Privacy Policy for PackBuddy
Privacy Policy for PackBuddy
Last Updated: June 8, 2026
This Privacy Policy outlines how the ItemifAI application (hereinafter referred to as the "Application") collects, processes, and protects the personal data of its users.
1. Data Controller
The Data Controller of your personal data is Mariusz Uziębło. For any questions regarding data protection or to exercise your rights, you can contact the Data Controller via email at: mariusz.9dev@gmail.com.
2. Data We Collect and How We Authenticate
- Registration and Authentication Data: The Application uses a passwordless login system. You only provide your email address, to which a one-time security token (Magic Link/OTP) is sent. The Application does not collect, process, or store user passwords.
- User Content: We process and store materials, texts, or files that you input into the Application to provide its core functionalities.
- Usage and Device Data: We collect basic technical information (operating system version, device model, Application version) and data about your activity within the Application to ensure its stability and improve performance.
3. Purpose and Legal Basis for Data Processing
Your data is processed for the following purposes:
- Providing electronic services (authentication, account maintenance) – Basis: necessity for the performance of a contract.
- Subscription management and payment verification – Basis: necessity for the performance of a contract.
- Providing technical support and communicating with users – Basis: legitimate interest of the Data Controller.
- Fulfilling legal obligations (e.g., tax and accounting requirements for purchases) – Basis: legal obligation.
4. Third-Party Services and Data Transfer
To ensure the proper functioning of the Application, we use specialized external service providers who process data on our behalf (Data Processors):
- Supabase / Amazon Web Services (AWS): Secure hosting of the database, user files, and management of the authentication token delivery system.
- RevenueCat: Subscription logic management, premium account status verification, and in-app purchase validation.
- App Stores (Google Play Store / Apple App Store): Direct execution of payment transactions. Neither the Data Controller nor RevenueCat has access to your credit card details or bank account information.
5. User Rights (GDPR Compliance)
You have the right to:
- Access your data and receive a copy of it.
- Rectify (correct) your data.
- Erase your data ("the right to be forgotten") – you can do this yourself directly within the Application.
- Restrict processing or object to the processing of your data.
- Lodge a complaint with a supervisory authority (e.g., the President of the Personal Data Protection Office in Poland or your local Data Protection Authority).
6. Data Security and Retention
Data is stored for the duration of your active user account. If you decide to delete your account, your data will be permanently erased within 30 days, except for anonymized transaction data required by applicable tax laws.