Informativa Privacy
PRIVACY POLICY — SayPhant
(pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 — "GDPR" — and of Italian Legislative Decree 196/2003)
Version 1.0 — effective from 3 October 2026
This policy explains how we process your personal data when you use the SayPhant app. "SayPhant" is the name of the app; the person who decides how and why your data is processed ("we", the controller) is the person indicated in section 1.
1. DATA CONTROLLER
The data controller is:
Stefano Gabriele Tagliabue
Email: sayphant.com@gmail.com
Certified email (PEC): tagliabue.stefano82@pec.it
To exercise your rights or for any question about privacy, you can write to the email or PEC address above. Registered users can also contact us from the support chat in Settings → Support.
Data Protection Officer (DPO): not designated, as it is not mandatory for this service (Art. 37 GDPR). For any privacy matter you can write directly to the contacts above.
2. WHAT DATA WE COLLECT
a) Data provided at registration
- First name, surname, email address and password: they are necessary to create the account; without them we cannot provide the service.
- Password: stored exclusively as a non-reversible hash (we do not keep it in plain text). The server receives it, over an encrypted connection, when you register, log in or reset it, in order to verify it and to manage the protection of your documents.
- Date of birth: requested at registration solely to verify the age requirement (section 9). The app uses it only for this calculation and does not keep it.
b) Content you create or upload
- Events, reminders, deadlines, recurrences and notes
- Photographed or imported documents (photos, PDFs) and the data we automatically extract from them: title, category, supplier, address, amounts, dates, serial numbers, expense items, notes and the document text (OCR)
- Voice dictation recordings (forwarded to the transcription provider) and the related transcripts
- Requests written or dictated to the AI assistant, generated replies and the history of interactions
- Messages you send us through support
This content may also concern other people (for example family members): enter it only if you have the right to do so.
c) Technical and usage data
- Push notification token (FCM), app language and country (if not provided by the app, inferred from the language, currency and price of your store), time zone, platform and app version
- App installation identifier: sent at first launch, before registration, and linked to your account when you register
- Usage log: sign-ins, app openings and closings with session duration, taps on notifications, deletion of events, date of last activity
- Installation check: once a week we send a silent notification to understand whether the app is still installed
- Technical server logs for operation and security (IP address, date/time of requests, services used and response times, any errors). The logs do not contain the texts of your requests, dictation transcripts or notification contents
- Notification delivery telemetry (delivery outcome, for diagnostic purposes); for notifications sent by the server it may include the reminder title
- Free trial data and, when available, subscription data (plan, start and end dates, transaction identifiers received from the stores; not payment details)
- "Invite a friend" programme: your referral code, who invited you, completed invitations and accrued rewards
d) Special categories of data (Art. 9 GDPR)
We do not ask you for health data or other special categories of data. However, the documents, notes, events, voice recordings and requests to the assistant that you voluntarily choose to enter may contain them: for example medical documents, prescriptions, test results, medical appointments, but also information about religion, sexual orientation, political opinions or trade union membership. We process this data only because you enter it, on the basis of the explicit consent (Art. 9.2.a GDPR) that you can give at registration or later in Settings → AI Features. Without this consent you can use the app with manual diary, events and notes, but the AI features (dictation, assistant, document analysis) remain disabled. You can withdraw your consent at any time in Settings → AI Features, choosing whether to keep or delete the uploaded content, or by writing to the contacts in section 1 or by deleting your account. Withdrawal immediately disables the AI features and deletes the history of AI interactions, the text extracted from documents (OCR), expense items and extracted structured data; title, supplier, address, amounts, dates and notes of documents remain until you delete them yourself. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
3. WHY WE PROCESS DATA (PURPOSES AND LEGAL BASES)
a) Provision of the service (account, diary, synchronisation, search, reminders and notifications, document archive; AI assistant, voice dictation and document analysis only with the consent under letter b): performance of the contract (Art. 6.1.b).
b) Special categories of data possibly contained in your content: your explicit consent (Art. 9.2.a).
c) Free trial and subscriptions managed by the stores (Google Play / App Store): performance of the contract (Art. 6.1.b); payment details are processed by the stores.
d) Support: answering your requests and, if needed to solve a problem, consulting your content: performance of the contract (Art. 6.1.b) and, for any special categories of data, the consent under letter b). If you write to support in a language other than Italian and you have active AI consent, the message may be automatically translated via Alibaba Cloud to facilitate the reply; without consent no translation takes place and the message stays in your language.
e) Security, abuse prevention, limitation of fraudulent access attempts, recording and resolution of errors: legitimate interest in protecting the service and the users (Art. 6.1.f).
f) Operation of notifications (delivery telemetry, checking tokens that are no longer valid): legitimate interest in making the service you requested work (Art. 6.1.f).
g) Service usage statistics (usage log, installation counts) and the "Invite a friend" programme: legitimate interest in understanding and improving the service, on technical data and not on the content of your documents (Art. 6.1.f). Quality control of the AI assistant and service improvement are carried out on pseudonymised interactions, with no direct reference to your identity: legitimate interest (Art. 6.1.f).
h) Legal obligations (tax, accounting, requests from authorities): legal obligation (Art. 6.1.c). Proof of consents and defence in court: legitimate interest (Art. 6.1.f).
For processing based on legitimate interest (letters e, f, g) you have the right to object (see section 8).
We do not advertise, we do not sell data and we do not use it to profile you for commercial purposes. The AI assistant automatically extracts and proposes dates, amounts, categories and reminders, but we do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR); you can always correct or delete the extracted data. You are interacting with an artificial intelligence system, not with a person. The AI can make mistakes: always check important dates, amounts and deadlines (medical, legal, fiscal).
4. HOW WE PROTECT YOUR CONTENT
- Documents and photos: they are encrypted with AES-256 before being saved to storage. They remain encrypted in storage and the storage provider cannot read their content. The encryption is not "end-to-end": for AI analysis the document content is sent, over an encrypted connection, to the AI provider that processes it, and for search, reminders and the assistant the server processes in plain text the data described in the following point.
- Data processed in plain text by the server: title, category, supplier, address, amounts, dates, serial numbers, expense items, notes, text extracted from the document (OCR), texts of events, unprotected reminders and notes, transcripts and history of requests to the assistant. They are necessary for the service to work (search, reminders, assistant replies) and are also present in backups (section 7).
- Protected notes: encrypted with a key derived from your password.
- Password: stored only as a non-reversible hash.
- All app-server communications take place over an encrypted connection (HTTPS/TLS).
- Access by the controller: the administrative console shows technical and usage statistics (counts, tokens consumed, costs, account activity) without content. Quality control and error analysis are carried out on pseudonymised views, with no direct reference to your identity. The controller may consult your content and the history of interactions in identifiable form only for technical support, troubleshooting and security issues: access takes place through an explicit action and every consultation is recorded in an audit log (who consulted what and when). Content is not consulted for other purposes nor communicated to third parties.
5. WHO RECEIVES YOUR DATA
Processors (Art. 28 GDPR), with whom we have entered into data processing agreements:
Essential services:
- DigitalOcean (server in London, UK): hosting of the server and the database.
- Cloudflare R2: storage of the encrypted files.
- Brevo (formerly Sendinblue SAS, France): sending of service emails (e.g. password recovery). It processes your email address, the message content and delivery data.
- Google Firebase Cloud Messaging (FCM): delivery of push notifications. It processes the device token and the notification content (title and text of the reminder) for the time necessary for delivery.
AI providers (they process only the content of the features you use):
- Alibaba Cloud — workspace configured in the Frankfurt region (EU): analysis of texts (events, reminders, searches, requests to the assistant) with the Qwen model; analysis of document images in case the main service is unavailable (Qwen-VL model); automatic translation of support messages when you have active AI consent; administrative analysis by the controller on technical and pseudonymised data (user identifiers are replaced by codes that cannot be traced back to identity).
- Google Cloud Vertex AI — EU region (Milan, europe-west8): main service for analysing document photos; backup service for voice transcription.
- Nebius B.V. (Netherlands, Finland region): backup text processing if the main service does not respond; the Zero Data Retention option is active.
- Groq Inc. (USA): main service for voice transcription; Zero Data Retention is active (the audio is not stored by Groq).
Under the applicable contractual terms, AI providers do not use your content to train their models.
Independent controllers:
- Google Play and Apple App Store: they manage purchases, payments and subscription refunds according to their own policies; they do not act on our behalf.
- Google Fonts: provides the typefaces used by the app, which are downloaded from Google's servers on first use (see section 11).
You can ask us for the updated list of processors. If we change the providers that process your content, we update this policy and notify you in the app.
6. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
The server and the database are in London; the United Kingdom is covered by an adequacy decision of the European Commission (Implementing Decision (EU) 2021/1772, renewed by Decision (EU) 2025/2574 until 27 December 2031). Analysis of document photos takes place in Milan. Some providers, however, are non-EU companies or belong to groups headquartered outside the EU, and we cannot rule out access from third countries (for example for technical support or security). Here are the cases and the safeguards:
- Groq Inc. (USA): only the audio of dictations, with Standard Contractual Clauses and Zero Data Retention.
- Alibaba Cloud (group headquartered outside the EU): texts and, as a backup, document images, processed by the Frankfurt workspace; for any access from third countries the contractual safeguards agreed with the provider apply (Standard Contractual Clauses).
- US companies of DigitalOcean, Cloudflare and Google: covered by the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
- Push notifications (FCM): Google's global infrastructure, also in the USA.
You can obtain a copy of the applicable safeguards by writing to the contacts in section 1.
7. HOW LONG WE KEEP DATA
- Account and content (events, documents, notes and extracted data): for as long as you keep the account. If the account remains inactive for more than 24 months it is deleted automatically; we notify you by email 30 days beforehand and a single login is enough to cancel the deletion.
- Interactions with the AI assistant: the texts of requests and replies are deleted after 90 days; only the technical counts per user remain (number of calls, tokens, response times) used for statistics and cost control.
- Usage log (sign-ins, app openings, session durations, actions performed in the app): for as long as you keep the account.
- Notification telemetry: 12 months.
- Anonymous aggregate monthly statistics (e.g. number of active users, events created, AI calls): kept indefinitely; they contain no personal data.
- Installation records not linked to an account: 90 days.
- Encrypted files in storage: as long as the document exists; files are deleted from storage when the document or the account is deleted.
- Content deleted by you: when you delete an event, a document or a note, the content is no longer accessible in the app and the associated files are deleted from storage; the technical record remains marked as deleted for a maximum of 30 days and is then permanently erased.
- Technical server logs (access and diagnostics, without the texts of requests): automatically deleted within 14 days.
- Internal error records (administrator console): 90 days, accessible only to the controller.
- Audit log of administrative accesses and the record of completed account deletions: 24 months.
- Acceptance data for legal documents and consents: date and version of each acceptance, grant, refusal or withdrawal, for as long as you keep the account.
- Accounting and tax data: for the period required by law (10 years).
- Service emails: the provider (Brevo, EU) keeps delivery logs for the period set out in its own policy.
- Backups: the automatic server backup is managed by DigitalOcean and kept for up to 28 days; we also make daily encrypted database dumps to Cloudflare R2 and keep the last 7 copies. When you delete content or your account, the data is no longer accessible in the app and is removed from the main system; backups already created are not modified and are overwritten within 28 days (server backup) and 7 days (dumps). We do not use them for other purposes.
8. YOUR RIGHTS
Right to object. You have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (section 3, letters e, f, g). Write to us at the contacts in section 1.
You also always have the right to (Arts. 15-22 GDPR):
- Access and copy: the "Download my data" function in the app (profile, events, reminders, documents, AI interactions, subscriptions); for other data concerning you (for example technical logs and the log of administrative accesses to your data) write to us.
- Rectification: edit your data from the profile and from individual items.
- Erasure: "Delete account" in Settings deletes data and files; we keep only the record of the completed deletion (a non-reversible identifier of your account, the date, the plan and the country) in the audit log, for the period indicated in section 7. You can also delete individual items.
- Portability: the export is in readable formats (JSON; original documents).
- Restriction: write to us at the contacts in section 1.
- Withdrawal of consent for special categories of data: from Settings → AI Features (with the choice of keeping or deleting the uploaded content), by writing to the contacts in section 1, or by deleting the content or the account; withdrawal does not affect processing already carried out.
- Complaint: you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome) or with the supervisory authority of the EU country where you habitually reside, work or where the alleged infringement occurred, and take legal action before the courts, including where you reside.
How we respond: without unjustified delay and in any case within one month of the request; this period may be extended by two months if the request is complex or we receive many, and in that case we will inform you within the first month. Requests are free of charge, unless they are manifestly unfounded or excessive. To protect your data we may ask you to confirm your identity, normally by writing from the email address of the account.
9. MINORS
The service is reserved for people aged at least 14. In Italy, 14 is the minimum age for consenting on one's own to the processing of personal data for online services (Art. 2-quinquies of Italian Legislative Decree 196/2003) and for the use of artificial intelligence systems (Art. 4(4) of Law 132/2025). At registration we ask for your date of birth to verify the requirement: if you do not have the required age, registration is not possible. In other EU countries the minimum age may be higher (up to 16): if you live in one of those countries you can use the service only with the authorisation of a person who holds parental responsibility. If we learn that an account belongs to a person who does not have the required age, we suspend it and delete the related data. Parents can report this to the contacts in section 1.
10. SECURITY AND DATA BREACHES
We adopt technical and organisational measures appropriate to the risk: encryption of stored files, encrypted connections (TLS), password hashing, limitation of login attempts, audit log of administrative accesses, encrypted database dumps. No measure completely eliminates risk. In case of a personal data breach that presents a risk to your rights and freedoms, we will notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it; if the risk to you is high we will also inform you without undue delay (Arts. 33-34 GDPR). We document every breach internally.
11. COOKIES AND TRACKING TOOLS
The app does not use cookies or third-party analytics or advertising SDKs. It uses technical identifiers (notification token, installation identifier) and a usage log managed by us, described in section 2.c. The typefaces (fonts) are provided by Google Fonts and are downloaded from Google's servers on first use: on that occasion Google receives the device's IP address, without any other user data. The service's web pages (e.g. password reset) use only technical session and security cookies, which do not require consent.
12. CHANGES TO THIS POLICY
If we update this policy we will notify you in the app. For substantial changes we will ask you to confirm that you have read them and, if the change requires a new consent (for example for new purposes), we will ask for it separately. We keep the date and version of each acceptance of the legal documents and of each user's consents.
CONTACTS
Controller: Stefano Gabriele Tagliabue — Email: sayphant.com@gmail.com — PEC: tagliabue.stefano82@pec.it