Privacy Policy
Effective date: August 13, 2026
Last updated: August 13, 2026
1. Who we are
Poliogo ("we", "us", "our") operates our website and applications — Poliogo reads your product. We decide why and how your personal data is processed, which makes us the data controller under the EU and UK GDPR, a business under the California Consumer Privacy Act, and the equivalent role under other privacy laws that apply to you.
- Contact for privacy questions and requests: [email protected]
- Where we are based: Israel
If you are in the EEA or the UK and we do not have an establishment there, you may contact us at the address above and we will route your request to our representative.
2. What personal data we collect
| Category | What it includes | How the law classifies it |
|---|---|---|
| Identity and contact data | Full name, email address, username or handle, company name, profile picture, country and password (kept only as a one-way hash) | GDPR personal data · CCPA Category A (identifiers) |
| Technical and usage data | Device identifier, browser and user-agent string, language preference and a pseudonymous analytics identifier, session logs, pages viewed, referrer | GDPR online identifiers · CCPA Category F (internet activity) |
| Content you give us | Images you upload and messages you send through the service | GDPR personal data — including data about other people you include in it |
| Support communications | Messages you send us and their attachments | GDPR personal data · CCPA Category A |
Some of what you give us contains other people's personal data — a document you upload, a name in a message, an address book you share. You need a lawful reason to give it to us, and we handle it under this policy on your behalf.
We do not deliberately collect biometric data, genetic data, precise geolocation or government identification numbers. If you send us any of these in a support message, we delete them once your request is resolved.
3. Where the data comes from
- Directly from you — when you create an account, fill in a form, make a purchase or contact support.
- Automatically — through cookies, server logs and the SDKs listed in section 7 when you use the service.
- From third parties — from the identity provider you sign in with (which tells us your name and email address), and from the payment and infrastructure providers listed below.
4. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Creating and running your account | Identity, technical data | Art. 6(1)(b) performance of a contract |
| Keeping the service secure and preventing fraud | Technical data, logs | Art. 6(1)(f) legitimate interests |
| Storing and displaying the content you give us | Content you give us | Art. 6(1)(b) performance of a contract |
Where another law applies, we rely on the equivalent basis: contractual necessity, legal obligation, legitimate interests, or your consent under the LGPD, PIPL, PIPEDA, the Australian Privacy Act and the US state privacy laws.
5. AI and automated decision-making
We do not use your personal data to train AI models, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
6. Cookies and tracking
We group everything we store on your device into four categories: strictly necessary, functional, analytics and marketing. Only strictly necessary items are set without your permission.
| Name | Set by | Category | What it does | Lifespan |
|---|---|---|---|---|
__session | Poliogo | Strictly Necessary | Carries the signed token that keeps you signed in | Until you sign out or it expires |
__cf_bm | Cloudflare | Strictly Necessary | Bot management and abuse prevention | 30 minutes |
firebase:authUser:* | Firebase | Strictly Necessary | Keeps you signed in (browser storage, not a cookie) | Until you sign out |
Beyond cookies we also use data we keep in your browser's local storage. The same consent rules apply to these as to cookies.
Where the law requires your consent, we ask for it before non-essential items are set. You can change your choices at any time by writing to [email protected], and we will apply them to every non-essential technology we use. Our full Cookie Policy explains each item in detail.
7. Who we share data with
We do not sell your personal data for money. We do not share personal data for cross-context behavioural advertising.
| Service | Provider | Why we use it | What it receives | Where it processes data |
|---|---|---|---|---|
| Cloudflare | Cloudflare, Inc. | CDN, DNS, security filtering and edge compute | IP addresses, request headers, security events | Edge locations worldwide |
| Netlify | Netlify, Inc. | Application hosting and edge delivery | Request logs, IP addresses, and aggregated visitor analytics | United States and edge regions worldwide |
| Vercel | Vercel Inc. | Application hosting and edge delivery | Request logs, IP addresses, and aggregated visitor analytics | United States and edge regions worldwide |
| Framer | Framer B.V. | Hosting the published site and collecting its form submissions | Visitor request logs and IP addresses, and form submissions from the published site | Netherlands, United States |
| Lovable | Lovable Labs Incorporated | Building and hosting the application | Visitor request logs and IP addresses for the published app, and the project contents you build in the editor | United States, Sweden |
| Railway | Railway Corp. | Application and database hosting | Request logs and anything your services store | Depends on your chosen region |
| Render | Render Services, Inc. | Application and database hosting | Request logs, IP addresses, and anything your services store | Depends on your chosen region |
| Replit | Replit, Inc. | Hosting and running the application | Visitor request logs and IP addresses for the deployment, and everything the repl stores | United States |
| Webflow | Webflow, Inc. | Hosting the published site and collecting its form submissions | Visitor request logs and IP addresses, form submissions, and any personal data held in CMS collections | United States |
| Firebase | Google LLC | Sign-in, app data storage and push messaging | Email, auth tokens, device push tokens, app usage events, stored documents | United States |
We also use the following, which are not part of the product's code: backboard.railway.com, authjs.dev, acmenotes.io, api.stripe.com, www.googleapis.com, securetoken.google.com, oauth2.googleapis.com, identitytoolkit.googleapis.com, stripe.com, js.stripe.com, login.microsoftonline.com, app.vssps.visualstudio.
Every provider above is bound by a data processing agreement that limits them to our instructions. We also disclose personal data when a law, court order or regulator requires it, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.
8. International transfers
Some of the providers above process data outside your country, including in the United States. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework, and we assess the destination country's laws before we do so. For transfers out of mainland China we rely on the mechanisms permitted by the PIPL.
9. How we protect your data
- Access to production systems is limited to the people who need it, on the principle of least privilege.
- Data is encrypted in transit and at rest by our infrastructure providers.
- Passwords are stored only as one-way hashes — we never hold the password itself.
- Input is validated on the server before it is stored, to keep records accurate.
- A documented incident process: if a breach is likely to put you at risk we notify the competent authority within 72 hours and tell you without undue delay.
No system is perfectly secure, so we cannot promise absolute security.
10. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account is open, then 30 days after deletion |
| Server and security logs | 90 days, rolling |
| Content you uploaded | Until you delete it, then removed from backups within 30 days |
| Support conversations | 24 months after the conversation is closed |
| Analytics and cookie data | As stated in the cookie table in section 6 |
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.
11. Your rights
| Right | What it means | Where it applies |
|---|---|---|
| Access | Get a copy of your data, its sources and who received it | GDPR Art. 15 · CCPA § 1798.100 · LGPD · PIPL |
| Deletion | Have your data erased, including at our processors | GDPR Art. 17 · CCPA § 1798.105 · DPDPA |
| Correction | Fix data that is wrong or out of date | GDPR Art. 16 · CCPA § 1798.106 |
| Portability | Receive your data in a machine-readable file (JSON or CSV) | GDPR Art. 20 · CCPA § 1798.130 |
| Opt out of sale, sharing and targeted ads | Stop advertising-related sharing, including via GPC | CCPA/CPRA · VCDPA · CPA · CTDPA |
| Limit use of sensitive data | Restrict use beyond what the service needs | CPRA § 1798.121 |
| Object or restrict | Object to processing based on legitimate interests | GDPR Art. 18 and 21 |
| Withdraw consent | Withdraw consent at any time, without affecting past processing | GDPR Art. 7(3) · LGPD · PIPL |
| No retaliation | We will never degrade your service because you exercised a right | CCPA § 1798.125 |
In the product you can already send us a privacy request through our request form without asking us. To exercise any of these, email [email protected] or use the request form in our Trust Center. We verify your identity through the email address on your account before we act. We answer within 30 days (GDPR) or 45 days (CCPA), and tell you if we need the extension the law allows. An authorised agent may submit a request with written proof of authority. You can also complain to your data protection authority — in the EU, the one where you live or work; in the UK, the ICO.
12. Children
The service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe someone below that age has given us data, write to [email protected] and we will delete it. Where we know a user is under 16 we do not sell or share their data without opt-in consent, as California and EU member state law require.
13. Regional information
California (CCPA/CPRA)
In the last 12 months we collected the categories in section 2 for the purposes in section 4, and disclosed them to the providers in section 7. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond the purposes permitted by § 7027(m). California residents may also request the "Shine the Light" disclosure under Civ. Code § 1798.83.
EEA and United Kingdom
Our legal bases are in section 4 and our transfer safeguards in section 8. You may lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office.
Brazil (LGPD)
You may confirm whether we process your data, request anonymisation of unnecessary data, ask who we shared it with, and revoke consent — write to [email protected].
China (PIPL)
Where the PIPL applies we obtain separate consent before processing sensitive personal information, before sharing data with third parties and before transferring data outside mainland China.
Other regions
Residents of Virginia, Colorado, Connecticut, Utah, Texas and Florida have equivalent access, deletion, correction, portability and opt-out rights, plus a right to appeal a refused request by replying to our decision email.
14. Changes to this policy
We update this policy when what we do changes. The date at the top always reflects the current version, and previous versions are kept for audit. If a change is material we tell you by email or an in-app notice at least 30 days before it takes effect.
Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.