Privacy Policy
This Privacy Policy explains how gottaSay ("we", "us", or the "Service") collects, uses, and protects personal data when you use the Service available at gottasay.app.
The Service is operated from the Republic of Serbia. This policy is written to comply with the Serbian Law on Personal Data Protection(Zakon o zaštiti podataka o ličnosti, "ZZPL") and, where applicable, the EU General Data Protection Regulation ("GDPR").
1. Who we are
The Service is operated by Altimcode, registered in the Republic of Serbia, tax identification number (PIB) 108662389, company registration number (matični broj) 63609960. Altimcode is the data controller for the personal data described in this policy. You can reach us at contact@gottasay.app, and that is the address to use for any request under this policy.
2. Information we collect
When you create an account (box owner): your email address, display name, and unique account identifier, provided to us by your sign-in provider (Google, GitHub, or LinkedIn). We also store any preferences you set within the Service.
When you subscribe to a paid plan:which plan you are on, when it renews, and the customer and subscription identifiers our payment provider assigns you. Your card details are entered on the payment provider's own checkout and never reach our servers.
When you create a box: the questions, prompts, response options, and settings you configure. This includes any follow-up question you choose to ask after an answer, and any link you choose to point people at afterwards, such as a review page.
When you share a box: the email address you enter for the person you are inviting, the access level you give them, and whether the invitation is still outstanding. If that person has no gottaSay account yet, we keep the address until the invitation is accepted, declined, or withdrawn, so that it can be matched to their account if they sign up.
When someone responds to a box: the content of the response — free-form text, a selected option, or a rating — and, where the box asks a follow-up question, the answer given to it. Both are stored together as a single response. Responses are submitted without sign-in, and we never ask a responder for their name, email address, or any other identifying detail.
A box may also finish by offering a link to another site, such as a review page the box owner has chosen. Following that link is optional, we do not record whether anyone does, and nothing about the response is passed to the site it leads to. Once there, that site's own terms and privacy policy apply, and anything written on it is outside gottaSay and is not anonymous in the way a response here is.
On boxes owned by a paid account we also record, alongside the response, a small set of coarse attributes derived from the request: the country the network resolves to, whether the device is a phone, tablet, or desktop, the operating system and browser name, and the hostname of the page the link was followed from. We do not store the responder's IP address alongside the response, and we do not combine these attributes into a profile or use them to link one response to another. The box owner, and anyone that owner has shared the box with, can see them, summarised as country, device, browser, and traffic-source breakdowns.
Automatically: server logs containing IP address, browser user agent, request timestamps, and pages requested. We use essential session cookies to keep you signed in. We do not use advertising or third-party tracking cookies.
Site analytics: we use Vercel Web Analytics on every page of the Service, the public response pages included, to count page views and see which pages and referring sites bring people here. It records the page visited, the referring site, and coarse country, operating system, browser, and device-type information. It sets no cookies and reads nothing already stored in your browser, and it does not retain IP addresses. Repeat views within a day are recognised by a short-lived value derived from the request, which is not used to build a profile or to identify anyone.
If you connect an AI provider (box owners, optional): the provider you choose (OpenAI, Anthropic, or Google) and an encrypted copy of the API key you supply for it. We use this key only to fulfil the AI requests you initiate, which today are response summaries and sorting responses by sentiment.
3. Why we process this data
- Contract performance — to create your account, store your boxes, and deliver responses to you.
- Legitimate interests — to keep the Service secure, prevent abuse, understand how the Service is used through the cookie-free site analytics described above, and improve the product.
- Consent — where the law requires consent for a particular purpose, we will ask for it first. Nothing described in this policy relies on consent today.
- Legal obligation — where we are required to retain or disclose information under applicable law.
4. Who we share data with
- Sign-in providers — Google, GitHub, and LinkedIn. When you sign in with one of them, that provider receives information about your interaction with the Service in accordance with its own privacy policy.
- People a box is shared with — if a box owner invites someone to a box, that person sees the box and every response submitted to it, including the attributes described in section 2, for as long as their access lasts.
- Infrastructure providers — we use third-party services to host the application and store data, including Vercel (hosting, and the site analytics described in section 2) and Neon (database hosting). These providers act as processors on our behalf under appropriate contractual safeguards.
- Payment provider — paid subscriptions are handled by Paddle, which acts as the merchant of record for the purchase. We pass it your email address so the subscription can be matched to your account. It collects your payment and billing details directly from you and processes them under its own privacy policy.
- Email provider — we use Resend to send account email, such as the welcome message after your first sign-in. It receives the recipient address and the contents of that message.
- AI providers (only if a box owner opts in) — if a box owner connects an OpenAI, Anthropic, or Google API key and asks for a summary or for their responses to be sorted by sentiment, the responses submitted to that box are sent to the provider they chose for processing. This only happens when the box owner takes that action; we do not send response content to an AI provider otherwise. Each provider processes that data under its own privacy policy, not ours.
- Law enforcement and authorities — only where required by valid legal process.
We do not sell personal data.
5. International transfers
Personal data may be transferred to and stored in countries outside the Republic of Serbia, including in the European Economic Area, the United Kingdom, and the United States, by our infrastructure, payment, and email providers, and, where a box owner opts into the AI features, by the AI provider they connect (OpenAI, Anthropic, and Google are all based in the United States). Where we transfer personal data abroad, we apply appropriate safeguards as required under ZZPL and, where applicable, GDPR.
6. How long we keep data
- Account information: while your account is active, deleted within a reasonable period after account closure.
- Boxes and responses: kept until you delete them or close your account.
- AI provider API keys: kept, encrypted, until you remove them in your account settings. Generated summaries are kept until you regenerate them or delete the box.
- Outstanding box invitations: kept until the invitation is accepted, declined, or withdrawn by the box owner.
- Billing records: subscription and payment records are kept for as long as we are required to retain them for tax and accounting purposes.
- Server logs: typically retained for up to 90 days for security and abuse-prevention purposes.
- Backups: residual copies may persist in encrypted backups for a limited additional period before being overwritten.
7. Your rights
Where your personal data is processed by us, you have the right to:
- access the data we hold about you;
- request correction of inaccurate data;
- request deletion (the "right to be forgotten");
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (Poverenik), or, if you are in the EU/UK, with your local data protection authority.
To exercise these rights, contact us at contact@gottasay.app.
8. Children
The Service is not intended for children under the age of 15. We do not knowingly collect personal data from children under 15. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. No system is perfectly secure, and we cannot guarantee absolute security.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Material changes will be communicated through the Service.