PRIVACY POLICY

Effective date: 1 September 2026

Data controller: DADDY FREUD S.R.L., Str. Petre Tutea nr. 24, Oradea, Bihor County, Romania. Contact: hello@daddyfreud.com

This Privacy Policy explains how Daddy Freud S.R.L. ("we") collects, uses, discloses, and protects personal data when you use daddyfreud.com and the related services (the "Service"), in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable Romanian data protection law.

1. Data collected

Data you provide:

  • Account data: name, email address, password (stored encrypted, as a hash).
  • Billing data: billing name and address. Full card numbers are collected and processed directly by Stripe and are never stored on our servers.
  • AI input data: prompts, texts, and files submitted to the AI Features, as well as the results generated for you.
  • Integration data: when you connect third-party accounts through the Composio-powered integrations, we receive account identifiers and the content needed to perform the requested actions. OAuth credentials are managed by Composio.
  • Communications: messages and support requests sent to hello@daddyfreud.com.

Data collected automatically:

  • Usage data: pages viewed, features used, timestamps, referral URLs.
  • Log data: IP address, browser type, operating system, device identifiers, approximate location derived from IP.
  • Cookies and similar technologies: see Section 4.

3. AI processing

The AI Features are provided through Vercel AI Gateway, which routes requests to OpenAI, L.L.C. When you use the AI Features:

  • Prompts, input data, and related metadata are transmitted to OpenAI to generate results, and the results are returned to you.
  • By default, at the API/business level, OpenAI does not use input and output data to train models and retains it for up to approximately 30 days for abuse monitoring purposes.
  • The provider's practices may change; its policy governs its processing. Do not transmit confidential or special-category data through the AI Features unless you accept such processing.

4. Cookies

We currently use only strictly necessary cookies — for these, consent is not required under GDPR/ePrivacy. Our analytics (Vercel Analytics) are cookie-less and do not collect personal data.

CookieSet byPurposeDuration
__cf_bmCloudflareBot management30 minutes
cf_clearanceCloudflarePassing security checksup to 30 days
__stripe_mid / __stripe_sidStripeFraud prevention1 year / 30 minutes
_vercelVercelRequest routing (not tracking)session

You can block or delete cookies from your browser settings; blocking strictly necessary cookies may affect the functioning of the Service. If we ever add non-essential cookies, we will obtain your consent first through a banner.

5. Providers and sub-processors

We share data with the following sub-processors, each under data protection contractual clauses:

ProviderRoleData processedPrivacy policy
Stripe, Inc. (US)Payments, fraud preventionCard data, billing datastripe.com/privacy
Vercel, Inc. (US)Hosting, logs, Vercel AI GatewayIP address, request logs, AI prompts and resultsvercel.com/legal/privacy-policy
Cloudflare, Inc. (US)CDN, DDoS/bot protectionIP address, request metadatacloudflare.com/privacypolicy
Composio (US)OAuth store, integrationsOAuth tokens, integration data, action datacomposio.dev/privacy
OpenAI, L.L.C. (US)AI model inferencePrompts, input and output dataopenai.com/policies/privacy-policy

We also disclose data: (a) to comply with the law or legal process; (b) to protect our rights, property, or safety; (c) in connection with a merger, acquisition, or sale of assets, with notice; (d) at your request.

6. International data transfers

Our providers process data mainly in the United States. Stripe, Vercel, and Cloudflare are certified under the EU–US Data Privacy Framework, and all listed providers offer EU Standard Contractual Clauses in their data processing agreements. Appropriate safeguards apply to all transfers; details are available on request.

7. Retention periods

  • Account data: for the lifetime of the account, plus 30 days after deletion.
  • Billing and transaction records: up to 10 years, under Romanian accounting and tax law (Law no. 82/1991).
  • AI prompts and results: for the lifetime of the history in your account; provider-level logs for up to ~30 days.
  • Server and security logs (Vercel, Cloudflare): up to 30 days.
  • Backups: rotating, ~30 days, then overwritten.

8. Security

We use TLS encryption in transit, encryption at rest where applicable, access controls, and vendor security reviews. Stripe is PCI DSS Level 1 certified. No system is 100% secure and we cannot guarantee absolute security.

9. Your rights (GDPR)

You have the right to:

  • access your personal data (Art. 15)
  • rectification of inaccurate data (Art. 16)
  • erasure of your data (Art. 17)
  • restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interest (Art. 21)
  • withdraw consent at any time, without affecting prior processing (Art. 7(3))

To exercise any right, write to hello@daddyfreud.com. We will verify your identity and respond within one month.

You also have the right to lodge a complaint with our supervisory authority: the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, Romania — https://www.dataprotection.ro.

10. Minors

The Service is not directed at children under 16 years of age (the digital age of consent in Romania) and we do not knowingly collect their data. If you believe a child has provided us with data, contact us and we will delete it.

11. Policy changes

We will publish changes here and update the effective date. Substantial changes affecting your rights will be notified at least 14 days in advance, where required.

12. Contact

DADDY FREUD S.R.L.

Str. Petre Tutea nr. 24, Oradea, Bihor County, Romania

hello@daddyfreud.com