Legal
Privacy Policy changelog
Every published version of our Privacy Policy. Material changes (new data categories, new sub-processors, changes to retention) trigger a 30-day notice via email and an in-app banner before they take effect (see §11 of the Privacy Policy).
v1.3
Effective 2026-07-23
Post-trial retention windows aligned to the 4-month (120-day) canon.
- Corrected the unfinished-trial deletion timeline to the board-approved 4-month window: final-deletion notice and automatic export at 113 days after trial end, a 7-day recovery grace beginning at 120 days, and physical deletion at 127 days (previously stated as 83 / 90 / 97 days).
- Aligned the data-retention summary to the same +127-day post-trial boundary. The canonical source of truth for all retention windows is docs/policies/content-retention-policy.md and the shared/billing/trial_lifecycle.py constants.
- Reaffirmed the always-available export path: an export is force-generated before automatic deletion unless a self-serve export was taken in the prior 30 days, and 'Export everything' is surfaced in the read-only and archive states rather than hidden in Settings.
v1.2
Effective 2026-07-22
Controller legal identity and cookie-consent / analytics opt-in.
- Recorded the controller's full legal identity: Individual Entrepreneur registration number, registration date, registering authority, and Tbilisi legal address.
- Introduced a cookie-consent banner (Accept all / Reject non-essential / Manage) and documented the optional PostHog analytics cookie, which stays off until you opt in and clears on withdrawal.
- Added PostHog to the sub-processor list and international-transfer disclosure (EU Cloud residency) and synchronised the cookie inventory across the policy.
- Noted that strictly consent-gated, off-by-default additions may take effect immediately because no processing occurs without separate consent.
v1.1
Effective 2026-07-21
Usage pricing, trial activation, and email-consent transparency.
- Added rated-usage wallets, reservations, ledger events, and provider-cost telemetry to the data inventory and retention disclosures.
- Separated optional product-nurture consent from editorial-newsletter consent; both remain off by default and independently withdrawable.
- Clarified target and legacy trial start rules and anchored post-trial retention to the persisted trial end date.
- Disclosed Paddle as the Merchant of Record for new billing and Stripe as the temporary legacy-subscription provider during migration.
v1.0
Effective 2026-05-04
Initial publication ahead of public launch.
- First public version covering data inventory, legal basis, sub-processors, GDPR rights, retention, transfers, security, and contact information.
← Back to the Privacy Policy.