Privacy Policy
Last updated:
This notice explains what personal data EU Labels 4 AI collects, why, who else touches it, how long it is kept, and what you can require us to do about it. It is written to meet Articles 13 and 14 of the GDPR, and to be readable.
1. Who is responsible
The controller of your personal data is [Full legal name], [Street address], [postal code] [town], Poland (NIP [0000000000]), the sole trader operating EU Labels 4 AI.
Data-protection questions and requests go to contact@eulabels4ai.com. Account, billing, and support questions go to support@eulabels4ai.com.
We have not appointed a Data Protection Officer. We are not required to: we are a small trader, we do not monitor people systematically or at scale, and we process no special-category data. The address above reaches the person accountable for these decisions.
2. The short version
- Your images never reach us. Labelling happens entirely inside your browser.
- We hold an email address and a credit balance. That is essentially the whole of it.
- There is no analytics, no tracking, and no advertising. No Google Analytics, no pixels, no session recording, no third-party fonts. This is why the site has no cookie banner.
- We do not sell or share your data, and we never will.
- Account data is stored in the European Union.
The rest of this page is the detail behind those five statements.
3. Your images stay on your device
The labelling editor runs in your browser. Each image you add is decoded, drawn with the label, and re-encoded by your own device. No image file, filename, or label setting is transmitted to us or to anyone else. We have no copy of your images, no ability to view them, and nothing to hand over if someone asks us for them.
The consequence is worth understanding in both directions: it is the strongest privacy property this service has, and it also means we cannot recover your work if you lose it. Keep your originals.
The only network traffic the editor generates is signing you in, reading your credit balance, and recording that credits were spent.
4. What we collect and why
We collect the minimum needed to run an account and take payment. Each purpose below names its lawful basis under Article 6(1) of the GDPR.
| Data | Why we have it | Lawful basis |
|---|---|---|
| Email address | It is your account. Sign-in is passwordless, so the address is both your identifier and how we send the link that authenticates you. | Performance of a contract — Art. 6(1)(b) |
| Sign-in records | When the address was confirmed, and when sessions were issued. Needed to make sign-in work, and to detect abuse of the sign-in system. | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Credit balance and credit history | What you hold and how it changed: signup bonus, purchases, credits spent on exports, automatic refunds for failed renders. It is the record we both rely on. | Contract — Art. 6(1)(b) |
| Purchase and billing records | That a payment happened, for how much, and against which order. Card details are handled by Stripe and never reach us. | Contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c) |
| Messages you send us | Emails, and anything you submit through the contact form, so we can answer and keep track of the conversation. | Legitimate interests in answering enquiries — Art. 6(1)(f); contract where you are a customer |
| Server and security logs | IP address, browser user-agent, requested URL and timestamp, recorded by our hosting and database providers. Used to keep the service up, debug faults, and block attacks. | Legitimate interests in security and reliability — Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed them against your rights. The interests are narrow — keeping the service available, preventing fraud and abuse of the free credits, and replying to people who write to us — the data involved is minimal and not used to profile anyone, and none of it is used for marketing. You can object to this processing at any time; see section 10.
Providing this data is necessary to have an account. Without an email address we cannot create one, and without a payment record we cannot sell you credits. There is no obligation to sign up.
How the contact form works
The contact form on this site does not post anything to a server. It opens a draft in your own email application with the fields filled in, and you press send. Your message reaches us as an ordinary email, and until you send it nothing has left your device.
5. What we do not collect
Stated explicitly, because a notice that only lists what is collected leaves you guessing:
- Your images, or anything derived from them. See section 3.
- Analytics or tracking of any kind. No Google Analytics, no Meta or advertising pixels, no heatmaps, no session recording, no A/B testing tools.
- Third-party content that would see your IP address. Fonts are served from this site, not from a font CDN. There are no embedded videos, maps, social widgets, or comment systems.
- Card or bank details. Stripe handles payment data; it does not pass through us.
- Passwords. There are none to steal, because sign-in is by emailed link and code.
- Special-category data under Article 9 — health, biometrics, political or religious views, and the rest. We do not ask for it and have no use for it.
- Profiling or automated decision-making that produces legal or similarly significant effects under Article 22. No decision about you is made by an algorithm here.
We do not sell personal data, share it with data brokers, or disclose it for anyone else’s marketing.
6. Cookies and local storage
This site sets no cookies. It stores two items in your browser’s local storage, both strictly necessary for the service you asked for:
- Your session. Once you sign in, a session token is kept in local storage so you stay signed in between pages and visits. Removing it signs you out.
- A redirect note. If you were sent to sign in from somewhere else on the site, the page you came from is held briefly in session storage so you land back there afterwards. It is discarded as soon as it is used, and when you close the tab.
Neither is used to track you, neither is shared, and neither follows you to other websites. Because both are strictly necessary to deliver a service you explicitly requested, Article 5(3) of the ePrivacy Directive does not require consent for them — which is why you are not asked to dismiss a cookie banner here.
You can clear both at any time through your browser’s site-data settings. Doing so signs you out; it does not delete your account.
7. Who processes data for us
We use a small number of providers to run the service. Each is bound by a data processing agreement, may only act on our instructions, and may not use your data for their own purposes — except Stripe, which is also an independent controller for payment processing, fraud prevention, and its own legal obligations.
| Provider | What it does | Where data sits |
|---|---|---|
| Supabase | Accounts, sign-in, and the credit database | European Union |
| Cloudflare | Website hosting, CDN, and DNS | Global edge network; company in the USA |
| Stripe | Payment processing and receipts | Ireland (Stripe Payments Europe, Ltd.), with group transfers |
| Resend | Delivery of sign-in links and service emails | Sending from the EU; account data and logs in the USA |
We may also disclose data where the law requires it — to a court, a tax authority, or a regulator — or to establish or defend legal claims. If a lawful request for your data arrives, we will tell you unless we are legally prohibited from doing so.
8. International transfers
Your account data — your email address, balance, and credit history — is stored in the European Union. It is not routinely transferred outside it.
Two of our providers do involve transfers to the United States, and we would rather say so than not:
- Resend, which delivers sign-in emails. Messages are sent from an EU region, but Resend’s account data and delivery logs — which include recipient email addresses — are held in the USA.
- Cloudflare, which serves this website. Requests are handled by whichever edge location is nearest you, and Cloudflare is a US company with access to its own operational logs.
Both transfers are covered by the European Commission’s Standard Contractual Clauses, and both providers are certified under the EU–US Data Privacy Framework. Supabase and Stripe likewise rely on Standard Contractual Clauses for any transfer within their own groups. You may ask us for details of these safeguards at contact@eulabels4ai.com.
9. How long we keep things
| What | Kept for |
|---|---|
| Account and email address | As long as the account exists, then deleted within 30 days of closure |
| Credit balance and credit history | With the account, then deleted with it — except entries tied to a purchase, which follow the row below |
| Invoices and accounting records | 5 years from the end of the calendar year in which the tax became due, as Polish tax law requires. This obligation outlives a request to delete your account. |
| Support emails | Up to 2 years after the conversation ends |
| Server and security logs | Up to 90 days, then overwritten |
When a retention period ends, data is deleted or irreversibly anonymised. Where we must keep a billing record for tax purposes, we keep only that record and not the rest of the account.
10. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you (Art. 15).
- Rectification — have inaccurate data corrected (Art. 16).
- Erasure — have your data deleted, subject to records we must keep for tax purposes (Art. 17).
- Restriction — have us pause processing while a dispute is resolved (Art. 18).
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller (Art. 20).
- Objection — object to processing based on legitimate interests, on grounds relating to your situation (Art. 21).
- Withdraw consent — where processing rests on consent, withdraw it at any time, without affecting what was done before (Art. 7(3)).
Write to contact@eulabels4ai.com from the address on your account. We answer within one month, and will tell you if we need longer because a request is complex — the GDPR allows up to two further months in that case. Exercising these rights is free; we may charge a reasonable fee only for requests that are manifestly unfounded or excessive.
We may need to confirm it is really you before acting, particularly for erasure. Since we hold little more than an email address, this usually means replying from that address.
11. Complaints
If you think we have handled your data wrongly, tell us first at contact@eulabels4ai.com — we would like the chance to put it right.
You also have the right to complain to a supervisory authority. Ours is:
- Prezes Urzędu Ochrony Danych Osobowych
- President of the Personal Data Protection Office (UODO)
- ul. Stawki 2, 00-193 Warsaw, Poland
- https://uodo.gov.pl
You may also complain to the supervisory authority in the EU country where you live or work, or where you think the problem happened.
12. Security
We keep the amount of data we hold small, which is the most effective security measure available to us. Beyond that:
- All traffic to this site and to our backend is encrypted in transit with TLS.
- Sign-in uses one-time links and codes rather than passwords, and the link exchange uses PKCE so that a link intercepted by a mail scanner cannot be turned into a working session.
- Database access is constrained by row-level security: a signed-in browser can read only its own rows, and can write nothing at all. Credit balances are changed only by server-side functions.
- Administrative access to production systems is restricted to the controller and is logged.
No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and notify the supervisory authority within 72 hours as Article 33 requires.
13. Children
The Service is not directed at children. Holding an account requires you to be 18 or over, because buying credits is a contract. We do not knowingly collect data from anyone below that age; if you believe a minor has created an account, write to contact@eulabels4ai.com and we will delete it.
14. Changes to this policy
We update this notice when what we do with data changes. The current version is always at this address, with the date it was last updated at the top.
If a change materially affects how we handle your personal data, we will tell you by email to the address on your account before it takes effect, so that you can object, close your account, or exercise any other right in section 10.
15. Contact
Privacy questions, data-protection requests, and complaints: contact@eulabels4ai.com.
Account, billing, and support: support@eulabels4ai.com.
By post: [Full legal name], [Street address], [postal code] [town], Poland.
Our Terms of Service cover the rest of the relationship between us.
