Back

MODALITY.INK – PRIVACY POLICY

Last updated 16 June 2025


1 Who We Are

Controller: JB Jerzy Balcerzak, NIP 9471951277
Bluszczańska 30 D/12, 00-712 Warsaw, Poland
Contact (general & privacy): contact@modality.ink
Data-Protection Officer (DPO): Jerzy Balcerzak contact@modality.ink


2 Scope

This Policy explains how we collect, use, share, and protect personal data when you use Modality.Ink (the “Service”). It applies to all users aged 18 or older. We do not knowingly provide the Service to children.


3 What Data We Collect

CategoryExamplesSource
Account DataName, email, Google profile imageYou / Google Sign-In
Usage DataGenerated Articles, upload history, feature interactionsAutomatically
Payment DataLast four digits of card, billing address, Stripe customer IDStripe
Support DataMessages sent via Crisp chat or emailYou
AnalyticsPseudonymous page views & events (no cookies)Umami

We do not collect special-category data (e.g., health or biometric data).


4 Why & On What Legal Basis We Process Data

PurposeLegal basis under GDPR
Provide and maintain the Service (create Articles, manage Credits, authenticate users)Contract performance (Art. 6 (1)(b))
Process payments and prevent fraudLegitimate interests (Art. 6 (1)(f)) & legal obligation for accounting (Art. 6 (1)(c))
Send operational emails (receipts, service updates)Contract performance
Send optional marketing newslettersConsent (Art. 6 (1)(a)) – you may withdraw at any time
Improve the Service (analytics, debugging)Legitimate interests
Comply with legal requests and tax obligationsLegal obligation
Technical Cookies (chat session management)Legitimate interests (Art. 6 (1)(f)) – session cookies (e.g., crisp-client/*) used to maintain chat state across pages or visits; do not track behavior.

5 Marketing Communications

We may occasionally email product news or promotions if you have opted in (e.g., a checkbox at sign-up). You can unsubscribe at any time via the link at the bottom of each message or by emailing contact@modality.ink.


6 Retention Periods

Data setRetention rule
Account dataStored while the account is active and deleted 30 days after you request account deletion or after 24 months of inactivity
Uploaded Materials & generated ArticlesStored until you delete them or delete your account
Payment & invoicing records7 years (tax law)
Back-upsEncrypted, stored in GCP for 1 year, then securely purged
Server logs & Umami analytics30 days, then aggregated or deleted
Support tickets24 months after resolution

7 Where We Store & Process Data

  • Google Cloud Platform (GCP) – us-central (Iowa, USA)
  • Stripe – USA & EEA
  • OpenAI, Google Gemini, Anthropic APIs – USA
  • Crisp – EU (France) datacentres

Because some providers are outside the European Economic Area (“EEA”), personal data may be transferred internationally. We rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • The provider's certification under an adequacy mechanism (e.g., EU-US Data Privacy Framework, where applicable).

Copies of SCCs are available on request.


8 Third-Party Recipients

RecipientRole
Stripe Payments Europe Ltd.Payment processing & fraud prevention
Google Cloud PlatformHosting, storage, back-ups
OpenAI LLC, Google LLC, Anthropic PBCAI model inference (content generation)
Crisp IM SASCustomer chat & support
Umami (self-hosted)Cookieless analytics

We share only the minimum data needed for each purpose.


9 Cookies & Similar Technologies

  • Umami: runs cookieless; no personal cookies.
  • Stripe & Crisp:set strictly necessary cookies to enable payment processing and chat functionality. These cookies are used solely for technical purposes (e.g., session continuity, fraud prevention) and are not used for behavioral tracking. You can block cookies via your browser settings, but chat and payments may not function properly.

You can block cookies via your browser settings, but payments or chat may not function.


10 Security Measures

  • TLS 1.2+ encryption in transit
  • AES-256 encryption at rest on GCP
  • Least-privilege, role-based access and MFA for admin accounts
  • Automated back-ups with integrity checks
  • Regular dependency patching and infrastructure hardening
  • Annual penetration testing and vulnerability scans

11 Automated Decision-Making

The Service generates Articles only when you request it. We do not perform automated decision-making that produces legal or similarly significant effects on you.


12 Your Rights (GDPR & UK GDPR)

You may exercise the following rights by emailing contact@modality.ink:

  1. Access – obtain a copy of your personal data.
  2. Rectification – correct inaccurate data.
  3. Erasure – request deletion (“right to be forgotten”).
  4. Restriction – limit processing under certain conditions.
  5. Portability – receive data in a structured, machine-readable format.
  6. Objection – object to processing based on legitimate interests or direct marketing.
  7. Withdraw consent – at any time, for marketing emails.

We will respond within 30 days. You also have the right to lodge a complaint with the relevant data protection authority in Poland or your local supervisory authority.


13 CCPA Notice (California Residents)

Modality.Ink is not currently a “business” under the California Consumer Privacy Act, but we voluntarily extend comparable rights of access and deletion. We do not sell or share personal data as defined by the CCPA.


14 Changes to This Policy

We may update this Policy from time to time. Material changes will be emailed to registered users at least 7 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.


15 Contact Us

For questions about this Policy or your personal data, email us at contact@modality.ink


© 2025 Modality.Ink. All rights reserved.