Poliogo

Privacy Policy

Effective date: August 7, 2026

Last updated: August 7, 2026

1. Who we are

Poliogo ("we", "us", "our") operates poliogo.com — a compliance layer that reads your codebase and keeps your privacy, terms and cookie documents up to date as your stack changes. We decide why and how your personal data is processed, which makes us the data controller under the EU and UK GDPR, a business under the California Consumer Privacy Act, and the equivalent role under other privacy laws that apply to you.

If you are in the EEA or the UK and we do not have an establishment there, you may contact us at the address above and we will route your request to our representative.

2. What personal data we collect

CategoryWhat it includesHow the law classifies it
Identity and contact dataFull name, email address, username or handle, company name, profile picture, country and password (kept only as a one-way hash)GDPR personal data · CCPA Category A (identifiers)
Technical and usage dataBrowser and user-agent string and language preference, session logs, pages viewed, referrerGDPR online identifiers · CCPA Category F (internet activity)
Content you give usImages you uploadGDPR personal data — including data about other people you include in it
Support communicationsMessages you send us and their attachmentsGDPR personal data · CCPA Category A

Some of what you give us contains other people's personal data — a document you upload, a name in a message, an address book you share. You need a lawful reason to give it to us, and we handle it under this policy on your behalf.

We do not deliberately collect biometric data, genetic data, precise geolocation or government identification numbers. If you send us any of these in a support message, we delete them once your request is resolved.

3. Where the data comes from

  • Directly from you — when you create an account, fill in a form, make a purchase or contact support.
  • Automatically — through cookies, server logs and the SDKs listed in section 7 when you use the service.
  • From third parties — from the identity provider you sign in with (which tells us your name and email address), and from the payment and infrastructure providers listed below.

4. Why we process it, and our legal basis

PurposeData usedLegal basis (EU/UK GDPR)
Creating and running your accountIdentity, technical dataArt. 6(1)(b) performance of a contract
Keeping the service secure and preventing fraudTechnical data, logsArt. 6(1)(f) legitimate interests
Storing and displaying the content you give usContent you give usArt. 6(1)(b) performance of a contract

Where another law applies, we rely on the equivalent basis: contractual necessity, legal obligation, legitimate interests, or your consent under the LGPD, PIPL, PIPEDA, the Australian Privacy Act and the US state privacy laws.

5. AI and automated decision-making

We do not use your personal data to train AI models, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

6. Cookies and tracking

We group everything we store on your device into four categories: strictly necessary, functional, analytics and marketing. Only strictly necessary items are set without your permission.

NameSet byCategoryWhat it doesLifespan
__sessionPoliogoStrictly NecessaryCarries the signed token that keeps you signed inUntil you sign out or it expires
__cf_bmCloudflareStrictly NecessaryBot management and abuse prevention30 minutes
firebase:authUser:*FirebaseStrictly NecessaryKeeps you signed in (browser storage, not a cookie)Until you sign out

Beyond cookies we also use data we keep in your browser's local storage. The same consent rules apply to these as to cookies.

Where the law requires your consent, we ask for it before non-essential items are set. You can change your choices at any time by writing to [email protected], and we will apply them to every non-essential technology we use. Our full Cookie Policy explains each item in detail.

7. Who we share data with

We do not sell your personal data for money. We do not share personal data for cross-context behavioural advertising.

ServiceProviderWhy we use itWhat it receivesWhere it processes data
CloudflareCloudflare, Inc.CDN, DNS, security filtering and edge computeIP addresses, request headers, security eventsEdge locations worldwide
FirebaseGoogle LLCSign-in, app data storage and push messagingEmail, auth tokens, device push tokens, app usage events, stored documentsUnited States

Every provider above is bound by a data processing agreement that limits them to our instructions. We also disclose personal data when a law, court order or regulator requires it, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.

8. International transfers

Our infrastructure runs in more than one region. Some of the providers above process data outside your country, including in the United States. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework, and we assess the destination country's laws before we do so. For transfers out of mainland China we rely on the mechanisms permitted by the PIPL.

9. How we protect your data

  • Access to production systems is limited to the people who need it, on the principle of least privilege.
  • Data is encrypted in transit and at rest by our infrastructure providers.
  • Passwords are stored only as one-way hashes — we never hold the password itself.
  • Input is validated on the server before it is stored, to keep records accurate.
  • A documented incident process: if a breach is likely to put you at risk we notify the competent authority within 72 hours and tell you without undue delay.

No system is perfectly secure, so we cannot promise absolute security.

10. How long we keep it

DataRetention
Account dataFor as long as your account is open, then 30 days after deletion
Server and security logs90 days, rolling
Content you uploadedUntil you delete it, then removed from backups within 30 days
Support conversations24 months after the conversation is closed
Analytics and cookie dataAs stated in the cookie table in section 6

When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.

11. Your rights

RightWhat it meansWhere it applies
AccessGet a copy of your data, its sources and who received itGDPR Art. 15 · CCPA § 1798.100 · LGPD · PIPL
DeletionHave your data erased, including at our processorsGDPR Art. 17 · CCPA § 1798.105 · DPDPA
CorrectionFix data that is wrong or out of dateGDPR Art. 16 · CCPA § 1798.106
PortabilityReceive your data in a machine-readable file (JSON or CSV)GDPR Art. 20 · CCPA § 1798.130
Opt out of sale, sharing and targeted adsStop advertising-related sharing, including via GPCCCPA/CPRA · VCDPA · CPA · CTDPA
Limit use of sensitive dataRestrict use beyond what the service needsCPRA § 1798.121
Object or restrictObject to processing based on legitimate interestsGDPR Art. 18 and 21
Withdraw consentWithdraw consent at any time, without affecting past processingGDPR Art. 7(3) · LGPD · PIPL
No retaliationWe will never degrade your service because you exercised a rightCCPA § 1798.125

In the product you can already send us a privacy request through our request form without asking us. To exercise any of these, email [email protected] or use the request form in our Trust Center. We verify your identity through the email address on your account before we act. We answer within 30 days (GDPR) or 45 days (CCPA), and tell you if we need the extension the law allows. An authorised agent may submit a request with written proof of authority. You can also complain to your data protection authority — in the EU, the one where you live or work; in the UK, the ICO.

12. Children

The service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe someone below that age has given us data, write to [email protected] and we will delete it. Where we know a user is under 16 we do not sell or share their data without opt-in consent, as California and EU member state law require.

13. Regional information

We have users in the EU, the UK and the United States. The sections below apply to you wherever you live.

California (CCPA/CPRA)

In the last 12 months we collected the categories in section 2 for the purposes in section 4, and disclosed them to the providers in section 7. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond the purposes permitted by § 7027(m). California residents may also request the "Shine the Light" disclosure under Civ. Code § 1798.83.

EEA and United Kingdom

Our legal bases are in section 4 and our transfer safeguards in section 8. You may lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office.

Brazil (LGPD)

You may confirm whether we process your data, request anonymisation of unnecessary data, ask who we shared it with, and revoke consent — write to [email protected].

China (PIPL)

Where the PIPL applies we obtain separate consent before processing sensitive personal information, before sharing data with third parties and before transferring data outside mainland China.

Other regions

Residents of Virginia, Colorado, Connecticut, Utah, Texas and Florida have equivalent access, deletion, correction, portability and opt-out rights, plus a right to appeal a refused request by replying to our decision email.

14. Changes to this policy

We update this policy when what we do changes. The date at the top always reflects the current version, and previous versions are kept for audit. If a change is material we tell you by email or an in-app notice at least 30 days before it takes effect.


Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.