Skip to main content
LEGAL · GDPR

Privacy Policy

How Freya collects, uses, and protects your personal data.

§ 01

Data Controller

The data controller for your personal data is:

Ihor Shaposhnyk

Sole proprietor (JDG) registered in Poland

NIP: PL 676 264 12 78

City: Krakow, Poland

Email: shaposhnik.mcd@gmail.com

§ 02

What Data We Collect and Why

In accordance with Articles 13-14 of the GDPR (Regulation (EU) 2016/679), we inform you that we collect and process the following categories of personal data:

2.1 Account Data

  • Email address — obtained from Google OAuth during sign-in. Used for account identification, authentication, and sending deadline reminder emails.
  • Google profile name and avatar — displayed in the app header for your convenience. Not stored in our database beyond the session.

2.2 Business Data

  • Company name, NIP, REGON, address — needed to generate invoices and calculate taxes correctly.
  • Bank account number (IBAN) — displayed on generated invoices for your clients. Encrypted at the application level before storage.
  • Tax form, ZUS status, VAT payer status — required for accurate tax and social contribution calculations.
  • Registration date — used to automatically determine your ZUS contribution tier.

2.3 Financial Records

  • Invoices — invoice numbers, dates, amounts, buyer details, line items. Created by you for tax calculation and PDF generation.
  • Expenses — descriptions, amounts, VAT, categories, vendors. Entered by you for cost tracking and tax deduction calculations.
  • Clients — company names, NIP numbers, addresses. Stored to pre-fill invoice forms.
  • Payments — records of tax and ZUS payments you mark as paid. Used for deadline tracking.

2.4 Technical Data

  • Audit logs — every data mutation (create, update, delete) is logged with a timestamp and action type for data integrity and security purposes.
  • Session data — JWT tokens stored in cookies for authentication (7-day expiry).

2.5 AI Chat Data

  • Chat messages — text you submit to the Freya AI assistant is sent to Anthropic (Claude) for response generation, and stored in our database for conversation history. When you ask the assistant about a specific document, the data of that document (invoices, expenses, clients, payments) — including counterparty details such as NIP — is also sent to Anthropic so the answer is about your own records.
  • Receipt images — when you use OCR-based receipt parsing, the image bytes are sent to Anthropic for extraction and stored briefly until processing completes.
§ 03

Legal Basis for Processing

We process your data under the following legal bases (Art. 6(1) GDPR):

  • Contract performance (Art. 6(1)(b)) — processing your business and financial data is necessary to provide the tax calculation service you signed up for.
  • Legitimate interest (Art. 6(1)(f)) — audit logging for security, and sending deadline reminder emails that you have explicitly enabled in settings.
  • Legal obligation (Art. 6(1)(c)) — retaining certain records as may be required by applicable tax and accounting regulations.
§ 04

Data Retention

  • Account data — retained for as long as your account is active. Upon an account-deletion request, personal data (name, email, avatar) is anonymized immediately under GDPR Art. 17; fiscal data is subject to a separate retention period (see below).
  • Business and financial records — data subject to tax obligations (invoices, expenses, payments, JPK/PIT filings, bank statements) is retained for 5 years counted from the end of the calendar year in which the tax payment deadline fell (art. 70 § 1 of the Polish Tax Ordinance; GDPR Art. 17(3)(b)), then permanently deleted. In practice the purge runs roughly 66 months after account deletion.
  • Audit logs — append-only (a Postgres trigger blocks updates and deletion), retained indefinitely as the permanent evidentiary record that the operations (including the account deletion itself) took place. Basis: legitimate interest — accountability and security (art. 6(1)(f) GDPR); after account anonymization the entries contain no identifying data.
  • AI chat transcripts — retained as long as your account is active; soft-deleted with the account. Anthropic retains chat content per its Commercial Terms (typically up to 30 days for abuse monitoring).
  • Session cookies — expire after 7 days of inactivity.
§ 05

Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15) — you can request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) — you can correct inaccurate data directly through the Settings page, or request a correction via email.
  • Right to erasure (Art. 17) — you can request deletion of your account and all associated data.
  • Right to data portability (Art. 20) — you can export your invoices and expenses in CSV format via the Annual Report page. You may also request a full data export.
  • Right to restrict processing (Art. 18) — you can request that we limit processing of your data in certain circumstances.
  • Right to object (Art. 21) — you can object to processing based on legitimate interest, including opting out of reminder emails in Settings.

To exercise any of these rights, contact us at shaposhnik.mcd@gmail.com. We will respond within 30 days as required by GDPR.

§ 06

Sub-processors and Data Transfers

We use the following third-party services to operate Freya:

ServicePurposeData LocationData Sent
Neon (neon.tech)PostgreSQL database hostingFrankfurt, Germany (EU)All application data (encrypted at rest)
Vercel (vercel.com)Application hosting and serverless functionsEU region (Frankfurt)Request metadata, server logs
Clerk (clerk.com)Authentication and account managementUSA (transfers covered by SCCs)Email, profile, sign-in events, session metadata
GoogleOAuth sign-in (no Google services beyond sign-in)Google Cloud (EU/US)Email and profile name (during sign-in only)
Anthropic (anthropic.com)AI chat assistant (Freya AI) and receipt OCR/parsingUSA (transfers covered by SCCs)Chat message text, receipt image bytes, the contents of uploaded PDFs (bank statements, supplier invoices) and data of documents you ask the assistant about (invoices / expenses / clients), including counterparty NIP
Stripe (stripe.com)Payment processing for paid plansUSA (with EU entity Stripe Payments Europe Ltd)Name, email, payment method tokens (no card data ever touches Freya servers)
Enable Banking (enablebanking.com)Bank feeds (PSD2 AIS) — importing your bank's transaction historyEU/EEA (licensed AISP)Account transaction history, IBAN, balances, counterparty names in payment descriptions
GoCardless (gocardless.com)Bank feeds (PSD2 AIS) — legacy integration, closed to new connectionsUnited Kingdom / EEA (adequacy decision, SCCs)Account transaction history, IBAN, balances, counterparty names in payment descriptions
Resend (resend.com)Sending deadline reminder and ops emailsUSA (transfers covered by SCCs)Email address and email content
Inngest (inngest.com)Background jobs (cron, email batching, retry queue)USA (transfers covered by SCCs, DPA — GDPR Art. 28)Email subject and recipient, internal identifiers, retry metadata
Sentry (sentry.io)Error and performance monitoringUSA (legitimate interest Art. 6(1)(f), transfers covered by SCCs)Stack traces (with PII redacted), URL paths, opaque user identifiers
Telegram (telegram.org)Reminders and notifications via the Telegram bot @FreyaTax_bot (opt-in)Telegram Messenger LLP global infrastructure (third country — no adequacy decision and no SCCs; basis: your voluntary bot connection / legitimate interest, GDPR Art. 6(1)(f) and the Art. 49(1)(a) derogation). Only internal request identifiers are sent to the ops channel — no name, email, or company data.Telegram user ID, reminder text (no invoice data or NIPs)
Vercel BlobStorage for receipt PDFs, bank statements, exportsEU (region fra1, Frankfurt)Files you upload or the service generates, access restricted via signed URLs

International transfers

Several of our processors (Clerk, Anthropic, Stripe, Resend, Inngest, Sentry) operate from the United States. Data transfers to the US are protected by Standard Contractual Clauses (SCCs) as required by Chapter V of the GDPR. Data Processing Agreements (DPAs) are in effect with each of the listed processors — each DPA is incorporated by reference into the provider's Terms of Service that we accepted at account registration, in line with the standard click-wrap acceptance procedure for B2B SaaS. Copies of the DPAs are retained internally and can be provided on request at shaposhnik.mcd@gmail.com.

Anthropic, PBC processes data solely to provide the service and — under its commercial API terms — does NOT use your data to train its models. Transfers to the US are protected by Standard Contractual Clauses (SCCs). Learn more: https://www.anthropic.com/legal/privacy.

§ 07

Cookies

Freya uses only strictly necessary cookies — without them the app cannot run. If we ever add analytics or marketing, they will activate only after your consent via the CMP banner.

  • Clerk session (__session, __client_uat, __clerk_db_jwt, clerk_active_context) — keep you signed in. Set by the Clerk auth provider. Clerk telemetry is disabled via telemetry: false.
  • Interface settings (tally-theme, landing-mode, NEXT_LOCALE) — theme, landing mode, language.
  • Document drafts (localStorage: tally:invoice-draft:v4, tally-onboarding-wizard) — keep your unfinished work locally, never sent to our server. Drafts are bound to the account and cleared on logout or when a different user signs in.
  • Cookie consent (tally-consent) — remembers your CMP choice for 365 days. You can change it anytime via the «Cookie settings» link in the footer.

We currently use no third-party analytics, ad trackers, or social-media pixels. If we ever add any, they will not run without your active opt-in under art. 173 Polish Telecom Act (transposing ePrivacy art. 5.3) and GDPR art. 7.

§ 08

Data Security

  • All data is transmitted over HTTPS (TLS 1.2+).
  • Sensitive fields (NIP, bank account numbers) are encrypted at the application level before database storage.
  • Database access is restricted to the application via connection pooling with SSL.
  • Authentication uses industry-standard OAuth 2.0 with JWT sessions.
  • All data mutations are logged in an audit trail.
  • Records are soft-deleted (never permanently removed immediately) to prevent accidental data loss.
§ 09

Right to Lodge a Complaint

If you believe that your personal data is being processed in violation of the GDPR, you have the right to lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO)

ul. Stawki 2, 00-193 Warszawa, Poland

Website: uodo.gov.pl

Phone: +48 22 531 03 00

§ 10

Changes to This Policy

We may update this Privacy Policy from time to time. The latest version is always available at this URL. Material changes will be communicated via email to registered users.

Last updated · August 13, 2026