Shuuty

Privacy Policy

Privacy Policy of the Shuuty Mobile Application

Last updated: July 30, 2026

1. Controller and contact details

The personal data controller is Shuuty Prosta Spółka Akcyjna, ul. Południowa 13, 32-353 Trzyciąż, Poland, entered in the National Court Register under KRS 0000947279, tax identification number (NIP) 6372215912, and statistical number (REGON) 52098153800000 (hereinafter “Shuuty,” “we,” or the “Controller”).

For privacy matters and the exercise of data protection rights, contact us at shuuty.app@gmail.com.

This Policy describes processing in the Shuuty mobile application (the “Application”) and, where relevant, on the public Shuuty website.

2. Data we process

2.1. Data provided by the user

Depending on the features selected, we may process:

  • account and sign-in data: email address, user identifier, username, display name, password hash, or an identifier associated with a Google, Apple, or Meta/Facebook account; Shuuty does not store a password in plain text;
  • registration and profile data such as date of birth, gender, language, time zone, nationality, interests, and profile photo;
  • content created or shared in the Application, including tasks, messages, reactions, meetings, groups, dates, locations, photos, and other media;
  • voice recordings, transcripts, queries, and limited context submitted to voice or artificial intelligence features when the user selects such a feature;
  • location information provided by the user or obtained with device-level permission for a task, meeting, group, map, or search;
  • the content of support requests and correspondence.

2.2. Technical and usage data

We may process data required to operate and protect the Application, such as the IP address, request date and time, platform, Application and operating-system versions, device type, installation or device identifier, push-notification token, session and sign-in information, security logs, error diagnostics, and basic feature-usage information. Once production monitoring is enabled, a limited set of technical diagnostic data may be sent to Sentry as described in section 4.

2.3. Purchase and subscription data

We process information needed to recognize entitlements, such as the product identifier, Free, Pro, or Teams plan, monthly or annual period, store, subscription status, expiration date, renewal state, and transaction identifiers. Payment is processed by the App Store or Google Play; Shuuty does not receive the user's full payment card or bank account details.

2.4. Access to the device calendar

When a user selects the feature for adding a specific meeting to the device calendar, the Application presents the system event-creation dialog and, depending on the operating system, requests permission to read and write the calendar. Granting this permission is voluntary. The Application accesses the calendar only at the user's express request to prepare the selected meeting and save it after confirmation in the system dialog. Refusing or withdrawing permission disables this feature but does not block other Application features. The contents of the device calendar are not sent to Shuuty's servers.

3. Purposes and legal bases

We process data only to the extent required for the following purposes:

  1. Performance of a contract or steps before entering into it - Article 6(1)(b) GDPR: creating and operating the account, sign-in, synchronization, performing features selected by the user, communication, sharing content according to settings, handling support requests, providing location, voice, and AI functions requested by the user, and verifying, restoring, and synchronizing Pro and Teams plans.
  2. Compliance with a legal obligation - Article 6(1)(c) GDPR: meeting tax, accounting, consumer, and complaint-handling obligations and responding to legally binding requests from authorities.
  3. Shuuty's legitimate interests - Article 6(1)(f) GDPR: protecting accounts and infrastructure, preventing fraud and abuse, diagnosing failures, improving reliability, compiling basic service-operation statistics, and establishing, exercising, or defending legal claims. We pursue these interests with due regard for users' rights and reasonable expectations.
  4. Consent - Article 6(1)(a) GDPR: where we expressly request consent and the law requires this basis, for example for a specific optional feature or communication. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

A device-level permission, such as access to location, microphone, camera, or photos, may be changed in device settings. Withdrawing a permission does not affect other features that do not require it.

4. Recipients and providers

We disclose data only to the extent required for the relevant purpose:

  • other Shuuty users when this follows from the feature and settings selected by the user, for example participation in a group, meeting, chat, or assigned task;
  • Apple, Google, and Meta/Facebook for sign-in or their platform functions, and Apple and Google also in connection with the App Store, Google Play, payments, and subscriptions;
  • RevenueCat to operate purchase information, entitlements, and subscription restoration;
  • OpenAI when the user selects a voice or AI feature; depending on the feature, the provider may receive a recording, transcript, query, and limited vocabulary context required to perform the request;
  • Sentry to detect and diagnose crashes and performance issues, based on Shuuty's legitimate interest in maintaining the security and reliability of the Application (Article 6(1)(f) GDPR). The data may include the Application and operating-system versions, device type, event time, error type and stack trace, performance traces, and a pseudonymous technical identifier. Shuuty's configuration disables default personally identifiable information, screenshots, and view hierarchy; the contents of tasks, messages, photos, and recordings are not intentionally attached to diagnostic reports;
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging to deliver push notifications;
  • Brevo to send transactional messages such as email verification and password resets;
  • Geoapify and Google Maps for place search, geocoding, and map display when the user uses location features;
  • Cloudflare R2 and Cloudinary to store, process, and deliver photos and other media;
  • infrastructure providers, including Railway for the backend, Neon for the database, and Vercel for the public Shuuty website;
  • professional advisers, public authorities, courts, or law enforcement where required to protect rights or comply with law.

Depending on the service and applicable law, a provider may act as a processor on Shuuty's behalf or as a separate controller under its own privacy notice.

5. Transfers outside the European Economic Area

Some providers may process data in countries outside the European Economic Area (the “EEA”), particularly when the user uses services provided by Apple, Google, Meta, RevenueCat, OpenAI, Expo, Sentry, or communication, map, hosting, and media providers.

Where data is transferred outside the EEA, we use a GDPR-permitted mechanism appropriate to the transfer, such as a European Commission adequacy decision, Standard Contractual Clauses together with required supplementary measures, or another valid basis. Information about the safeguard used for a particular provider or a copy of the relevant clauses may be requested from us.

6. Retention

We do not apply one period to all data. Retention is determined by the purpose, the lifetime of the account or feature, legal obligations, limitation periods for claims, security needs, backup cycles, and provider agreements:

  • account data and content are retained while the account is used. After deletion, data is deleted or anonymized except where it is required for legal obligations, abuse prevention, or the establishment, exercise, or defense of legal claims;
  • limited copies may remain until overwritten in the normal backup cycle; access is restricted and the data is not reused for ordinary service delivery;
  • a recording uploaded to a voice feature is retained temporarily and deleted after transcription. The transcript and content produced from it may remain if the user saves them in the Application;
  • subscription, transaction, complaint, and correspondence information is retained for the time needed to handle the matter, meet legal obligations, and protect legal claims;
  • technical and security logs are retained for a period justified by diagnostics, service protection, and abuse detection, and are then deleted or anonymized;
  • external providers apply their own periods consistent with their role, agreements, and applicable law.

7. User rights

Subject to the conditions set out in the GDPR, the user has the right to:

  • access personal data and receive a copy;
  • correct personal data;
  • erase data or restrict its processing;
  • data portability;
  • object to processing based on Article 6(1)(f) GDPR, including an objection based on the user's particular situation;
  • withdraw consent at any time where processing is based on consent; withdrawal is not retroactive;
  • lodge a complaint with the President of the Personal Data Protection Office in Poland (PUODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl, or another competent supervisory authority in the EEA.

A rights request may be sent to shuuty.app@gmail.com. Before fulfilling it, we may request information necessary to confirm identity and protect the account.

8. Whether providing data is mandatory

Data marked as required during registration, in particular data needed to authenticate the user, create the account, and confirm that the age requirement is met, is necessary to enter into and perform the agreement. Without it, creating or operating an account may not be possible.

Profile data marked as optional, location, access to the camera, microphone, or photos, and the use of voice and AI features are voluntary. Refusing to provide them or withdrawing permission may prevent use of the specific feature but should not block other features that do not need that data.

9. Automated decision-making

Shuuty does not make decisions about users based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them.

The Application may automatically organize content, transcribe and interpret instructions, suggest search results, or enforce technical plan limits. These operations support the feature selected by the user and do not constitute a decision with the effect described above.

10. Security and confidentiality

We use organizational and technical measures appropriate to the risk, including access controls, encrypted transmission, protection of authentication data, backups, and abuse-detection mechanisms. No transmission or storage method is completely secure. Users should protect their credentials and must not send a password in support requests.

11. Children and teenagers

The Application is intended for persons who are at least 16 years old. We do not knowingly allow children below that age to register. If such an account may have been created, please contact us.

12. Cookies and external links

The mobile Application does not use browser cookies as its primary operating mechanism. The public Shuuty website stores a technical “lang” cookie to remember the selected language. External websites, including the App Store and Google Play, apply their own cookie and privacy policies.

13. Changes to this Policy

The current version and last-updated date are published on this page. We may also communicate material changes in the Application or by email and, where required by law, request consent.

14. Contact

Questions, requests, and objections concerning personal data may be sent to shuuty.app@gmail.com.