Privacy Policy
How Freya collects, uses, and protects your personal data.
Data Controller
The data controller for your personal data is:
Ihor Shaposhnyk
Sole proprietor (JDG) registered in Poland
NIP: PL 676 264 12 78
City: Krakow, Poland
Email: shaposhnik.mcd@gmail.com
What Data We Collect and Why
In accordance with Articles 13-14 of the GDPR (Regulation (EU) 2016/679), we inform you that we collect and process the following categories of personal data:
2.1 Account Data
- Email address — obtained from Google OAuth during sign-in. Used for account identification, authentication, and sending deadline reminder emails.
- Google profile name and avatar — displayed in the app header for your convenience. Not stored in our database beyond the session.
2.2 Business Data
- Company name, NIP, REGON, address — needed to generate invoices and calculate taxes correctly.
- Bank account number (IBAN) — displayed on generated invoices for your clients. Encrypted at the application level before storage.
- Tax form, ZUS status, VAT payer status — required for accurate tax and social contribution calculations.
- Registration date — used to automatically determine your ZUS contribution tier.
2.3 Financial Records
- Invoices — invoice numbers, dates, amounts, buyer details, line items. Created by you for tax calculation and PDF generation.
- Expenses — descriptions, amounts, VAT, categories, vendors. Entered by you for cost tracking and tax deduction calculations.
- Clients — company names, NIP numbers, addresses. Stored to pre-fill invoice forms.
- Payments — records of tax and ZUS payments you mark as paid. Used for deadline tracking.
2.4 Technical Data
- Audit logs — every data mutation (create, update, delete) is logged with a timestamp and action type for data integrity and security purposes.
- Session data — JWT tokens stored in cookies for authentication (7-day expiry).
2.5 AI Chat Data
- Chat messages — text you submit to the Freya AI assistant is sent to Anthropic (Claude) for response generation, and stored in our database for conversation history. When you ask the assistant about a specific document, the data of that document (invoices, expenses, clients, payments) — including counterparty details such as NIP — is also sent to Anthropic so the answer is about your own records.
- Receipt images — when you use OCR-based receipt parsing, the image bytes are sent to Anthropic for extraction and stored briefly until processing completes.
Legal Basis for Processing
We process your data under the following legal bases (Art. 6(1) GDPR):
- Contract performance (Art. 6(1)(b)) — processing your business and financial data is necessary to provide the tax calculation service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — audit logging for security, and sending deadline reminder emails that you have explicitly enabled in settings.
- Legal obligation (Art. 6(1)(c)) — retaining certain records as may be required by applicable tax and accounting regulations.
Data Retention
- Account data — retained for as long as your account is active. Upon an account-deletion request, personal data (name, email, avatar) is anonymized immediately under GDPR Art. 17; fiscal data is subject to a separate retention period (see below).
- Business and financial records — data subject to tax obligations (invoices, expenses, payments, JPK/PIT filings, bank statements) is retained for 5 years counted from the end of the calendar year in which the tax payment deadline fell (art. 70 § 1 of the Polish Tax Ordinance; GDPR Art. 17(3)(b)), then permanently deleted. In practice the purge runs roughly 66 months after account deletion.
- Audit logs — append-only (a Postgres trigger blocks updates and deletion), retained indefinitely as the permanent evidentiary record that the operations (including the account deletion itself) took place. Basis: legitimate interest — accountability and security (art. 6(1)(f) GDPR); after account anonymization the entries contain no identifying data.
- AI chat transcripts — retained as long as your account is active; soft-deleted with the account. Anthropic retains chat content per its Commercial Terms (typically up to 30 days for abuse monitoring).
- Session cookies — expire after 7 days of inactivity.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15) — you can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) — you can correct inaccurate data directly through the Settings page, or request a correction via email.
- Right to erasure (Art. 17) — you can request deletion of your account and all associated data.
- Right to data portability (Art. 20) — you can export your invoices and expenses in CSV format via the Annual Report page. You may also request a full data export.
- Right to restrict processing (Art. 18) — you can request that we limit processing of your data in certain circumstances.
- Right to object (Art. 21) — you can object to processing based on legitimate interest, including opting out of reminder emails in Settings.
To exercise any of these rights, contact us at shaposhnik.mcd@gmail.com. We will respond within 30 days as required by GDPR.
Sub-processors and Data Transfers
We use the following third-party services to operate Freya:
| Service | Purpose | Data Location | Data Sent |
|---|---|---|---|
| Neon (neon.tech) | PostgreSQL database hosting | Frankfurt, Germany (EU) | All application data (encrypted at rest) |
| Vercel (vercel.com) | Application hosting and serverless functions | EU region (Frankfurt) | Request metadata, server logs |
| Clerk (clerk.com) | Authentication and account management | USA (transfers covered by SCCs) | Email, profile, sign-in events, session metadata |
| OAuth sign-in (no Google services beyond sign-in) | Google Cloud (EU/US) | Email and profile name (during sign-in only) | |
| Anthropic (anthropic.com) | AI chat assistant (Freya AI) and receipt OCR/parsing | USA (transfers covered by SCCs) | Chat message text, receipt image bytes, the contents of uploaded PDFs (bank statements, supplier invoices) and data of documents you ask the assistant about (invoices / expenses / clients), including counterparty NIP |
| Stripe (stripe.com) | Payment processing for paid plans | USA (with EU entity Stripe Payments Europe Ltd) | Name, email, payment method tokens (no card data ever touches Freya servers) |
| Enable Banking (enablebanking.com) | Bank feeds (PSD2 AIS) — importing your bank's transaction history | EU/EEA (licensed AISP) | Account transaction history, IBAN, balances, counterparty names in payment descriptions |
| GoCardless (gocardless.com) | Bank feeds (PSD2 AIS) — legacy integration, closed to new connections | United Kingdom / EEA (adequacy decision, SCCs) | Account transaction history, IBAN, balances, counterparty names in payment descriptions |
| Resend (resend.com) | Sending deadline reminder and ops emails | USA (transfers covered by SCCs) | Email address and email content |
| Inngest (inngest.com) | Background jobs (cron, email batching, retry queue) | USA (transfers covered by SCCs, DPA — GDPR Art. 28) | Email subject and recipient, internal identifiers, retry metadata |
| Sentry (sentry.io) | Error and performance monitoring | USA (legitimate interest Art. 6(1)(f), transfers covered by SCCs) | Stack traces (with PII redacted), URL paths, opaque user identifiers |
| Telegram (telegram.org) | Reminders and notifications via the Telegram bot @FreyaTax_bot (opt-in) | Telegram Messenger LLP global infrastructure (third country — no adequacy decision and no SCCs; basis: your voluntary bot connection / legitimate interest, GDPR Art. 6(1)(f) and the Art. 49(1)(a) derogation). Only internal request identifiers are sent to the ops channel — no name, email, or company data. | Telegram user ID, reminder text (no invoice data or NIPs) |
| Vercel Blob | Storage for receipt PDFs, bank statements, exports | EU (region fra1, Frankfurt) | Files you upload or the service generates, access restricted via signed URLs |
International transfers
Several of our processors (Clerk, Anthropic, Stripe, Resend, Inngest, Sentry) operate from the United States. Data transfers to the US are protected by Standard Contractual Clauses (SCCs) as required by Chapter V of the GDPR. Data Processing Agreements (DPAs) are in effect with each of the listed processors — each DPA is incorporated by reference into the provider's Terms of Service that we accepted at account registration, in line with the standard click-wrap acceptance procedure for B2B SaaS. Copies of the DPAs are retained internally and can be provided on request at shaposhnik.mcd@gmail.com.
Anthropic, PBC processes data solely to provide the service and — under its commercial API terms — does NOT use your data to train its models. Transfers to the US are protected by Standard Contractual Clauses (SCCs). Learn more: https://www.anthropic.com/legal/privacy.
Data Security
- All data is transmitted over HTTPS (TLS 1.2+).
- Sensitive fields (NIP, bank account numbers) are encrypted at the application level before database storage.
- Database access is restricted to the application via connection pooling with SSL.
- Authentication uses industry-standard OAuth 2.0 with JWT sessions.
- All data mutations are logged in an audit trail.
- Records are soft-deleted (never permanently removed immediately) to prevent accidental data loss.
Right to Lodge a Complaint
If you believe that your personal data is being processed in violation of the GDPR, you have the right to lodge a complaint with the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Website: uodo.gov.pl
Phone: +48 22 531 03 00
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available at this URL. Material changes will be communicated via email to registered users.
Last updated · August 13, 2026