Legal document

Privacy Policy

AnotherDashboard (anotherdashboard.com) · Last updated: September 3, 2026 · Version 2026-09-03
This English version is provided as a courtesy translation for the convenience of international users. In case of any discrepancy between this document and the Polish original (Polityka Prywatności), the Polish version prevails, as the Service is operated under Polish law and GDPR is directly applicable EU law.

1. Data controller

1.1. The controller of personal data processed in connection with the use of the AnotherDashboard service is the owner of the AnotherDashboard service.

1.2. Contact for data-protection matters: support@anotherdashboard.com.

1.3. This Policy is based on Regulation (EU) 2016/679 (GDPR) and applicable Polish data-protection law.

2. What data we collect

CategoryExamples
Account dataemail address, password (stored only as a bcrypt hash), name (optional), email verification status
Technical data and logsIP address on login and on every visit to the Service, timestamps, login events — for security and abuse-prevention purposes
User-generated contenttasks, notes, activities, birthdays of third parties entered by the User, "About me" free-text field
Habit-tracking datahabits and their completion history, counters, addiction/streak trackers (name, start date, daily cost), mood entries (1–6 scale)
Financial data entered by the Userexpenses (amount, category, description, date), savings "vault" balance and transaction history, hashed PIN protecting the vault
Health/fitness-adjacent data entered by the Userweight measurements, weight goals, workout log (routines, sessions, exercises)
Physical-activity data (pedometer)daily step count read from the phone's motion sensor — only in the Android mobile app, and only after you start the pedometer and grant access to the activity sensor; manual corrections of a given day, the daily goal and its history, and pedometer achievement badges (identifier and unlock date). The data is synced to your Account; a local copy is kept on your device (details in §9.4)
Voice data (speech input)utterances captured by the microphone when you use speech input in the AI Assistant chat. We do not store or receive the recordings — speech-to-text happens on the platform provider's side (details in §4.3); only the resulting text reaches the Assistant, where it is treated like any ordinary message (§4.2, §5)
Billing dataPRO Plan purchase history (plan, amount, currency, status, Paddle transaction identifiers) — no card data ever reaches our servers (see §4)
AI Assistant conversation contentmessages sent to the assistant plus a contextual excerpt of Account data necessary to answer (see §4.2)
Preferencesvisual theme, interface language, location (city/coordinates) for weather display

2.2. We do not intentionally collect special categories of personal data under Art. 9 GDPR. Please note, however, that data you enter voluntarily in the Addictions/Trackers and Mood modules, the workout log, and weight measurements may be health-adjacent in nature; it is processed solely on your own initiative and with your knowledge, to deliver the relevant feature, on the basis of the contract (Art. 6(1)(b) GDPR). Physical-activity data (steps) is purely informational and motivational — it is not used to assess your health, for medical purposes, or for any other purpose (including marketing).

3. Purposes and legal bases

PurposeLegal basis
Account creation and provision of Service featuresArt. 6(1)(b) GDPR — necessary for performance of a contract
Processing PRO Plan paymentsArt. 6(1)(b) GDPR — performance of the sales contract (see also §4 on Paddle's role as Merchant of Record)
Transactional emails (verification, password reset, purchase confirmation)Art. 6(1)(b) and (c) GDPR — contract performance and legal obligations
Security logs (login/visit IP addresses)Art. 6(1)(f) GDPR — legitimate interest (security, abuse prevention)
AI Assistant featureArt. 6(1)(b) GDPR — delivering a feature explicitly invoked by the User
Pedometer feature (step counting, daily goals, badges) and syncing activity data to the AccountArt. 6(1)(b) GDPR — delivering a feature activated and used by the User; access to the device's activity sensor requires a separate Android system permission, which the User grants voluntarily and may revoke at any time in the device settings
Task reminders and notifications (local, and — in a browser — push)Art. 6(1)(b) GDPR — delivering a feature at the User's request (details in §4.4)
Speech input in the AI Assistant chatArt. 6(1)(b) GDPR — a feature invoked voluntarily by the User; the recording is processed by the platform provider, not by the Controller (see §4.3)
Handling complaints and correspondenceArt. 6(1)(b) and (f) GDPR
Tax/accounting obligationsArt. 6(1)(c) GDPR — legal obligation
Direct marketing of our own services (if conducted)Art. 6(1)(f) GDPR or consent (Art. 6(1)(a)), depending on the channel

4. Recipients and processors

4.1. We do not sell personal data. Data may be shared with, or processed by, the following categories of recipients, strictly to the extent necessary for their function:

4.2. About the AI Assistant specifically: the prompt sent to DeepSeek includes a concise excerpt of your Account data (e.g. today's/tomorrow's tasks, habit/counter/tracker names, birthdays) — only what's needed to power the "assistant can see your data" feature. Historical data (past expenses, notes, older entries) is only sent on your explicit request during the conversation. Savings-vault data is only sent after you verify your PIN. Using the AI Assistant is optional — if you'd rather your data not be processed by DeepSeek, simply don't use that feature.

4.3. Speech input. Speech-to-text in the AI Assistant chat (microphone) happens on the platform provider's side, directly on your device: in the Android mobile app this is Google's speech recognition service, in a browser — the Web Speech API (provider depending on the browser). The Controller neither receives nor stores voice recordings. Only the resulting text reaches the Assistant, where it is then subject to the rules in §4.2 and §5.

4.4. Activity data, notifications, and reminders. Activity data (steps, goals, badges) is not shared with any third parties — it is stored in the Service and linked to your Account. Task reminders in the mobile app are scheduled solely on your device and are not sent to the Controller. The one exception is the end-of-rest alarm in a browser, which may be delivered via a push notification: the subscription and the content/timing of such a notification reach the Service's server only for delivery purposes and are held solely in working memory until delivery or cancellation (they are never written to the database).

5. International data transfers

5.1. The AI Assistant provider (DeepSeek) processes data outside the European Economic Area, in a country not covered by a European Commission adequacy decision under Art. 45 GDPR.

5.2. This transfer relies on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses) and is limited to message content and the minimal context described in §4.2.

5.3. You may request a copy of the safeguards applied by contacting us at the address in §1.2.

6. Data retention

6.1. Account data and User-generated content are retained for as long as the Account exists, i.e. until deleted by the User or at their request.

6.2. Billing records (purchase history) are retained for the period required by tax law (generally 5 years from the end of the year in which the tax became due).

6.3. Security logs (IP addresses, login events) are retained for no longer than 12 months, unless needed to investigate an ongoing security incident.

6.4. After an Account is deleted, data is removed from the production database without undue delay; backups containing the deleted data are overwritten in the normal backup-rotation cycle.

6.5. Physical-activity data (steps, goals, badges) is retained for as long as the Account exists and is deleted together with it (§7.1).

7. Your rights

7.1. In connection with the processing of your personal data, you have the right to:

7.2. To exercise these rights, please contact us at the address in §1.2. We respond without undue delay, and in any event within one month of receiving your request.

8. Data security

8.1. User passwords are stored only as bcrypt hashes — the Controller never has access to passwords in plain text.

8.2. Account access is secured by a session token (JWT), stored locally in the User's browser and sent via a request header — the Service does not use cookies for this purpose.

8.3. The PIN protecting the "Savings vault" module is stored only as a hash.

8.4. Access to the admin panel (statistics, billing data, user list) is restricted to a small, designated group of individuals authorized by the Controller.

8.5. We recommend using a unique, strong password for your Account and never sharing it with third parties.

9. Cookies and localStorage

9.1. The Service does not use cookies for login or tracking purposes.

9.2. The Service uses the browser's localStorage mechanism (data stored locally on your device) to: store the session token (authentication), remember preferences (theme, language), and cache weather data. This data is not sent to third parties except as part of the normal operation of the relevant feature (e.g. the token is sent to our own server in a request header).

9.3. Because the Service does not use cookies for analytics or marketing, no cookie-consent banner is shown — this mechanism does not apply here.

9.4. Mobile app — data stored on your device. The Android app keeps locally on your device: scheduled task reminders (content and time), a local copy of your steps and daily goal (used for background step counting), and any data saved without signing in (guest mode). This data is not sent to the Controller (apart from the copies synced to your Account, described in §2) and is removed when you uninstall the app or clear its data.

10. Children's data

10.1. The Service is not directed at individuals under the age of 16. In line with Art. 8 GDPR and its Polish implementation, individuals under this age should not create an Account without parental or guardian consent.

10.2. If we become aware that we have processed the data of a child under 16 without the required consent, please contact us — such data will be deleted promptly.

11. Automated decision-making

11.1. The Controller does not make decisions about Users based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them (Art. 22 GDPR). AI Assistant responses (§4.2) are supportive in nature and do not constitute automated decision-making in this sense.

12. Changes to this Policy

12.1. This Policy may be updated, in particular in connection with changes to the Service's features, changes to third-party providers, or changes in law. Users will be notified of material changes electronically or via an in-app notice.

12.2. The current version of this Policy is always available at this address, together with the "last updated" date shown in the document header.