Evil Twin AI
TERMS OF SERVICE, RULES FOR ELECTRONIC SERVICES, ACCEPTABLE USE TERMS AND PRIVACY POLICY
Version 1.0
Effective / last updated: 28 August 2026
print / save return to site

Terms of Service and Privacy Policy

READ THIS DOCUMENT BEFORE USING OR PURCHASING THE SERVICE. This document is intended to serve as the terms for electronically supplied services within the meaning of art. 8 of the Polish Act of 18 July 2002 on Providing Services by Electronic Means, as well as the contractual terms, acceptable-use rules and privacy notice for Evil Twin AI. Mandatory rights granted to consumers or data subjects by applicable law prevail over any inconsistent contractual wording. Nothing in this document is intended to waive a right that cannot lawfully be waived.

1. Operator, scope and contractual status

1.1. The service marketed under the name Evil Twin AI is operated by Evil Twin AI (the “Operator”, “Evil Twin AI”, “we”, “us” or “our”).

1.2. Registered / business address: must be inserted before commercial launch.

1.3. Electronic contact address: electronic contact address must be inserted before commercial launch. Privacy contact: electronic contact address must be inserted before commercial launch.

1.6. The Service includes the website, account system, subscription functionality, AI chat interface, model-routing infrastructure, generated responses, account controls and any related features made available under the Evil Twin AI brand.

1.7. These Terms apply to visitors, registered users, subscribers and business users unless a separate written agreement expressly replaces a provision.

1.8. In accordance with art. 8 UŚUDE, these Terms are made available without charge before conclusion of the electronic-services contract and in a form capable of being stored and reproduced. Users should save a copy of the version applicable when they subscribe.

2. Definitions

Account means the user account used to access authenticated features.

AI Output means text, code, summaries, suggestions, analyses or other machine-generated material returned by the Service.

Consumer means a natural person acting for purposes outside that person’s trade, business, craft or profession, including a person enjoying equivalent mandatory rights under applicable Polish or EU law.

Conversation Content means prompts, messages, attachments, feedback and outputs exchanged through the chat functionality.

Digital Service means the continuously supplied digital functionality made available through the Service.

Plan means a free, trial, Basic, Pro or other paid usage tier displayed at checkout or in the account interface.

Prohibited Use means use described in section 10 or any activity contrary to applicable law, mandatory third-party provider restrictions or binding legal orders.

Provider or Third-Party Provider means an infrastructure, hosting, CDN, model, email, authentication, payment, support, security or other technical service provider used to operate the Service.

User means any person or entity accessing or using the Service.

3. Eligibility and age

3.1. The Service is intended only for persons aged 18 or older. By creating an Account or purchasing a Plan, you represent that you are at least 18 and legally capable of entering into the agreement.

3.2. If you use the Service for an organisation, you represent that you have authority to bind that organisation. References to “you” include the organisation where appropriate.

3.3. We may refuse registration, suspend activation or request additional verification where reasonably necessary to comply with law, payment rules, sanctions restrictions, fraud prevention or account-security obligations.

4. Technical requirements and electronic service

4.1. Technical requirements include a functioning internet connection, a reasonably current browser, JavaScript support, transport-layer encryption support and, for authenticated features, the cookies or local storage strictly necessary for login, security and session management.

4.2. The User bears ordinary costs of internet access and compatible hardware.

4.3. The Service may be unavailable during maintenance, security incidents, upstream-provider outages, capacity limits or force-majeure events.

4.4. In accordance with art. 6 UŚUDE, electronic services carry risks typical of internet use, including malware, credential theft, interception attempts, phishing, account compromise and software vulnerabilities. Users should maintain updated software, secure credentials and appropriate device protection.

5. Nature of the AI service

5.1. You are interacting with an artificial-intelligence system. AI Outputs are generated probabilistically and may be inaccurate, incomplete, outdated, fabricated, inconsistent, offensive, unsuitable, legally incorrect or technically unsafe.

5.2. AI Outputs are not statements of fact merely because they are written confidently. You must independently verify important information before acting on it.

5.3. Unless separately and expressly agreed in writing, the Service does not provide legal, medical, tax, investment, accounting, engineering, safety-critical or other regulated professional advice.

5.4. The Service is not an emergency service and must not be relied upon where delay, error or unavailability could reasonably create a risk of death, bodily injury, major property damage or other serious harm.

5.5. The Service may use multiple underlying models, routing systems or Third-Party Providers. A particular model, provider, response style, context length, feature or level of availability is not guaranteed indefinitely.

6. Marketing language, fictional branding and no promise of unlawful functionality

6.1. Evil Twin AI uses provocative branding, satire, hyperbole, fictional crime imagery, black comedy and slogans intended to communicate a less sterile conversational style. Illustrations may depict fictional or absurd scenarios involving hacking, fictional malware, fictional criminal characters, money-laundering puns, laboratory props, weapons, fictional evidence cleanup, rebellious conduct or similar themes.

6.2. Such branding is expressive and promotional. It is not an instruction, approval, invitation, authorisation, procurement offer, conspiracy, endorsement of unlawful conduct or representation that the Operator will facilitate a crime.

6.3. Phrases such as “uncensored”, “no refusals”, “doesn’t refuse”, “no filters”, “anything”, “evil”, “unrestricted”, “forbidden”, “sketchy”, “no lectures” or similar promotional language, if used, are not literal promises that every request will receive every requested answer.

6.4. No marketing statement creates a contractual right to obtain assistance that the Operator reasonably determines would be unlawful, unsafe, abusive, technically unavailable, contrary to a binding provider rule, contrary to an applicable platform rule, or otherwise outside the Service as actually supplied.

6.5. Nothing in this section limits mandatory consumer rights or the legal effect of a sufficiently specific public assurance where applicable law requires such assurance to be taken into account. In particular, mandatory rules on conformity of digital services, including applicable provisions of the Polish Consumer Rights Act, remain unaffected.

7. Refusals, filters, restrictions and model behaviour

7.1. The Service may refuse, redirect, truncate, filter, block, rate-limit, delay or otherwise decline to provide some AI Outputs.

7.2. A refusal may result from law, safety systems, abuse controls, sanctions rules, fraud prevention, intellectual-property concerns, privacy concerns, model-provider restrictions, infrastructure-provider restrictions, technical limitations, capacity, automated classifications, human review, account history, security incidents or changes to the Service.

7.3. Purchasing a paid Plan does not purchase a guarantee that any specific prompt will be answered in a specific manner.

7.4. Users have no contractual entitlement to disable every safety, legal, provider or technical restriction.

7.5. We may change moderation, routing, safety or abuse-prevention logic without advance notice where reasonably necessary for security, legal compliance or protection of the Service. Consumer rights relating to material modifications of a continuously supplied digital service remain unaffected.

7.6. A refusal, incomplete answer or altered output is not by itself evidence of service non-conformity. Mandatory statutory conformity standards still apply where applicable.

8. User responsibility

8.1. You are solely responsible for your prompts, files, instructions, decisions, downstream use of AI Outputs and compliance with laws applicable to you.

8.2. You must not represent AI Output as verified professional advice where it has not been independently reviewed by a qualified person.

8.3. You must obtain any permission required to upload personal data, confidential information, copyrighted material, trade secrets or third-party content.

8.4. You must use human judgment before deploying generated code, automation, security configurations, financial calculations, legal language or other material capable of causing material harm if wrong.

9. No consent to illegal conduct

9.1. The Operator does not authorise, request, encourage, conspire in, assist in the commission of, or consent to unlawful activity merely by making a general-purpose AI interface available.

9.2. The User may not treat branding, fictional illustrations, slogans, model personality, generated text or the availability of a prompt field as permission to violate criminal, civil, regulatory, sanctions, intellectual-property, privacy, consumer-protection or other law.

9.3. The Operator may cooperate with competent authorities where legally required and may preserve information subject to a valid legal preservation obligation, court order or other binding process.

10. Prohibited use

10.1. You must not use the Service to commit, materially facilitate, procure, organise or conceal unlawful acts. Without limiting the general rule, prohibited activity includes use intended to materially facilitate:

10.2. Discussion, analysis, fictional depiction, academic discussion, defensive security work, legitimate compliance work, journalism, historical analysis, safety research or other lawful context is not automatically Prohibited Use merely because the topic is sensitive. The Operator may nevertheless restrict a request where context cannot be reliably established or risk remains excessive.

10.3. Attempts to evade restrictions through obfuscation, encoding, role-play, prompt injection, fragmented requests, proxy users or repeated reformulation may result in rate limits, suspension or termination.

11. Account security

11.1. You must keep credentials secure and must not share an Account in a manner inconsistent with the Plan.

11.2. You are responsible for activity performed through your Account until you notify us of suspected compromise, except to the extent mandatory law provides otherwise.

11.3. We may force a password reset, revoke sessions or temporarily restrict access where compromise is reasonably suspected.

12. User content and permissions

12.1. As between you and the Operator, you retain any rights you lawfully hold in material you submit.

12.2. You grant the Operator a non-exclusive, worldwide, limited licence to host, reproduce, transmit, transform and otherwise process submitted material only to the extent reasonably necessary to provide, secure, maintain, support and legally operate the Service.

12.3. You represent that you have the rights and permissions required to submit the material.

12.4. Do not submit confidential information if disclosure to the Operator or relevant service providers would violate a duty owed to another person.

13. AI Output rights and non-exclusivity

13.1. To the extent permitted by applicable law and subject to third-party rights, the Operator does not claim ownership over AI Output solely because it was generated for you.

13.2. AI systems can generate identical or similar material for different users. No exclusivity is promised.

13.3. Copyright or other protection may not arise in machine-generated material in every jurisdiction. You are responsible for determining whether and how an Output can lawfully be used.

13.4. The Operator does not warrant that AI Output is non-infringing, unique, registrable, patentable, trademark-clear or free of third-party rights.

14. Plans, usage limits and capacity

14.1. Each Plan may include message limits, token limits, rate limits, file limits, context limits, model access, feature access or other capacity rules displayed at purchase or in the account interface.

14.2. Usage allowances do not constitute stored monetary value and, unless mandatory law requires otherwise, unused allowance does not roll over after the billing period.

14.3. We may apply reasonable anti-abuse and fair-use controls even where a Plan is described as “unlimited”, if such a Plan is ever offered. Any material limitation will be disclosed in a reasonably accessible manner.

15. Prices, subscriptions and recurring billing

15.1. Paid Plans are billed at the price and interval shown at checkout. Taxes may be added or included as required by law.

15.2. Unless expressly stated otherwise, subscriptions renew automatically for successive billing periods until cancelled.

15.3. You authorise the payment provider to charge the selected payment method for recurring fees, applicable taxes and properly disclosed charges.

15.4. If payment fails, we may retry payment, downgrade the Plan, limit access or suspend paid features.

15.5. Price changes will apply prospectively and, where required, notice will be given before the new price applies. Consumers retain any mandatory right to reject a modification or terminate.

16. Payment processing and card data

16.1. Payments are processed by an external payment service provider, such as Stripe or another provider identified at checkout.

16.2. The Operator is not intended to receive or store complete payment-card numbers, card security codes or equivalent raw payment credentials.

16.3. The payment provider may process identity, billing, transaction, device, network and anti-fraud information under its own legal terms and privacy notice.

16.4. The Operator may receive limited payment metadata necessary for account administration, such as Plan, payment status, currency, amount, invoice or transaction identifier, subscription state, refund or chargeback status, country or tax classification and limited masked payment-method information where supplied by the processor.

17. Cancellation

17.1. You may cancel renewal through the account interface or another cancellation method made available by us.

17.2. Unless applicable law requires an earlier effect, cancellation stops future renewal and access continues until the end of the already-paid billing period.

17.3. Deleting an Account and cancelling a subscription are separate actions unless the interface expressly states otherwise.

18. EU / Polish consumer withdrawal rights

18.1. A Consumer concluding a distance contract generally has a statutory 14-day right of withdrawal under art. 27 of the Polish Consumer Rights Act, subject to statutory rules and exceptions.

18.2. If you expressly request that a paid service begin during the withdrawal period, the Operator may, where the statutory conditions are met, be entitled to a proportionate amount for the service supplied before withdrawal.

18.3. Where the law permits loss of a withdrawal right after full performance or in relation to specific digital content, such loss occurs only when all legally required conditions, consents, acknowledgements and confirmations have been satisfied.

18.4. Nothing in these Terms attempts to remove a withdrawal right where the statutory requirements for removing that right have not been met.

18.5. A withdrawal statement may be submitted through the electronic contact address identified in section 1 or another withdrawal channel displayed at checkout.

19. Refunds and chargebacks

19.1. Refunds are provided where required by mandatory law, these Terms or a separately published refund commitment.

19.2. A User should contact support before filing a chargeback where reasonably possible so that billing errors can be investigated.

19.3. Fraudulent chargebacks, false payment disputes or abuse of payment systems may result in suspension and recovery of costs to the extent permitted by law.

20. Conformity of the digital service and statutory remedies

20.1. For Consumers, mandatory rules concerning supply and conformity of digital services apply, including applicable provisions of arts. 43j to 43q of the Polish Consumer Rights Act.

20.2. Nothing in a disclaimer of AI accuracy eliminates mandatory duties concerning the Digital Service itself, including functionality, availability, compatibility, security or other characteristics where the law requires conformity with contract.

20.3. Where a Digital Service is non-conforming, a Consumer may have statutory rights to bring it into conformity, obtain a price reduction, terminate or exercise other remedies, subject to the conditions laid down by law.

20.4. Public marketing statements may be relevant to statutory conformity where applicable law provides. The Operator therefore distinguishes promotional tone and fictional branding from concrete factual claims about paid functionality.

21. Changes to a continuously supplied digital service

21.1. We may modify features, models, user interface, infrastructure, routing, limits or security controls for valid reasons including improvement, legal compliance, security, provider changes, technical evolution, abuse prevention, cost management and interoperability.

21.2. Changes will not create an additional charge unless you affirmatively choose a paid upgrade or the law and contract permit a properly notified price change.

21.3. Where mandatory consumer law requires advance notice, a valid contractual basis, an objective reason or a right to terminate following a materially adverse modification, those requirements prevail.

22. Suspension and termination

22.1. We may suspend or terminate access for material breach, Prohibited Use, payment fraud, security risk, repeated attempts to defeat controls, unlawful content, sanctions restrictions, legal orders, attacks on the Service or conduct that creates material risk to users, providers or the Operator.

22.2. Where practical and legally appropriate, we may provide notice and an opportunity to remedy before termination. Immediate action may be taken for urgent security, legal or abuse reasons.

22.3. A Consumer’s mandatory rights regarding prepaid periods, termination and statutory remedies remain unaffected.

23. Third-party providers and dependencies

23.1. The Service depends on internet, hosting, CDN, database, authentication, payment and AI-model providers that are not fully controlled by the Operator.

23.2. Provider outages, model changes, API limits, policy changes, sanctions restrictions, capacity shortages or security events may affect the Service.

23.3. We may replace Third-Party Providers where reasonably necessary. Users are not guaranteed access to a specific upstream provider unless expressly stated in a separate written agreement.

24. Intellectual property of the Service

24.1. The Evil Twin AI brand, original artwork, website design, software, interfaces, databases, documentation and other Operator materials are protected by applicable intellectual-property law.

24.2. Except as expressly allowed, you may not copy, sell, sublicense, scrape, reverse engineer, reproduce or create confusingly similar branding from protected Operator materials.

24.3. You may not use the Service to develop a competing service through systematic extraction of outputs, model behaviour or proprietary interface elements where such activity violates applicable law or contractual rights.

25. Feedback

If you voluntarily provide suggestions or feedback, you grant the Operator a worldwide, perpetual, irrevocable, royalty-free licence to use that feedback for improvement and development without an obligation to compensate you, to the extent permitted by law.

26. No warranties beyond mandatory law

26.1. To the maximum extent permitted by law, and subject to mandatory consumer-conformity obligations, the Service is supplied without warranties that every Output will be accurate, complete, lawful for your intended use, uninterrupted, unique, non-infringing or fit for a purpose that has not been expressly accepted by the Operator.

26.2. We do not warrant that the Service will answer every prompt, maintain a particular tone, preserve a particular model indefinitely or never produce an error.

26.3. Nothing in this section limits guarantees, warranties or statutory rights that cannot lawfully be excluded.

27. Limitation of liability

27.1. Nothing in these Terms excludes or limits liability where exclusion or limitation is prohibited by law, including liability that cannot be excluded toward a Consumer or for intentional misconduct where applicable law makes exclusion ineffective.

27.2. For Users acting in the course of business, and to the maximum extent permitted by law, the Operator is not liable for indirect, consequential, special or punitive damages, lost profits, lost revenue, lost opportunity, loss of goodwill or loss of data arising from use of AI Output, except where such limitation is prohibited.

27.3. For business Users only, the Operator’s aggregate contractual liability arising out of the Service in a 12-month period is limited, to the maximum extent permitted by law, to fees actually paid by that User for the Service during the preceding 12 months.

27.4. The limitations in this section do not reduce mandatory statutory rights of Consumers.

28. Indemnity for business users

If you use the Service in the course of business, you agree, to the extent permitted by law, to indemnify the Operator against third-party claims arising from your unlawful use, infringement of third-party rights, breach of section 10 or unauthorised submission of third-party confidential or personal data. This clause does not apply to Consumers to the extent it would unlawfully alter their rights.

29. Force majeure

The Operator is not responsible for delay or failure caused by events beyond reasonable control, including major provider outages, internet failures, cloud incidents, power failures, natural disasters, war, terrorism, civil disorder, governmental action, sanctions, labour disputes, epidemics, critical software vulnerabilities or widespread cyber incidents, subject to mandatory law.

30. Complaints

30.1. Complaints concerning electronic services, billing, access or Digital Service conformity may be submitted to the electronic contact address in section 1 or through the Contact page.

30.2. A complaint should identify the Account, describe the issue, state the requested resolution and include information reasonably necessary to investigate.

30.3. Complaints will be handled without undue delay and within any mandatory statutory period.

30.4. The User is not required to surrender mandatory court, regulator, ADR or consumer-remedy rights merely because an internal complaint process exists.

31. Consumer ADR and dispute information

31.1. Consumers may be entitled to seek assistance from a municipal or district consumer ombudsman, the Polish Trade Inspection system, the European Consumer Centre or another competent alternative-dispute-resolution body, depending on the dispute and jurisdiction.

31.2. Participation in a particular ADR procedure is mandatory only where required by law or expressly accepted by the Operator.

32. Governing law and jurisdiction

32.1. These Terms are governed by Polish law.

32.2. A Consumer is not deprived of mandatory protection granted by the law of the country in which that Consumer has habitual residence where such protection applies notwithstanding a choice of law.

32.3. Disputes with Consumers are heard by courts determined under applicable mandatory jurisdiction rules.

32.4. For business Users, to the extent legally effective, disputes shall be submitted to courts competent for the Operator’s registered office.

33. Changes to these Terms

33.1. We may amend these Terms for valid reasons, including legal changes, new features, provider changes, security, abuse prevention, billing changes and clarification.

33.2. Material changes affecting an ongoing paid relationship will be notified in a manner required by applicable law. Where a User has a statutory right to terminate because of a change, that right remains available.

33.3. A revised version applies prospectively from its stated effective date. We will not use a terms update to retroactively legalise conduct that was unlawful when it occurred.

34. Severability, priority and assignment

34.1. If a provision is invalid or unenforceable, the remaining provisions continue to apply to the extent legally possible.

34.2. Mandatory law prevails over inconsistent contractual language.

34.3. A separately signed written agreement prevails over these Terms to the extent of a conflict.

34.4. The Operator may assign the agreement as part of a merger, restructuring, financing, sale of business or transfer of the Service, subject to applicable consumer and data-protection law.

35. Privacy Policy: role and scope

35.1. This section explains the Operator’s processing of personal data in connection with the website, Accounts, subscriptions, support and AI service.

35.2. Where the Operator determines the purposes and means of processing, the Operator acts as controller within the meaning of Regulation (EU) 2016/679 (GDPR).

35.3. Third-Party Providers may act as processors, independent controllers or sub-processors depending on their role and contract.

36. Data-minimisation position

36.1. The Service is intended to follow data minimisation, purpose limitation and storage limitation principles reflected in art. 5 GDPR.

36.2. We aim to avoid collecting identity information that is not necessary to provide, secure, bill or legally operate the Service.

36.3. “Anonymous” or “privacy-first” marketing does not mean that no data are ever processed. Account data, content submitted to obtain a response, necessary security data and billing metadata may still be processed as described here.

37. Categories of personal data

CategoryExamplesTypical purpose
Account datausername, email or authentication identifier, account status, planregistration, login, account administration, contract performance
Conversation dataprompts, attachments, outputs, user feedbackgenerate responses, provide history if enabled, support, safety and service integrity
Usage / service datamessage counts, feature usage, timestamps, model-routing metadata, error eventsdeliver limits, capacity, debugging, abuse prevention, service improvement
Billing metadatasubscription state, amount, currency, transaction or invoice identifier, refund / chargeback statebilling, accounting, support, fraud prevention, legal obligations
Support datasupport messages and information voluntarily suppliedrespond to requests, resolve disputes and technical issues
Consent / preference datacookie choices, marketing consent where applicablerecord and respect preferences and legal choices
Security datasession identifiers, authentication events, anti-abuse indicatorsprotect Accounts and Service

38. IP addresses

38.1. The Operator’s intended application-level design is not to intentionally store users’ IP addresses as persistent Account profile fields or routine application logs.

38.2. Internet communication nevertheless necessarily exposes network addressing information to network-layer participants. Hosting, CDN, DDoS-protection, security, authentication, payment or other infrastructure providers may transiently receive or independently process IP addresses or equivalent network identifiers as part of delivering and securing their services.

38.3. The Operator will not advertise “IP never exists anywhere on the internet.” The narrower commitment is that the Operator does not intentionally build an application-level user IP history where such collection is not necessary.

38.4. If infrastructure architecture changes so that the Operator begins storing IP addresses, this Policy must be updated before or at the time required by law.

39. Payment data

39.1. Full card credentials are intended to be collected and processed directly by the external payment provider, not by the Operator.

39.2. The payment provider may independently collect data required for payment processing, anti-fraud screening, regulatory compliance and dispute handling.

39.3. The Operator may receive limited billing metadata described in section 37, but not complete card numbers or card security codes.

40. Conversation content

40.1. Conversation Content must be processed to provide an AI response. This may involve transmitting content to one or more model or infrastructure providers acting under contractual arrangements.

40.2. If conversation-history functionality is enabled, Conversation Content may be stored so that the User can return to prior threads. Users should use available deletion controls where they do not want history retained.

40.3. Conversation Content may be subject to limited automated or human review where reasonably necessary for support requested by the User, abuse investigation, fraud prevention, security incidents, legal compliance, provider troubleshooting or enforcement of these Terms.

40.4. Access should be restricted according to role and necessity.

40.5. Users should not submit unnecessary special-category data, government identifiers, full financial credentials, passwords or secrets.

41. Purposes and GDPR legal bases

PurposeTypical GDPR basis
Provide Account, chat, history and paid Planart. 6(1)(b), performance of contract or steps requested before contract
Billing, accounting, tax and legally required recordsart. 6(1)(c), legal obligation
Security, abuse prevention, fraud prevention, service integrity and defence of legal claimsart. 6(1)(f), legitimate interests, balanced against user rights
Non-essential analytics or marketing storage where consent is requiredart. 6(1)(a), consent, together with applicable electronic-communications rules
Support communicationsart. 6(1)(b) and/or art. 6(1)(f), depending on context
Compliance with binding orders and legal dutiesart. 6(1)(c)

42. Cookies, local storage and similar technologies

42.1. Strictly necessary cookies or equivalent storage may be used for authentication, session continuity, security, load balancing, fraud prevention and other functionality requested by the User.

42.2. Under art. 399 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej), storing information on, or accessing information already stored on, an end user’s terminal generally requires prior clear information and consent unless the statutory necessity exception applies.

42.3. Non-essential analytics, advertising or tracking technologies will be activated only where a valid legal basis and any required terminal-device consent have been obtained.

42.4. A User can withdraw consent through the cookie / privacy controls made available by the Service where consent is the basis for processing.

43. Recipients and service providers

Personal data may be disclosed, only as reasonably necessary, to categories such as cloud-hosting providers, CDN and security providers, database providers, model / inference providers, authentication providers, transactional-email providers, payment processors, customer-support systems, professional advisers and competent public authorities acting under valid legal authority.

44. International data transfers

44.1. Some Providers may process data outside Poland or the EEA.

44.2. Where GDPR Chapter V applies, transfers to third countries must rely on a lawful transfer mechanism, such as an adequacy decision under art. 45 GDPR, appropriate safeguards including standard contractual clauses under art. 46 GDPR, or another lawful mechanism.

44.3. Additional safeguards and transfer-risk assessment will be used where required by applicable law.

45. Retention

45.1. Data are retained for no longer than reasonably necessary for the purpose for which they were processed, subject to legal, accounting, tax, fraud-prevention, security and claims-preservation requirements.

45.2. Account data may be retained while the Account is active and for a limited period afterward where needed to close the account, resolve disputes or comply with law.

45.3. Billing and tax records may be retained for statutory accounting and tax periods.

45.4. Conversation history, if stored, is retained according to product settings, deletion controls and any limited preservation period necessary for security, disputes or binding legal obligations.

45.5. Backups may retain deleted material for a limited rotation period before automatic overwrite, subject to security and legal requirements.

46. Security

46.1. We use technical and organisational measures intended to provide security appropriate to risk, taking into account art. 32 GDPR.

46.2. Measures may include encryption in transit, access controls, authentication protections, least-privilege access, provider due diligence, logging of security events, backup controls and incident-response procedures.

46.3. No internet system is perfectly secure. Users must protect their credentials and devices.

47. Personal-data breaches

Where a personal-data breach occurs, the Operator will assess and, where required, notify the competent supervisory authority and affected data subjects in accordance with arts. 33 and 34 GDPR.

48. Automated decision-making and profiling

48.1. AI generation itself involves automated processing of the User’s prompt to produce a response.

48.2. Unless separately disclosed, the Service is not intended to make solely automated decisions producing legal effects or similarly significant effects about Users within the meaning of art. 22 GDPR.

48.3. Automated systems may be used for spam, fraud, abuse, security or rate-limit classification. Where art. 22 or another mandatory rule applies, required safeguards will be provided.

49. Data-subject rights

49.1. Subject to statutory conditions, data subjects may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent under arts. 15 to 21 GDPR, as well as rights relating to qualifying automated decisions under art. 22 GDPR.

49.2. Consent can be withdrawn at any time without affecting lawfulness of processing before withdrawal.

49.3. Where processing relies on legitimate interests, a data subject may object in accordance with art. 21 GDPR.

49.4. Requests may be submitted to the privacy contact in section 1. We may need to verify identity before fulfilling a request.

49.5. Rights are not absolute. Statutory exemptions, competing rights, legal obligations and preservation duties may apply.

50. Supervisory authority

EEA data subjects have the right to lodge a complaint with a competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

51. Children’s data

The Service is intended for adults aged 18 or older. We do not knowingly target the Service to children. If we learn that an underage person created an Account contrary to these Terms, we may close it and delete or restrict associated data subject to legal requirements.

52. Law-enforcement and legal requests

52.1. We may disclose data where required by a valid and binding legal obligation, court order or authorised request.

52.2. We may challenge overbroad or defective requests where appropriate and legally possible.

52.3. We do not promise to possess data that the architecture was deliberately designed not to retain.

53. DSA and content-restriction transparency, where applicable

If and to the extent the Service qualifies as an “intermediary service” subject to Regulation (EU) 2022/2065 (Digital Services Act), restrictions on user-provided information, moderation measures, algorithmic tools and complaint mechanisms will be described and applied in accordance with applicable DSA obligations, including art. 14 where relevant. Nothing in these Terms asserts that every part of the Service necessarily falls within every DSA service category.

54. EU AI Act transparency

54.1. The product identifies itself as an AI service and Users should understand that they are interacting with machine-generated systems.

54.2. Where applicable, the Operator will implement transparency and other obligations under Regulation (EU) 2024/1689 (AI Act), including relevant requirements for systems intended to interact directly with natural persons.

54.3. The Operator does not use provocative marketing as permission to engage in AI practices prohibited by applicable law.

55. Marketing communications

55.1. Marketing email or equivalent direct electronic marketing will be sent only where a valid legal basis and any separately required communications consent exist.

55.2. Consent can be withdrawn using the unsubscribe mechanism or the contact method identified in section 1.

55.3. Commercial information will be identified as such where required by law.

56. Do-not-sell / targeted-advertising position

56.1. The Operator does not intend to sell personal data for monetary consideration as a core business model.

56.2. If the Service ever engages in legally defined “sale”, “sharing”, targeted advertising or equivalent regulated disclosure, the Policy and user controls must be updated before or when legally required.

56.3. Users in jurisdictions providing additional privacy rights may exercise those rights where the relevant statute applies to the Operator.

57. Contact and exercise of rights

Contract, billing and complaint contact: electronic contact address must be inserted before commercial launch.

Privacy contact: electronic contact address must be inserted before commercial launch.

Website contact route: /contact.

58. Principal legal references

This list identifies principal legal frameworks considered in drafting. It is not an exhaustive statement of every law that may apply to every user, transaction or jurisdiction.

59. Interpretation

59.1. Headings are for navigation only.

59.2. “Including” means “including without limitation” unless context requires otherwise.

59.3. References to statutes include amendments and successor provisions applicable at the relevant time.

59.4. If a translated version exists and the Operator designates one version as controlling, that designation must respect mandatory consumer-language and transparency requirements.

60. Final provisions

60.1. These Terms, together with the Plan information shown at purchase and any expressly incorporated policy, form the agreement for use of the Service.

60.2. The Operator’s failure to enforce a provision on one occasion is not a waiver of future enforcement.

60.3. No person other than the parties has contractual enforcement rights except where applicable law provides otherwise.

60.4. The current version will remain publicly available at this URL. Historic versions should be retained internally and, where reasonably required, made available to Users affected by them.