1.1. The controller of personal data processed in connection with the use of the AnotherDashboard service (the "Service") is:
1.2. Contact for data-protection matters: support@anotherdashboard.com.
1.3. This Policy is based on Regulation (EU) 2016/679 (GDPR) and applicable Polish data-protection law.
| Category | Examples |
|---|---|
| Account data | email address, password (stored only as a bcrypt hash), name (optional), email verification status |
| Technical data and logs | IP address on login and on every visit to the Service, timestamps, login events — for security and abuse-prevention purposes |
| User-generated content | tasks, notes, activities, birthdays of third parties entered by the User, "About me" free-text field |
| Habit-tracking data | habits and their completion history, counters, addiction/streak trackers (name, start date, daily cost), mood entries (1–6 scale) |
| Financial data entered by the User | expenses (amount, category, description, date), savings "vault" balance and transaction history, hashed PIN protecting the vault |
| Health/fitness-adjacent data entered by the User | weight measurements, weight goals, workout log (routines, sessions, exercises) |
| Billing data | PRO Plan purchase history (plan, amount, currency, status, Paddle transaction identifiers) — no card data ever reaches our servers (see §4) |
| AI Assistant conversation content | messages sent to the assistant plus a contextual excerpt of Account data necessary to answer (see §4.2) |
| Preferences | visual theme, interface language, location (city/coordinates) for weather display |
2.2. We do not intentionally collect special categories of personal data under Art. 9 GDPR — however, note that data entered voluntarily in the "Addictions/Trackers" and "Mood" modules may be health-adjacent in nature. This data is entered solely on the User's own initiative and with their knowledge, to deliver the relevant feature, on the basis of the contract (Art. 6(1)(b) GDPR).
| Purpose | Legal basis |
|---|---|
| Account creation and provision of Service features | Art. 6(1)(b) GDPR — necessary for performance of a contract |
| Processing PRO Plan payments | Art. 6(1)(b) GDPR — performance of the sales contract (see also §4 on Paddle's role as Merchant of Record) |
| Transactional emails (verification, password reset, purchase confirmation) | Art. 6(1)(b) and (c) GDPR — contract performance and legal obligations |
| Security logs (login/visit IP addresses) | Art. 6(1)(f) GDPR — legitimate interest (security, abuse prevention) |
| AI Assistant feature | Art. 6(1)(b) GDPR — delivering a feature explicitly invoked by the User |
| Handling complaints and correspondence | Art. 6(1)(b) and (f) GDPR |
| Tax/accounting obligations | Art. 6(1)(c) GDPR — legal obligation |
| Direct marketing of our own services (if conducted) | Art. 6(1)(f) GDPR or consent (Art. 6(1)(a)), depending on the channel |
4.1. We do not sell personal data. Data may be shared with, or processed by, the following categories of recipients, strictly to the extent necessary for their function:
4.2. About the AI Assistant specifically: the prompt sent to DeepSeek includes a concise excerpt of your Account data (e.g. today's/tomorrow's tasks, habit/counter/tracker names, birthdays) — only what's needed to power the "assistant can see your data" feature. Historical data (past expenses, notes, older entries) is only sent on your explicit request during the conversation. Savings-vault data is only sent after you verify your PIN. Using the AI Assistant is optional — if you'd rather your data not be processed by DeepSeek, simply don't use that feature.
5.1. The AI Assistant provider (DeepSeek) processes data outside the European Economic Area, in a country not covered by a European Commission adequacy decision under Art. 45 GDPR.
5.2. This transfer relies on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses) and is limited to message content and the minimal context described in §4.2.
5.3. You may request a copy of the safeguards applied by contacting us at the address in §1.2.
6.1. Account data and User-generated content are retained for as long as the Account exists, i.e. until deleted by the User or at their request.
6.2. Billing records (purchase history) are retained for the period required by tax law (generally 5 years from the end of the year in which the tax became due).
6.3. Security logs (IP addresses, login events) are retained for no longer than 12 months, unless needed to investigate an ongoing security incident.
6.4. After an Account is deleted, data is removed from the production database without undue delay; backups containing the deleted data are overwritten in the normal backup-rotation cycle.
7.1. In connection with the processing of your personal data, you have the right to:
7.2. To exercise these rights, please contact us at the address in §1.2. We respond without undue delay, and in any event within one month of receiving your request.
8.1. User passwords are stored only as bcrypt hashes — the Controller never has access to passwords in plain text.
8.2. Account access is secured by a session token (JWT), stored locally in the User's browser and sent via a request header — the Service does not use cookies for this purpose.
8.3. The PIN protecting the "Savings vault" module is stored only as a hash.
8.4. Access to the admin panel (statistics, billing data, user list) is restricted to a small, designated group of individuals authorized by the Controller.
8.5. We recommend using a unique, strong password for your Account and never sharing it with third parties.
9.1. The Service does not use cookies for login or tracking purposes.
9.2. The Service uses the browser's localStorage mechanism (data stored locally on your device) to: store the session token (authentication), remember preferences (theme, language), and cache weather data. This data is not sent to third parties except as part of the normal operation of the relevant feature (e.g. the token is sent to our own server in a request header).
9.3. Because the Service does not use cookies for analytics or marketing, no cookie-consent banner is shown — this mechanism does not apply here.
10.1. The Service is not directed at individuals under the age of 16. In line with Art. 8 GDPR and its Polish implementation, individuals under this age should not create an Account without parental or guardian consent.
10.2. If we become aware that we have processed the data of a child under 16 without the required consent, please contact us — such data will be deleted promptly.
11.1. The Controller does not make decisions about Users based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them (Art. 22 GDPR). AI Assistant responses (§4.2) are supportive in nature and do not constitute automated decision-making in this sense.
12.1. This Policy may be updated, in particular in connection with changes to the Service's features, changes to third-party providers, or changes in law. Users will be notified of material changes electronically or via an in-app notice.
12.2. The current version of this Policy is always available at this address, together with the "last updated" date shown in the document header.