GDPR
Privacy policy
The Slovak version is the legally binding one. Translations into other languages are informative.
This document describes what personal data Peter Valašik processes as controller within the VNORIA service under Regulation (EU) 2016/679 (GDPR). It is based on the actual data flows of the application — with no invented vendors or retention periods.
1. Controller and contact
Peter Valašik, Obrancov mieru 2005/10, 953 01 Zlaté Moravce, Slovensko, ID No. 50058045, Tax ID 1121257951.
Contact for personal data matters: vnoria.slavic.oracle@gmail.com · +421 948 616 012.
The controller is not required to appoint a Data Protection Officer (DPO).
2. Categories of processed data (based on real features)
2.1 Account and e-mail
At sign-up we store: your e-mail address, a login identifier, optionally the name and avatar from Google/Apple sign-in, the technical time of account creation and your interface language. E-mail is used solely for authentication, transactional communication (purchases, legal notices) and to reply to your requests.
2.2 Your questions (free text)
Questions you enter into Personal Prophecy, Whisper of Dreams, Cards of Fate or other text inputs are sent to the AI model (Google Gemini via the Lovable AI Gateway) and stored in your Book of Fate. If such texts may contain data about health, sex life, sexual orientation, faith or mental state, we process them only based on your explicit, separate consent (Art. 9(2)(a) GDPR).
Exact wording of the consent (v1): “I expressly consent to the processing of sensitive data I voluntarily provide, solely to generate the requested reading and store it according to my settings.”
2.3 Book of Fate
A private timeline of your readings, notes, favourite symbols and ratings. Access is limited to your own account (Row-Level Security). You can delete a single entry or reading at any time — open it in the Book of Fate and use the “Delete” button. Full deletion is available in Account → Privacy.
2.4 Generated readings
AI outputs (reading text, symbols, card image) are stored together with your question. If you have turned off memory storage in your account, readings are not fed into any long-term context.
2.5 Payment data
Payments are processed exclusively by Stripe. We only store the transaction identifier, amount, currency, product, status (paid/refunded), type (one-off/subscription) and time. We never store your card number, CVV or bank details.
2.6 Security logs
IP address, timestamp and browser header are processed short-term for rate-limiting, protection against attacks and auditing account changes. Legal basis: legitimate interest — service security (Art. 6(1)(f)).
2.7 Cookies and analytics
Before your consent we only run strictly necessary cookies (sign-in, language, storing the consent itself). Google Analytics 4, any marketing pixels and other optional analytics are loaded only after your explicit consent. Details and management: Cookies.
2.8 Support communication
Messages from the contact form, complaints, withdrawal statements and GDPR requests are stored together with your identification (name, e-mail) and content so we can handle them and prove lawful processing.
3. Purposes and legal bases
- Providing the service and performing the contract — Art. 6(1)(b) (account, readings, payments).
- Legal obligations — Art. 6(1)(c) (accounting, complaints, withdrawals).
- Legitimate interest — Art. 6(1)(f) (security, prevention of misuse).
- Consent — Art. 6(1)(a) (analytics cookies, newsletter, blog analysis) and Art. 9(2)(a) for special categories (sensitive data in free text).
4. Recipients and processors
Actually active processors:
- Supabase Inc. — database, authentication, storage of accounts and the Book of Fate. Location: EU (Frankfurt, Germany). Policy.
- Cloudflare, Inc. — application hosting, serverless runtime (Workers), CDN and attack protection. Location: global network, primarily EU regions. Transfer: Standard Contractual Clauses (SCC). Policy.
- Stripe Payments Europe, Ltd. — payment processing, subscription management, payment receipts. Location: Ireland (EU), global Stripe infrastructure. Transfer: SCC. Policy.
- Google LLC — Gemini API (via Lovable AI Gateway) — generation of AI readings. Inputs are not used for model training. Location: USA / global Google infrastructure. Transfer: SCC. Policy.
- Lovable, Inc. — AI Gateway — proxying AI model calls and aggregating usage metering. Location: EU / USA. Transfer: SCC. Policy.
- Google Ireland Ltd. — Google Analytics 4 — anonymised traffic analytics; loaded only after consent. Location: EU / USA. Transfer: SCC. Policy.
5. Transfers outside the EU/EEA
Some infrastructure (Google/Gemini, Cloudflare, Stripe, Lovable AI Gateway, GA4) may process data outside the EU/EEA. Any such transfer is always secured by Standard Contractual Clauses (SCC) under Art. 46 GDPR entered into with the processor.
6. Retention periods
- Account and e-mail: until account deletion, then 30 days for technical backups.
- AI readings and Book of Fate: stored in your Book of Fate until you delete them or close your account.
- Accounting documents: 10 years from the end of the accounting period (Slovak Accounting Act).
- Contact messages: 12 months from the last communication.
- Consents (including sensitive data): for the duration of your account + 3 years to demonstrate consent.
- Security logs: 30 days, then deleted or aggregated.
- Cookies: see Cookies.
7. Your rights
- Right of access, rectification, erasure (“right to be forgotten”) and restriction of processing.
- Right to data portability (JSON export directly in your account).
- Right to object to processing based on legitimate interest.
- Right to withdraw any consent at any time — free of charge and with no impact on your access to the service.
- Right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
Practical tools: data export and account deletion, GDPR request form, withdrawal of individual consents.
8. Blog analysis — separate voluntary opt-in
Off by default. Without your consent we do not use your entries for any blog analysis. If you grant consent, these rules apply: historic entries from before consent are not used; raw texts or excerpts are never fed into analytics; we only store broad anonymous categories and counts; a category cannot be traced back to a specific user; once you withdraw consent we stop using data for this purpose. Refusal has no impact on your access to the service.
Exact wording (v1): “I consent to Vnoria analysing the content of my entries solely to create anonymous aggregated topics for the blog. My texts, identity and direct quotations will not be published.”
9. Newsletter
Off by default. You are subscribed only after ticking a separate, pre-unchecked box. Every e-mail contains a free unsubscribe link; you can also unsubscribe in Account → Privacy.
Exact wording (v1): “I consent to receiving the VNORIA newsletter to my e-mail address. I may withdraw this consent free of charge at any time via the link in every e-mail or in my Account.”
10. AI and automated decision-making
The application uses generative AI (Google Gemini via Lovable AI Gateway) to create text readings, dream interpretations and symbols. Under the AI Act you are communicating with an AI system and the outputs are machine-generated. We do not carry out automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. Outputs are informational and reflective — they do not provide medical, legal, financial or comparable professional advice. Details: AI information.
11. Security
We use encrypted communication (HTTPS/TLS), separated roles, strict RLS policies in the database (each user sees only their own records), regular backups and auditing of critical changes. Administration access is protected by strong authentication.
12. Children
The service is not intended for persons under the age of 16.
13. Changes
We may update this document. The version and effective date are shown in the header and footer of the document. We will notify you of material changes by e-mail or in the application.