Privacy Policy and Data Processing
Last updated: August 21, 2026
This Privacy Policy describes the terms under which Jorge Arrojo Macías (the “Controller” or the “Operator”) collects, processes, stores, and protects the personal data of users (the “User”) through the mobile and desktop application (the “Application”) and the associated backend services.
This document has been drafted in strict compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Identity of the Data Controller
Controller: Jorge Arrojo Macías
Contact / support email: hola@jorgearrojo.dev
Service provided: Content generation application using Artificial Intelligence (AI) and a backend API.
2. Categories of Data Processed, Purposes, and Legal Basis (Art. 5.1.c and Art. 6 GDPR)
In accordance with the principle of data minimization, only the data strictly necessary to provide the service are collected. It is expressly stated that the Controller does not store the User’s public IP address; server session and audit logs only retain the internal/private IP of the deployment environment, making identification of the individual impossible.
The data processed on the Controller’s servers are detailed below:
| Data Category | Processing Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|---|
| nickname | User account identification. | Contract performance (Art. 6.1.b) / Consent (Art. 6.1.a). |
| Password (stored exclusively as a hash) | Account authentication and security. | Contract performance (Art. 6.1.b) / Legitimate interest (Art. 6.1.f). |
| Session data (hashed tokens, userAgent, device identifier) | Maintaining the active session and security control. | Contract performance (Art. 6.1.b) / Legitimate interest (Art. 6.1.f). |
| Content of requests (prompts) and AI responses | Technical provision of the generation service. | Contract performance (Art. 6.1.b) / Consent (Art. 6.1.a). |
| Audit logs, usage, notifications, and outbox | Security, error diagnostics, and quota/billing control. | Legitimate interest in security and proper operation (Art. 6.1.f). |
The Controller does not collect direct payment data or official identity documents.
3. Local Data Processing on the Device (App Store Sandbox)
To guarantee maximum privacy, much of the information is processed and retained exclusively in the User’s local device storage, without being transmitted to the Controller’s servers:
Secure Keychain: Secure local storage without iCloud synchronization is used to hold API keys of integrated providers (such as Zen Pro, DeepSeek, etc.), access and refresh session tokens, basic profile information (nickname, identifier, plan), and automatic sign-in credentials.
Configuration Directory (settings.json): Locally stores the selected chat provider configuration, premium subscription metadata (device identifier, consumed and refunded tasks), and generation metadata (title, format, model, size).
Data Directory (Files and Conversations): Generated files (PDF, DOC, MD, HTML, or code) are saved to local disk once decoded, constituting the only existing copy after their automatic deletion from the server. The conversation history is persisted locally in JSON format within the Application’s isolated directories.
Volatile Memory: The Application does not use localStorage or IndexedDB. base64 files are discarded immediately after being written to local disk.
4. Processing of Special Categories of Data (Art. 9 GDPR) and Disclaimer
The Application and the services provided do not require, request, or have the purpose of collecting personal data belonging to special categories (those revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person’s sex life or sexual orientation).
To the extent that the User freely enters this type of information in their requests (prompts), such processing shall be covered by the User’s explicit consent (Art. 9.2.a GDPR), granted through a clear affirmative action when submitting the request. These data will be processed ephemerally and automatically, solely and exclusively for the technical purpose of generating the requested response through the language model.
Disclaimer and limitation of liability:- Voluntary nature: The User expressly acknowledges and accepts that the inclusion of personal data, whether their own or belonging to others, in the content of their requests is carried out strictly voluntarily and under their sole responsibility.
- Third-Party Data: If the User enters personal data (especially sensitive data or special categories of data) relating to third-party natural persons, the User declares, warrants, and assumes responsibility for having the appropriate legal basis (such as the explicit and documented consent of that third party) to share such information with the Application.
- Voluntary nature: The Controller declines any liability arising from infringement of data protection regulations, the right to honor, privacy, or personal image, resulting from the unlawful, non-consensual, or negligent introduction of confidential information or personal data by the User in the Application’s text boxes.
5. Retention Periods (Art. 5.1.e GDPR)
Data on our servers is subject to automatic deletion with the following periods:
Completed tasks, generated content, and notifications: 12 months.
Audit logs and usage metrics: 6 months.
Expired sessions and processed outbox: 30 days.
User account: While it remains active. If deletion is requested, the account, sessions, tasks, content, notifications, and associated records will be deleted in cascade immediately (within 24 to 48 hours).
6. Data Processors and Data Hosting (Art. 28 GDPR)
To provide the AI model generation services, the content of the User’s requests is processed using the infrastructure of the technology provider Scaleway, whose servers are physically located in France (European Union).
Scaleway acts as a Data Processor. Since the servers are located within the European Economic Area (EEA), no international data transfers requiring additional safeguards under Chapter V of the GDPR are carried out. The relationship between the Controller and Scaleway is strictly governed by a Data Processing Agreement (DPA) that ensures compliance with European security and confidentiality regulations.
The rest of the infrastructure is under our exclusive control. The Controller does not sell or assign data to third parties for commercial purposes.
7. Security Measures (Art. 32 GDPR)
Technical and organizational measures are applied to ensure security:
Passwords and tokens using hashing.
Communications encrypted via TLS/HTTPS.
Access to infrastructure restricted on a private network, without recording of public IP.
Encryption at rest: data on an encrypted server volume with protected backups.
8. Rights of Data Subjects (Arts. 15 to 22 GDPR and LOPDGDD)
The User may exercise their rights of access, rectification, erasure, restriction, portability, and objection. Erasure is available directly in the app and by request to hola@jorgearrojo.dev. The legal response period is 1 month.
9. Minors
Service not directed at minors under 18 years of age. We do not knowingly process data of minors.
10. Notification of Security Breaches (Arts. 33 and 34 GDPR)
In the event of an incident affecting your data, we will notify the User and the AEPD when applicable.
11. Changes to this policy
They will be published here with their date; continued use implies acceptance.