1. Controller and document status
The controller will be [FULL LEGAL NAME], [LEGAL FORM], [ADDRESS], registration/tax number [COMPLETE]. Privacy contact: [COMPLETE]. These details must be completed before testing with people outside the authorised team.
The controller/processor roles of MamHumor, MamPomoc and Specialists are being formally determined and will be described transparently before public launch.
This interim notice for closed testing does not replace the duty to identify the controller.
2. Key distinctions
- Peer calls: the Platform does not create audio/video recordings or transcripts in the current MVP.
- AI Avatar: message text is sent to Anthropic and, in defined fallback/RAG flows, Google Gemini.
- Pseudonymity: a peer need not know your identity, but infrastructure uses UUIDs, tokens, IP addresses and technical metadata.
- Mood choices and wellbeing statements may reveal health data and require enhanced safeguards.
3. Data categories
- Account and device: Supabase UUID/session, optional nickname, dates, language, domain, platform, bans, IP and request logs held by infrastructure providers.
- Matching and mood: mood/emotion, conversation role, language, country, waiting time, session context, reports and blocks.
- Peer sessions: room/socket identifiers, participants, call type and setup events; live audio, video and chat transmitted to the other peer.
- AI: current message/history, persona, locale, generated reply, session counter and crisis event without conversation text in the current database schema.
- Specialist: login email, professional display name, optional contact, topics, MamPomoc URL, onboarding and availability heartbeat.
- Exercises: local challenge state/history and room/card/reaction state for paired games and challenges.
- Safety and telemetry: report category/free text, enforcement, device hash, network/call timings, ICE, RTT, bitrate, loss, errors and end reason.
4. Peer calls and AI processing
Peer media uses WebRTC P2P or encrypted TURN relay. Direct P2P may reveal a public IP to the peer device. The Platform does not record media, use face recognition, create voiceprints or archive peer chat in its database. External recording remains technically possible and is prohibited by Platform rules.
Avatar requests are processed through Supabase Edge Functions and sent primarily to Anthropic. Google Gemini may generate a fallback reply and create an embedding for RAG. MamHumor/HappyGo does not store Avatar conversation text in its own MVP database, but providers apply their contractual retention and safety logging.
Anthropic states a standard 30-day API deletion period with safety, legal and contractual exceptions. Google's treatment depends on service tier, billing and ZDR configuration. Production settings must be confirmed before public launch.
5. Purposes and legal bases
- Contract, Article 6(1)(b) GDPR: requested account, matching, transmission and product functions in the necessary scope.
- Legitimate interests after a balancing test, Article 6(1)(f): safety, abuse prevention and minimal reliability telemetry.
- Legal obligation, Article 6(1)(c), where a specific law applies.
- Consent, Article 6(1)(a), for genuinely optional purposes; health data also requires an Article 9 exception, likely explicit consent under Article 9(2)(a) subject to legal approval.
- Legal claims, Article 6(1)(f) and, where relevant, Article 9(2)(f).
Accepting the Terms is not blanket consent. The code contains a consent draft, but fully versioned explicit health-data consent and easy withdrawal are not yet wired. Public health-data testing must wait for that fix.
6. Recipients and international transfers
Necessary data may be handled by Supabase, Vercel, Fly.io, Cloudflare, Anthropic, Google, Slack/Salesforce if safety alerts are active, MamPomoc, relevant Specialists, advisers and authorities where required by law.
Some providers or subprocessors may operate outside the EEA. DPAs, regions, subprocessors and the applicable transfer mechanism such as adequacy, EU-US DPF or SCCs must be confirmed. We do not currently claim that all data remains in the EU.
7. Retention
Queue and availability data are short-lived; peer content is not archived by the Platform; Avatar content follows provider retention; local exercise state remains until expiry or device-site data is cleared.
Mood history and raw telemetry are intended to have a maximum 30-day retention. Automated deletion has not yet been verified in the repository, so this is not yet a production guarantee. Closed-test data is deleted manually or on request until TTL jobs are live. Safety, enforcement and Specialist retention still require formal approval.
Public tests that persist mood data must not start before retention is automated and monitored.
8. Device storage and automated decisions
Local storage may hold terms acceptance, media preferences, temporary emotional context, challenge state and a technical call index. Strictly necessary storage may rely on the requested-service exception; analytics, marketing or non-essential storage requires a separate assessment and, where required, prior consent. The MVP should not run marketing trackers.
Matching may use language, role, waiting time, mood compatibility, reports and blocks. Safety systems may automatically restrict queue access. Article 22 GDPR and DSA scope will be assessed; significant restrictions should support a reason, challenge and human review. Health data is not used for advertising or commercial targeting.
9. Rights, security and age
Depending on the legal basis, you may request access, a copy, correction, deletion, restriction or portability, object, and withdraw consent without affecting earlier processing. You may complain to the Polish data-protection authority or your competent supervisory authority. Contact: [PRIVACY EMAIL]. An anonymous account may require the identifier held on your device.
We use encrypted transmission, pseudonymous identifiers, row-level security, access controls and minimisation. A self-service privacy centre for withdrawal, export and deletion is a P0 requirement before public launch.
The Platform is for adults aged 18+. Because the product combines wellbeing data, vulnerable users, AI and moderation, a DPIA screening and, if high risk is confirmed, a full DPIA will be completed before scaling.
10. Changes
Each policy version has a number and date. Material changes to purposes, legal bases, AI providers, retention or data categories will be communicated before new processing begins. A new consent will be requested where required; silence is not consent.