LEGAL
Privacy Policy
Last updated: September 1, 2026
Data Controller
FerrisTech Marcin Miłoszewski
ul. Szosa Chełmińska 169B lok. 49
87-100 Toruń, Poland
Tax ID (NIP): 8792422300
E-mail: ferrisintech@gmail.com
1. Introduction and Scope
This Privacy Policy explains how FerrisTech Marcin Miłoszewski ("PicoStep", "we", "us") collects, uses, discloses and protects personal data when you use the PicoStep mobile application (the "App") and this website (the "Site"), regardless of where you are located in the world. We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA (CCPA), Brazil's LGPD, Canada's PIPEDA and other applicable regional laws.
2. What Data We Collect
- Account data — when you sign in with Apple, we receive your name and e-mail address (or a private relay e-mail if you hide your address). This is stored in our Supabase database to identify your account.
- User profile data — your in-app preferences (AI personality, energy level, blocker profile) and subscription status.
- Task content — the text of your brain dumps and generated micro-steps. This is stored locally on your device (encrypted Hive storage). Cloud records are limited to your account and profile data.
- Purchase data — subscription status and entitlements, processed by Apple and RevenueCat. We never see or store your payment card details.
- Technical data — standard, short-lived server logs (e.g., IP address, timestamps) required to operate the service securely.
3. What We Do NOT Do
- We do not sell, rent or share your personal data for advertising.
- We do not use advertising networks, trackers or behavioural profiling.
- We do not store your voice recordings — audio is processed on your device by Apple's Speech Recognition and discarded.
- We do not use your task content to train public AI models.
4. Voice and Speech Recognition
When you use the voice brain dump, audio is transcribed locally through Apple's native Speech Recognition APIs on your device. Audio buffers are transient and are never transmitted to, or stored on, our servers. The resulting text stays on your device unless you choose to defragment it (see section 5).
5. AI Task Defragmentation
When you request AI defragmentation, the text of your prompt, together with your in-app preference settings (energy level, personality, blocker profile), is transmitted over an encrypted HTTPS connection to our processing backend (Supabase Edge Functions) solely to generate your micro-step plan. Prompts are processed to deliver the service and are not used to advertise to you or to train public language models.
6. Legal Bases for Processing (EEA/UK)
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the App's features and managing your account and subscription.
- Legitimate interests (Art. 6(1)(f) GDPR) — securing our systems, preventing abuse and maintaining short-lived server logs.
- Consent (Art. 6(1)(a) GDPR) — optional permissions you grant on your device (microphone, speech recognition, notifications), which you may withdraw at any time in your device settings or in the App.
- Legal obligation (Art. 6(1)(c) GDPR) — accounting or tax obligations, where applicable.
7. Cookies and Local Storage
This website does not use tracking cookies. The App stores your tasks and preferences locally on your device (Hive / SharedPreferences) so the service works offline; you can erase this data by deleting the App or using "Delete Account".
8. Data Retention
- Account and profile data: kept for as long as your account exists. Deleted permanently when you use "Delete Account" or request deletion.
- AI processing prompts: processed transiently and retained only where technically necessary (e.g., short-lived logs), after which they are deleted.
- Server logs: retained for a maximum of 90 days for security purposes.
- Local task data: remains on your device until you delete it or uninstall the App.
9. International Data Transfers
Our service providers (including Supabase and its hosting providers) may process data outside your home country. Where data is transferred out of the EEA or the UK, we rely on European Commission adequacy decisions or on Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable), together with appropriate technical and organisational safeguards. You may request a copy of the safeguards we apply by contacting us.
10. Your Rights — Worldwide
EEA, UK and similar regimes
Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your supervisory authority — in Poland: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa (uodo.gov.pl).
California (CCPA/CPRA)
We do not "sell" or "share" personal information as defined by the CCPA, and we do not process sensitive personal information for targeted advertising. California residents have the rights to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination for exercising these rights. To exercise any right, e-mail ferrisintech@gmail.com; we will verify your request and respond within the statutory time frame.
Brazil (LGPD), Canada (PIPEDA) and other regions
If you are located in Brazil, Canada or any other jurisdiction with a comprehensive privacy law, we honour equivalent rights (access, correction, deletion, portability, information about sharing, and withdrawal of consent) to the extent required by local law, through the same contact e-mail.
11. Children's Privacy
PicoStep is not directed at children under 13 (or under 16 in the EEA, where applicable). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
12. Security
We apply industry-standard safeguards: encrypted transport (HTTPS/TLS), encrypted local storage on device, access controls and data minimisation. No method of transmission or storage is 100% secure, but we continuously review and improve our protections.
13. Third-Party Processors
- Apple Inc. — App Store distribution, Sign in with Apple, on-device speech recognition, in-app purchase processing.
- RevenueCat, Inc. — subscription management and entitlement validation.
- Supabase (hosted in the EU/US) — authentication and cloud storage of account/profile data.
These providers act as processors or independent controllers as applicable, each bound by their own privacy commitments (supabase.com/privacy, revenuecat.com/privacy, apple.com/privacy).
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date above shows the current version. Material changes will be highlighted in the App or on this Site.
15. Contact
For any privacy question, request or complaint, contact the Data Controller:
FerrisTech Marcin Miłoszewski · ul. Szosa Chełmińska 169B lok. 49, 87-100 Toruń, Poland · NIP: 8792422300 · ferrisintech@gmail.com