Privacy Policy

How personal information, prompt data, and generated assets are securely protected when using Pynokio.

Pynokio Privacy & Data Protection

Version 2026-09-22 · effective 22 September 2026 · updated 5 October 2026 (named storage and speech-processing providers, section 3)

1. Controller and contact

The controller is <imię i nazwisko albo firma>, <adres>. Privacy contact: [email protected]. DPO/privacy officer contact, where appointed: [email protected].

2. Data, purposes and legal bases

3. Recipients and international transfers

Data may be disclosed only as necessary to hosting/storage, transactional email, payment, security/support and the AI provider selected for a generation. Current provider categories and transfer safeguards are described in the AI Transparency Notice. Where data leaves the EEA, the controller must use an adequacy decision, Standard Contractual Clauses and supplementary safeguards as applicable. Prompts and media are not used by Pynokio to train public foundation models unless a separate, optional opt-in is presented.

4. Retention

5. Your rights

Subject to legal conditions, you may request access, rectification, erasure, restriction, portability and objection, and withdraw consent without affecting earlier processing. A machine-readable account export and account deletion are available in account settings/API. You may complain to Prezes Urzedu Ochrony Danych Osobowych (UODO) or your local supervisory authority.

6. Automated decisions and children

Pynokio does not use account data for decisions producing legal or similarly significant effects solely by automated means. Model outputs are probabilistic and require human review. The self-service service is intended for adults. Voice cloning involving a minor requires verifiable guardian authority and enhanced review; the standard workflow must not be used to evade that requirement.

7. Security and incidents

Controls include TLS, hashed passwords and tokens, least-privilege access, private object access, short-lived signed links, audit logs, upload validation, rate limits, encrypted backups and provider allowlists. No system is risk-free. Suspected incidents should be reported immediately to [email protected]. The controller assesses notification duties under GDPR Articles 33-34.

Important: deleting an account removes or anonymises operational data and private assets. Minimal accounting, acceptance, fraud-prevention and legal-claim records may remain where retention is legally required and are access-restricted.