Version 1.0 · updated 2026-06-09
Privacy Policy (GDPR) — FizzUp
1. Who we are (Data Controller)
The controller of personal data is:
DB 77 CUW Sp. z o.o.
ul. Żółkiewskiego 31, 87-100 Toruń, Polska
NIP 8792706635, REGON 381680838, KRS 0000755526
E-mail (privacy matters): privacy@fizzup.ai
E-mail (support): support@fizzup.ai
If we appoint a Data Protection Officer (DPO), we will publish their contact details in this Policy.
2. Who this Policy applies to
This Policy applies to:
- visitors to the website (landing / web build),
- users of the FizzUp app (iOS / Android / web),
- people who contact us (form, e-mail, support),
- paying customers (subscriptions) and users within company accounts (B2B), if and to the extent such a feature is launched.
3. What data we process (categories)
3.1 Account data
- e-mail,
- authentication data (the password is stored as a hash),
- display name / first and last name (if you provide it),
- profile settings and preferences.
3.2 Data related to learning and use of the app
Depending on the app features you use, we process, among other things:
- the history of sessions and text conversations (e.g. session topics, the content of your utterances in text sessions),
- saved phrases and "memory" items (Memory Engine),
- style preferences and signals (e.g. "I like / I don't like this style"),
- feature usage metadata (e.g. usage counters and plan limits).
3.3 Voice data and transcripts (microphone)
The app may process your speech in voice features.
In particular:
- the app requests access to the microphone (system permission),
- in Speak (Gemini Live) mode, the audio stream and transcripts may be transmitted directly to the provider (Google Gemini Live) from your device (WebSocket),
- in STT/TTS features handled by our backend, audio or text may be transferred to speech service providers (e.g. STT: OpenAI Whisper or Google Speech-to-Text; TTS: Google Text-to-Speech).
Important (current state per the code): transcripts and audio from Gemini Live mode are not currently stored in our database on the backend side (the backend only issues an ephemeral token for the connection).
3.4 Payment data (subscriptions)
If you use paid plans:
- card payments may be handled by Stripe (in the "Checkout/Portal" model),
- we do not store full payment card details (they are processed by the payment provider),
- on our side, data about subscription status, customer/subscription identifiers on the Stripe side, and billing data required by law may be stored.
3.5 Contact data and leads (B2B / demo)
If you use the contact form or a demo request, we may process:
- first and last name,
- e-mail,
- company name, team size,
- the content of your message.
3.6 Technical and security data
We may process data such as:
- IP address (e.g. in server logs),
- information about the device, app version and environment,
- logs and security events.
4. Why we process data (purposes and legal bases)
Depending on the situation, we process data for the following purposes:
- providing the service and performing the contract (Art. 6(1)(b) GDPR) — maintaining the account, running sessions, "memory" features, ensuring the app works,
- ensuring security and preventing abuse (Art. 6(1)(f) GDPR) — logs, system protection, abuse detection,
- billing and legal obligations (Art. 6(1)(c) GDPR) — accounting, taxes, complaints,
- contact and support (Art. 6(1)(b) or (f) GDPR) — handling requests,
- marketing (if we launch it and you give consent) (Art. 6(1)(a) GDPR) — newsletter, marketing communications.
For the processing of voice data, the legal basis is in principle the provision of the service (Art. 6(1)(b) GDPR) and your action (activating the voice feature + system consent for the microphone). If, in a given deployment, an additional explicit consent is required (e.g. due to local interpretations), we will implement it in the app and describe it in this Policy.
5. Who we share data with (recipients / processors)
We use trusted infrastructure and service providers:
- Google — Gemini Live (real-time voice conversations) and/or STT/TTS (depending on configuration),
- OpenAI — Whisper (transcription) depending on configuration,
- Stripe — payment handling (if launched),
- Railway — hosting of the app and database (infrastructure).
We publish the full list and updates in the "Subprocessors" document.
6. Transfers outside the EEA
Some providers may process data outside the European Economic Area (EEA). In such cases, we apply appropriate safeguards (e.g. standard contractual clauses) — details will be confirmed and described in the final version of the documents.
7. How long we keep data (retention)
Retention depends on the type of data and the purpose:
- account data and learning data — for the duration of the account, unless you delete the account or data earlier,
- billing data — for the period required by law,
- lead/contact data — for the period necessary to handle the matter and any claims,
- security logs — for a reasonable period necessary to ensure security (exact periods will be specified).
Audio: in the current state of the code, we do not store permanent recordings from Gemini Live mode on our side. If we implement storage of audio or transcripts from voice features, we will update this Policy and provide user control.
8. Your rights (GDPR)
You have the right to:
- access your data,
- rectification,
- erasure ("the right to be forgotten"),
- restriction of processing,
- data portability,
- objection (with respect to Art. 6(1)(f)),
- withdraw consent (if we process on the basis of consent),
- lodge a complaint with a supervisory authority (in Poland: the President of the UODO).
The app provides the following features:
- Export data: "What I remember about you" → Export (GDPR Art. 20),
- Forget memory: "What I remember about you" → Forget (clears the memory, keeps the account),
- Delete account: "What I remember about you" → Delete account (GDPR Art. 17; deletes sessions/memory and redacts identifying data).
9. Automated decision-making and profiling
FizzUp may create learning profiles (e.g. weak patterns, style preferences, exercise recommendations) for the purpose of personalization and learning support. We do not make decisions producing legal effects, or similarly significantly affecting you, solely by automated means.
10. Security
We apply technical and organizational measures appropriate to the risk (including access control, transmission encryption, limited access to environments, event logging). We do not make certification claims if we do not hold them.
11. Children and age
The Service is intended for persons aged 18+. If we learn that an account belongs to a person under 18, we may delete it and redact the data, subject to legal obligations.
12. Contact
For privacy matters, write to: privacy@fizzup.ai
For support matters: support@fizzup.ai
FizzUp legal documents are published in English. This English version is the canonical reference; localized translations, where provided, are for convenience only.