经验项目博客
联系我

Privacy Policy

Last Updated: June 2026

This Privacy Policy describes how we process personal data in full compliance with the EU General Data Protection Regulation (GDPR).

1. Data Controller and Contact

The Data Controller responsible for processing your data via the Service is detailed in our mandatory Imprint/Impressum. For any privacy-related matters, you can reach us directly at privacy@byphil.eu.

2. Legal Basis for Data Processing (GDPR Art. 6)

  • Performance of a Contract (Art. 6(1)(b) GDPR): Processing your email address via the OTP login flow to provision and maintain your paid Pro subscription.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Processing technical identifiers (such as the X-Install-ID or transient text tokens) to enforce free-trial anti-abuse caps and route request metrics safely.

3. Zero-Retention Text Processing Array

In-Memory Volatility: When you execute a text or document summary request, the payload context is transmitted to our secure loopback gateway (api.byphil.eu) and proxied directly to OpenRouter.

Once the summary token stream is returned to your browser view, the raw source text is permanently expunged from our memory arrays. We do not cache, log, store, or train models on the contents of your documents.

4. Third-Party Data Handshakes & Paddle Processing

For payment infrastructure, billing, and global tax processing, your transactional data is shared directly with our Merchant of Record, Paddle. You can view Paddle's specific data processing metrics via their privacy documentation at paddle.com/legal/privacy.

To execute AI inferences, text streams are securely forwarded to OpenRouter. Where data is transferred to downstream servers outside the European Economic Area (EEA), we ensure strict security protocols are met via standard zero-data-retention pipeline privacy rules.

5. Your GDPR Rights

As an EU resident, you hold the following statutory rights under the GDPR:

  • Art. 15: Right of Access to your stored parameters (Email, subscription state).
  • Art. 16 & 17: Right to rectification or complete erasure ("Right to be forgotten") of your account record.
  • Art. 20: Right to data portability.

To exercise these rights, submit a request to privacy@byphil.eu. You also reserve the right to lodge an official complaint with a competent data protection supervisory authority.

← Back to Legal Overview