obligacje.io

Version 2026-10-07 · effective from 7 October 2026

Privacy policy

How obligacje.io processes account, session and AI-assistant conversation data.

Key information

  • The data controller is Apify Piotr Gorzelany.
  • An account requires a verified email address and a password or Google or Apple sign-in identifier.
  • We do not run marketing, newsletters or advertising profiling. Basic visit statistics are collected only with your consent.
  • Conversations are not used to train models; an authorised operator may review newer conversations to improve obligacje.io.
  • Conversations are deleted 12 months after the last message or earlier at the user's request.
  • If you connect an MCP application, the chosen application receives results of permitted calls. You can revoke access in account settings.

1. Controller and contact

The controller of personal data is Apify Piotr Gorzelany, ul. Stanisławowska 47, 54-611 Wrocław, Poland, tax ID (NIP) 6182099561.

For all privacy matters and to exercise data rights, contact obligacje-io@agentmail.to.

2. Data we process

At sign-in, Google or Apple provides an account identifier, email address, email-verification status and, where supplied, a display name and profile image. We do not receive the password for the provider account.

For email registration we receive an email address and password. The password is processed only to check it and create a salted Argon2id cryptographic hash; we do not store the plaintext password. We store email-verification status, pending registrations and hashes of single-use tokens. The link in the delivery queue is encrypted and removed after sending, revocation or expiry.

We process user and account identifiers, the accepted terms version and adult confirmation, roles, entitlements and session data. During sign-in attempts we briefly retain cryptographic hashes of the IP address and browser information to prevent abuse. For password sign-in and link delivery we also use email and IP address hashes for shared abuse-prevention limits.

When the assistant is used, we process message and answer content, current-page context, sources and tools used, and technical metadata such as time, model, provider, token count, outcome and error category. Application logs should not contain complete conversation content.

Our error diagnostics record category, deployment version, time and a technical correlation identifier. They do not send form contents, conversations, visited URLs or error stacks. Submission sampling uses a daily technical pseudonym derived from the IP address; this diagnostics store does not retain the raw IP. Aggregate reports and measurements are retained for 7 days, and rate sampling pseudonyms for 2 days. Incident history contains sanitized operational information and repair actions.

When basic visit statistics are enabled and you consent, we process a random browser identifier, its cryptographic hash, the visit date, and the consent-notice version and grant, expiry and withdrawal times. Analytics does not store IP addresses, account data, page URLs, query parameters, form contents or conversations. Identifiers are pseudonyms, not fully anonymous data.

Your private favorites list stores the bonds and issuers you choose, your user identifier and the date added. It is not shared with connected MCP applications or AI model providers.

3. Purposes and legal bases

Account, sign-in, session, terms-acceptance and conversation data is processed to enter into and perform the service contract (Article 6(1)(b) GDPR).

Technical data, limits, audit records and information needed to detect abuse are processed for the controller's legitimate interests in securing the service, diagnosing faults, establishing or defending claims and ensuring accountability (Article 6(1)(f) GDPR). On the same basis, an authorised operator may review the content of conversations started after this notice was presented when terms containing the conversation-review disclosure introduced on 18 August 2026 were accepted, to identify problems, assess answer quality and improve obligacje.io features.

Where law requires data to be kept or disclosed to an authority, the basis is compliance with a legal obligation (Article 6(1)(c) GDPR). The current service does not rely on consent for marketing or newsletters.

Your approval of connection permissions implements the integration you request (Article 6(1)(b) GDPR); evidence of access approval and technical safeguards serve accountability and security (Article 6(1)(f) GDPR).

Basic statistics measure unique daily and calendar-month visitors to assess use of the website. Storing and reading the analytics cookie requires prior consent under Article 399 of the Polish Electronic Communications Law. Consent is the basis for processing analytics data (GDPR Article 6(1)(a)). A limited record of consent and withdrawal is retained for accountability (Article 6(1)(c), in conjunction with Articles 5(2) and 7(1)).

We store your favorites list to provide it through your account across devices, on the basis of performing the contract for that feature (Article 6(1)(b) GDPR).

4. Google and Apple sign-in

Google and Apple confirm a user's identity and provide data needed to create or find an account. They also act under their own privacy terms and may independently process sign-in information.

A user may connect verified Google and Apple sign-ins to one account. For a historical technical duplicate, sign-in identifiers and conversations may be moved to the primary account and the duplicate data is pseudonymised; technical usage and audit records remain under the retention rules.

Provider connections in obligacje.io are removed when the account is deleted; permissions granted separately to a provider can also be managed in Google or Apple account settings.

5. AI assistant

The prompt, page context and necessary data or document excerpts are sent to OpenRouter, which routes the request to the model provider selected in the service configuration. The model provider may change without changing the processing purpose.

The assistant uses OpenAI GPT-6.1 Sol through OpenRouter. OpenAI may retain request and response content in abuse-monitoring logs for up to 30 days, or longer where required by law or necessary to prevent harm; zero retention does not apply to the selected endpoint. Routing denies use of conversations for training or general improvement of provider models, and application prompt logging is disabled. Conversations are stored in our own database so users can return to them and continue the context and — for conversations covered by this notice version — so the operator can improve service quality.

Conversations are not used to train models or for general improvement of provider models. An authorised operator may read content to respond to a support request, protect security, resolve a fault, or analyse and improve obligacje.io. Access requires a personal account, is limited to what is necessary and is recorded each time without copying content into the audit record. Product review does not include conversations started before this information was presented and terms containing the conversation-review disclosure introduced on 18 August 2026 were accepted.

6. MCP application connections

You can choose to connect a compatible MCP application, such as ChatGPT, Claude, Cursor or Codex, to obligacje.io. Connection approval specifies the application, account, permissions and access period. This is separate from Google or Apple sign-in identities. We retain user and account identifiers, application identifier and name, metadata URL, selected callback URL, permissions, the version of the notice shown at approval, approval, expiry and revocation times, and technical usage and abuse-prevention records.

The application sends arguments for a selected tool, such as a catalog filter, bond identifier or assistant question with necessary context, then receives that call’s result. The integration does not accept a complete external conversation transcript or disclose private obligacje.io conversation history. When our assistant is used, the question and necessary data are sent to OpenRouter and the model provider under the assistant section above; messages and usage records are created in the account.

The connected MCP application is the external application you choose to receive data. Its subsequent processing, storage location, transfers and retention depend on its provider’s policies and your settings there. Our assistant training and retention policy does not determine the external application’s policy. We do not promise deletion of copies it received when access is revoked in obligacje.io.

If the application supports renewal, it can renew access for up to 30 days from connection; otherwise its access expires after at most 15 minutes and a new connection may require approval. Signing out does not revoke approval. Account → Connected applications lets you revoke the whole connection and renewal. The approval and revocation record remains as evidence of permissions and security under technical retention rules. Pending requests expire after 10 minutes, codes after 2 minutes and individual access tokens after 15 minutes. Hashes of OAuth codes, access tokens and refresh tokens are removed after the 30-day connection period; cleanup runs in batches and may lag during an outage. Durable approval records contain no plaintext tokens or external chat content.

7. Hosting and other recipients

Railway provides application and PostgreSQL database hosting. Google and Apple provide sign-in. OpenRouter and the model provider selected through it process data required to generate an answer.

AgentMail, Inc. sends email-verification, password-reset and add-password links. It receives the recipient address, metadata and message content containing the link; it does not receive the password or its hash. We do not enable email open tracking.

A TradingView embedded chart loads automatically on bond pages. The browser therefore connects directly to TradingView, which may receive the IP address, viewed-page URL and standard browser data under its own privacy policy.

When form protection is enabled, we use Cloudflare Turnstile for registration, starting Google or Apple sign-in and sending verification or reset links. The browser connects to Cloudflare and provides technical signals such as IP address, browser and connection information and the site domain to detect automated abuse. Our backend submits the verification token without form contents, passwords or conversations. Details: https://www.cloudflare.com/turnstile-privacy-policy/.

Data may be disclosed to advisers or public authorities only where necessary to protect rights or required by law. We do not sell personal data.

Our own statistics are stored in our database hosted by Railway; we use no external analytics service. Hosting may process technical connection data, including IP addresses, separately from our minimal counter. Detailed statistics are restricted to authorised administrators. The hosting transfer provisions in section 8 apply.

8. Transfers outside the EEA

Some providers and infrastructure may process data in the United States or other countries outside the European Economic Area. This particularly concerns hosting, sign-in, OpenRouter, the model provider and TradingView. AgentMail processes email messages in the United States. Cloudflare may process technical form-protection signals outside the EEA under its data-protection terms.

Other providers describe their transfer mechanisms in their documentation, including adequacy decisions or Standard Contractual Clauses. AgentMail references a DPA in its terms; we have requested its text and clarification of US-transfer safeguards. We have not yet verified a specific mechanism for our account. Current information can be requested from the controller.

9. Cookies and analytics

Essential cookies protect sign-in, maintain sessions, provide your selected language and remember your privacy decision. Your theme choice may be stored locally in the browser. Session and application-connection protection cookies are unavailable to JavaScript; pending access-request protection lasts ten minutes.

When visit statistics are enabled, we request separate voluntary consent. The obligacje_analytics cookie holds a random identifier and is set only after you click “I agree”. It lasts 180 days. The obligacje_privacy cookie remembers only the choice and notice version for 180 days, including refusals. Refusing or making no choice does not restrict the website or start counting.

You can change or withdraw consent without signing in through “Privacy settings” in the footer. Withdrawal stops future counting, removes the analytics cookie and deletes retained visit markers for your browser. Previous aggregate counts, which contain no browser identifiers, remain. Withdrawal does not affect the lawfulness of earlier processing. The decision applies to this browser; other devices require a separate choice. Clearing cookies may cause another consent request and the same person being counted again.

We do not use advertising cookies, advertising fingerprinting, session recordings or marketing profiles. The external TradingView chart is a direct integration described above.

10. Retention

Account data is kept until the user deletes the account or the service is discontinued. Accounts are not automatically deleted merely because they are inactive.

Conversation content and related technical data are deleted 12 months after the last message. A user can delete a conversation earlier. An active session expires no later than 7 days after creation, or earlier after sign-out or account deletion.

Pending unverified registrations are deleted after 7 days. Email-verification links are valid for 24 hours and reset links for 30 minutes; both are single-use. Reset revokes all sessions, and password change revokes other sessions. Account deletion deletes password credentials and tokens.

Removing a link from our queue does not delete the email provider’s copy. AgentMail’s published policy retains messages and attachments until deletion, database recovery points for up to 35 days, metrics for up to 90 days and most logs for up to 365 days. Raw message and attachment objects and message-received logs have no configured automatic expiration. We have requested clarification of deletion of these copies; we do not promise their automatic removal when an obligacje.io account is deleted.

One-time OAuth states and abuse-prevention counters are short-lived and cleaned regularly. After account deletion, only pseudonymised records needed for security, accountability, legal obligations or defence of claims remain, and only for as long as required for those purposes.

Visit markers with browser pseudonyms are retained until the end of their calendar month, then removed in batches by a recurring task running every 15 minutes. Consent and withdrawal evidence is deleted 30 days after the end of the 180-day consent period. Aggregate counts without browser identifiers are retained for the current month and the previous 12 months. Outages or a large cleanup queue can delay recurring deletion. Backups follow the hosting retention cycle and are not used for active counting.

Removing a favorite item deletes its record from the active database. Account deletion erases the entire favorites list. Any backup remnants follow the backup retention described here and are not used to continue providing the list.

11. Account deletion and data export

An account can be deleted from the security section after a recent sign-in. Conversation content is then deleted, password credentials and pending tokens are deleted, OAuth identities are disconnected, sessions are revoked and account data is pseudonymised. Some pseudonymised records may remain under the retention rules above.

A copy of account data can be requested by emailing obligacje-io@agentmail.to from the address linked to the account. We may ask for identity confirmation before disclosure. The export is prepared manually in a commonly used format.

Browser statistics are not linked to accounts, so deleting an account does not withdraw consent for statistics. Privacy settings allow consent withdrawal and removal of retained visit markers without an account. When contacting us about your rights, do not send cookie values or tokens. We can arrange a safe way to confirm the browser; without an identifier we may not be able to locate your records. Limited consent and withdrawal evidence remains for the stated accountability period.

12. User rights

Users may request access, rectification, erasure, restriction and portability, and may object to processing based on legitimate interests. The scope of a right depends on the legal basis and processing circumstances.

Requests can be sent to obligacje-io@agentmail.to. We respond without undue delay, generally within one month, and may request information needed to confirm identity.

13. Complaint and security

A user may complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or the competent authority in the country of habitual residence, place of work or alleged infringement.

We use access restrictions, encrypted connections, hashed session tokens, request limits and other measures appropriate to risk. No online service can provide an absolute security guarantee.

14. Policy changes

This policy may change with law, providers or service features. Material changes will be announced in the service or by email before they take effect where required or practicable.

The current version and effective date are always shown at the beginning of the document.