Last updated: February 16, 2026
The controller responsible for data processing on this website is:
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data ("data") in connection with the provision of the EPOS-AI platform.
Legal bases: This Privacy Policy is based on:
Upon registration we collect:
Payments are processed by Stripe. We do NOT store credit card data on our servers.
The following data is stored for billing purposes:
During use of the Service we process:
We use the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| session_token | Authentication (strictly necessary) | 1 hour |
| preferences | Storing UI settings | 1 year |
We do NOT use Google Analytics or any other third-party tracking tools.
| Data Type | Legal Basis (GDPR) |
|---|---|
| Account data, payment data | Art. 6(1)(b) GDPR (contract performance) |
| Usage data, logs | Art. 6(1)(f) GDPR (legitimate interests) |
| Marketing emails | Art. 6(1)(a) GDPR (consent) |
Purpose: Generating AI responses
Recipient: Anthropic PBC, USA
Privacy: anthropic.com/privacy
Guarantees:
Purpose: Processing payments
Recipient: Stripe Payments Europe Ltd., Ireland / Stripe Inc., USA
Privacy: stripe.com/privacy
Purpose: Sending transactional emails (registration, password reset, subscription confirmations)
Recipient: Resend, Inc., USA
Data transmitted: Name, email address
Legal basis: Art. 6(1)(b) GDPR (contract performance)
We do NOT share your data with:
Your data is stored on servers in Switzerland.
Hosting: FireStorm ISP GmbH, Kirchenrainstrasse 27, 8632 Tann (ZH), Switzerland — CHE-114.927.665 (Swiss company, servers in Switzerland, Swiss data protection law)
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Projects and texts | Until manual deletion |
| Payment data | 10 years (statutory retention obligation) |
| Logs (IP addresses) | 30 days |
| After account deletion | 30 days (backup retention), then complete deletion |
You have the following rights regarding your data:
You may request information about the data we hold about you.
You may request correction of inaccurate data.
You may request deletion of your data ("right to be forgotten").
You may request restriction of processing.
You may download your data in a structured format (JSON/CSV).
You may object to processing on grounds relating to your particular situation.
Where processing is based on consent, you may withdraw it at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.
Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
www.edoeb.admin.ch/en
UK:
Information Commissioner's Office (ICO)
ico.org.uk
EU:
The supervisory authority of your EU member state
We confirm:
Our Service is not directed at persons under 18 years of age. We do not knowingly collect data from minors.
We reserve the right to update this Privacy Policy to reflect changes in law or in our Service. Changes will be announced by email. The current version is always available on this page.
For questions about privacy or to exercise your rights, please contact:
We respond within 30 days.