tokens