Legal document

Privacy Policy

AnotherDashboard (anotherdashboard.com) · Last updated: August 6, 2026 · Version 2026-08-06
This English version is provided as a courtesy translation for the convenience of international users. In case of any discrepancy between this document and the Polish original (Polityka Prywatności), the Polish version prevails, as the Service is operated under Polish law and GDPR is directly applicable EU law.

1. Data controller

1.1. The controller of personal data processed in connection with the use of the AnotherDashboard service (the "Service") is:

[TO BE COMPLETED] — full legal name of the Controller, registered address or address for service, and business registration number, where applicable. This is a mandatory disclosure under Art. 13(1)(a) GDPR and cannot be filled in automatically.

1.2. Contact for data-protection matters: support@anotherdashboard.com.

1.3. This Policy is based on Regulation (EU) 2016/679 (GDPR) and applicable Polish data-protection law.

2. What data we collect

CategoryExamples
Account dataemail address, password (stored only as a bcrypt hash), name (optional), email verification status
Technical data and logsIP address on login and on every visit to the Service, timestamps, login events — for security and abuse-prevention purposes
User-generated contenttasks, notes, activities, birthdays of third parties entered by the User, "About me" free-text field
Habit-tracking datahabits and their completion history, counters, addiction/streak trackers (name, start date, daily cost), mood entries (1–6 scale)
Financial data entered by the Userexpenses (amount, category, description, date), savings "vault" balance and transaction history, hashed PIN protecting the vault
Health/fitness-adjacent data entered by the Userweight measurements, weight goals, workout log (routines, sessions, exercises)
Billing dataPRO Plan purchase history (plan, amount, currency, status, Paddle transaction identifiers) — no card data ever reaches our servers (see §4)
AI Assistant conversation contentmessages sent to the assistant plus a contextual excerpt of Account data necessary to answer (see §4.2)
Preferencesvisual theme, interface language, location (city/coordinates) for weather display

2.2. We do not intentionally collect special categories of personal data under Art. 9 GDPR — however, note that data entered voluntarily in the "Addictions/Trackers" and "Mood" modules may be health-adjacent in nature. This data is entered solely on the User's own initiative and with their knowledge, to deliver the relevant feature, on the basis of the contract (Art. 6(1)(b) GDPR).

3. Purposes and legal bases

PurposeLegal basis
Account creation and provision of Service featuresArt. 6(1)(b) GDPR — necessary for performance of a contract
Processing PRO Plan paymentsArt. 6(1)(b) GDPR — performance of the sales contract (see also §4 on Paddle's role as Merchant of Record)
Transactional emails (verification, password reset, purchase confirmation)Art. 6(1)(b) and (c) GDPR — contract performance and legal obligations
Security logs (login/visit IP addresses)Art. 6(1)(f) GDPR — legitimate interest (security, abuse prevention)
AI Assistant featureArt. 6(1)(b) GDPR — delivering a feature explicitly invoked by the User
Handling complaints and correspondenceArt. 6(1)(b) and (f) GDPR
Tax/accounting obligationsArt. 6(1)(c) GDPR — legal obligation
Direct marketing of our own services (if conducted)Art. 6(1)(f) GDPR or consent (Art. 6(1)(a)), depending on the channel

4. Recipients and processors

4.1. We do not sell personal data. Data may be shared with, or processed by, the following categories of recipients, strictly to the extent necessary for their function:

4.2. About the AI Assistant specifically: the prompt sent to DeepSeek includes a concise excerpt of your Account data (e.g. today's/tomorrow's tasks, habit/counter/tracker names, birthdays) — only what's needed to power the "assistant can see your data" feature. Historical data (past expenses, notes, older entries) is only sent on your explicit request during the conversation. Savings-vault data is only sent after you verify your PIN. Using the AI Assistant is optional — if you'd rather your data not be processed by DeepSeek, simply don't use that feature.

5. International data transfers

5.1. The AI Assistant provider (DeepSeek) processes data outside the European Economic Area, in a country not covered by a European Commission adequacy decision under Art. 45 GDPR.

5.2. This transfer relies on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses) and is limited to message content and the minimal context described in §4.2.

5.3. You may request a copy of the safeguards applied by contacting us at the address in §1.2.

6. Data retention

6.1. Account data and User-generated content are retained for as long as the Account exists, i.e. until deleted by the User or at their request.

6.2. Billing records (purchase history) are retained for the period required by tax law (generally 5 years from the end of the year in which the tax became due).

6.3. Security logs (IP addresses, login events) are retained for no longer than 12 months, unless needed to investigate an ongoing security incident.

6.4. After an Account is deleted, data is removed from the production database without undue delay; backups containing the deleted data are overwritten in the normal backup-rotation cycle.

7. Your rights

7.1. In connection with the processing of your personal data, you have the right to:

7.2. To exercise these rights, please contact us at the address in §1.2. We respond without undue delay, and in any event within one month of receiving your request.

8. Data security

8.1. User passwords are stored only as bcrypt hashes — the Controller never has access to passwords in plain text.

8.2. Account access is secured by a session token (JWT), stored locally in the User's browser and sent via a request header — the Service does not use cookies for this purpose.

8.3. The PIN protecting the "Savings vault" module is stored only as a hash.

8.4. Access to the admin panel (statistics, billing data, user list) is restricted to a small, designated group of individuals authorized by the Controller.

8.5. We recommend using a unique, strong password for your Account and never sharing it with third parties.

9. Cookies and localStorage

9.1. The Service does not use cookies for login or tracking purposes.

9.2. The Service uses the browser's localStorage mechanism (data stored locally on your device) to: store the session token (authentication), remember preferences (theme, language), and cache weather data. This data is not sent to third parties except as part of the normal operation of the relevant feature (e.g. the token is sent to our own server in a request header).

9.3. Because the Service does not use cookies for analytics or marketing, no cookie-consent banner is shown — this mechanism does not apply here.

10. Children's data

10.1. The Service is not directed at individuals under the age of 16. In line with Art. 8 GDPR and its Polish implementation, individuals under this age should not create an Account without parental or guardian consent.

10.2. If we become aware that we have processed the data of a child under 16 without the required consent, please contact us — such data will be deleted promptly.

11. Automated decision-making

11.1. The Controller does not make decisions about Users based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them (Art. 22 GDPR). AI Assistant responses (§4.2) are supportive in nature and do not constitute automated decision-making in this sense.

12. Changes to this Policy

12.1. This Policy may be updated, in particular in connection with changes to the Service's features, changes to third-party providers, or changes in law. Users will be notified of material changes electronically or via an in-app notice.

12.2. The current version of this Policy is always available at this address, together with the "last updated" date shown in the document header.