1. Data Controller

The data controller responsible for processing your personal data is:

Ilia Grezin

Obchodná 559/37, 811 06 Bratislava-Staré Mesto, Slovak Republic

IČO (Business ID): 54382394

Email: hello@kotia.app

2. Data We Collect

When using kotia.app, we collect the following data:

  • Account data (legal basis: contract): name, email, avatar via Google OAuth 2.0
  • Generated content (legal basis: contract): request topics and created articles
  • Token usage (legal basis: contract): history of free and paid token consumption
  • Technical data (legal basis: legitimate interest): IP address, browser type, device information for security and service stability
  • Analytics data (legal basis: consent): pages visited and actions on them via Yandex.Metrica, including session recording (Webvisor); collected only with your consent
  • Support requests via Telegram (legal basis: legitimate interest): your Telegram account ID, name and username, and the app language. The conversation itself is not stored on our side

3. How We Use Data

We use your data for the following purposes:

  • Service delivery (contract): providing AI content generation, managing your account, processing token transactions
  • Payment processing (contract): confirming cryptocurrency transfers using public blockchain data
  • Service improvement (legitimate interest): analyzing usage patterns to improve service quality
  • Communication (legitimate interest): sending important service notifications about your account
  • Analytics (consent): understanding how users interact with our platform via Yandex.Metrica
  • AI model training: we do not train models on your data and do not pass it to anyone for training. Retention and usage terms differ between model providers. Anthropic, OpenAI and Google use what is sent only to produce the answer and do not use it for training; with OpenAI we have additionally disabled retention of the conversation on their side. DeepSeek is the exception: what is sent stays with the provider, may be used by them to train their models, and this cannot be switched off technically. DeepSeek models are chosen by you manually; if the material is confidential, pick another model

4. Data Storage and Retention

Your data is stored securely with the following standards:

  • Data encryption in transit (TLS/SSL)
  • Regular encrypted backups
  • Limited data access (administrators only)

Retention periods:

  • Account data: retained until you delete your account
  • Generated content: retained until you delete your account or specific articles
  • Technical logs: retained for 90 days
  • Payment records: retained for 10 years (legal obligation)
  • Analytics data: retained according to Yandex.Metrica rules
  • Telegram support request data: retained until the account is deleted or until you ask us to delete it

5. Third-Party Services

We share data with the following third-party processors:

  • Google OAuth 2.0: authentication — processes name, email, avatar
  • Anthropic (Claude): answer generation and assistant work — receives the conversation text, attached files and the materials you put to work
  • OpenAI: same purpose and same scope of data. Retention of the conversation on the provider side is disabled by us
  • Google (Gemini): same purpose and same scope of data
  • DeepSeek: same purpose and same scope of data. What is sent stays with the provider — see the AI model training section
  • TronGrid: a public TRON network node — used to verify that a transfer arrived. We do not send it any payment or personal data
  • Yandex: Yandex.Metrica site analytics — processes IP address, browser and device details, pages visited and actions on them, including session recording (Webvisor); with your consent only. The same provider protects our sign-in and sign-up forms from bots (Yandex SmartCaptcha)
  • Google: Google Ads tag — processes IP address, browser and device details, the fact that you arrived from an ad and conversion actions on the site; with your consent only
  • Telegram: feedback bot — delivers your request and our answer; receives the text of the request, its attachments and the messages you send to support inside the service, and, for an identified user, the email address and subscription plan
  • Hetzner: hosting infrastructure — stores all data (servers in EU, Germany)

Privacy policies of our processors:

6. International Data Transfers

Your data is primarily stored within the European Union (Hetzner, Germany). Some third-party services may process data outside the EU:

  • Anthropic, OpenAI: data may be processed in the USA
  • Google services (OAuth, Gemini): data may be processed in the US under the EU-US Data Privacy Framework
  • DeepSeek: data may be processed in China under Standard Contractual Clauses (SCCs)
  • Yandex (Metrica, bot protection for forms): data may be processed in Russia on the basis of your consent (GDPR Art. 49)
  • Google (Google Ads tag): data may be processed in the USA on the basis of your consent (GDPR Art. 49)
  • Telegram (feedback bot): the operator is registered in the British Virgin Islands and data of EEA users is stored in data centres in the Netherlands; the transfer is unavoidable — you choose this channel yourself, and it is necessary to deliver your request and our answer to it (GDPR Art. 49)
  • Stripe: data may be processed in the US under the EU-US Data Privacy Framework

All international transfers are protected by appropriate safeguards in accordance with GDPR Chapter V.

7. Cookies

We use the following categories of cookies:

Essential cookies (always active):

  • Session cookie — maintains your login session (httpOnly, secure, sameSite: lax)
  • Preferences — remembers your theme and language settings
  • Short-lived technical cookies — carry advertising tags, the consent flag, the referral code and the Telegram linking key through sign-in (duration: up to 1 hour)

Analytics cookies (require your consent):

  • _ym_uid, _ym_d, _ym_isad and other Yandex.Metrica cookies — site analytics and session recording (duration: up to 1 year)
  • _gcl_au and other Google Ads cookies — measuring ad clicks and conversion actions (duration: up to 90 days)

You can manage your cookie preferences at any time through the cookie settings in the footer of our website.

8. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of access (Art. 15): obtain a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate personal data
  • Right to erasure (Art. 17): request deletion of your personal data
  • Right to restriction (Art. 18): restrict the processing of your data
  • Right to data portability (Art. 20): receive your data in a machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interest
  • Right regarding automated decisions (Art. 22): not be subject to solely automated decision-making
  • Right to withdraw consent (Art. 7): withdraw consent at any time without affecting prior processing

To exercise your rights, contact us at: hello@kotia.app

You also have the right to lodge a complaint with the supervisory authority:

Úrad na ochranu osobných údajov Slovenskej republiky

Hraničná 12, 820 07 Bratislava 27, Slovak Republic

dataprotection.gov.sk

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to: know what personal information we collect and how it is used; request deletion of your personal data; opt out of the sale of personal information. We do not sell your personal information to third parties. To exercise these rights, contact hello@kotia.app with "Privacy Request" in the subject line.

9. Security

We implement the following security measures:

  • Rate limiting for DDoS protection
  • Validation of all input data
  • SQL injection protection (parameterized queries)
  • CORS policy for CSRF protection
  • Regular security audits

10. Policy Changes

We may update this privacy policy. We will notify you of significant changes via email or service notifications. The latest version is always available at this page.

In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities within 72 hours of discovery, in accordance with applicable law.

11. Contact

For privacy questions, contact us: