Poliogo · Legal
Privacy Policy
Effective date: August 7, 2026
Last updated: September 11, 2026
1. Who we are
Poliogo ("we", "us", "our") operates poliogo.com — a compliance layer that reads your codebase and keeps your privacy, terms and cookie documents up to date as your stack changes. We decide why and how your personal data is processed, which makes us the data controller under the EU and UK GDPR, a business under the California Consumer Privacy Act, and the equivalent role under other privacy laws that apply to you.
- Contact for privacy questions and requests: support.polio.ai@gmail.com
- Where we are based: Israel
If you are in the EEA or the UK and we do not have an establishment there, you may contact us at the address above and we will route your request to our representative.
2. What personal data we collect
| Category | What it includes | How the law classifies it |
|---|---|---|
| Identity and contact data | Full name, email address, username or handle, company name, profile picture, country and password (kept only as a one-way hash) | GDPR personal data · CCPA Category A (identifiers) |
| Technical and usage data | Browser and user-agent string and language preference, session logs, pages viewed, referrer | GDPR online identifiers · CCPA Category F (internet activity) |
| Content you give us | Images you upload | GDPR personal data — including data about other people you include in it |
| Support communications | Messages you send us and their attachments | GDPR personal data · CCPA Category A |
Some of what you give us contains other people's personal data — a document you upload, a name in a message, an address book you share. You need a lawful reason to give it to us, and we handle it under this policy on your behalf.
We do not deliberately collect biometric data, genetic data, precise geolocation or government identification numbers. If you send us any of these in a support message, we delete them once your request is resolved.
3. Where the data comes from
- Directly from you — when you create an account, fill in a form, make a purchase or contact support.
- Automatically — through cookies, server logs and the SDKs listed in section 7 when you use the service.
- From third parties — from the identity provider you sign in with (which tells us your name and email address), and from the payment and infrastructure providers listed below.
4. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Creating and running your account | Identity, technical data | Art. 6(1)(b) performance of a contract |
| Keeping the service secure and preventing fraud | Technical data, logs | Art. 6(1)(f) legitimate interests |
| Storing and displaying the content you give us | Content you give us | Art. 6(1)(b) performance of a contract |
| Taking payment and running your subscription | Identity, transaction records | Art. 6(1)(b) performance of a contract |
| Understanding how our public marketing pages are used, and catching errors in them | Technical data | Art. 6(1)(f) legitimate interests |
Where another law applies, we rely on the equivalent basis: contractual necessity, legal obligation, legitimate interests, or your consent under the LGPD, PIPL, PIPEDA, the Australian Privacy Act and the US state privacy laws.
5. AI and automated decision-making
We do not use your personal data to train AI models, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
6. Cookies and tracking
We group everything we store on your device into four categories: strictly necessary, functional, analytics and marketing. Only strictly necessary items are set without your permission.
| Name | Set by | Category | What it does | Lifespan |
|---|---|---|---|---|
__session | Poliogo | Strictly Necessary | Carries the signed token that keeps you signed in | Until you sign out or it expires |
__cf_bm | Cloudflare | Strictly Necessary | Bot management and abuse prevention | 30 minutes |
firebase:authUser:* | Firebase | Strictly Necessary | Keeps you signed in (browser storage, not a cookie) | Until you sign out |
Beyond cookies we also use data we keep in your browser's local storage. The same consent rules apply to these as to cookies.
Where the law requires your consent, we ask for it before non-essential items are set. You can change your choices at any time by writing to support.polio.ai@gmail.com, and we will apply them to every non-essential technology we use. Our full Cookie Policy explains each item in detail.
7. Who we share data with
We do not sell your personal data for money. We do not share personal data for cross-context behavioural advertising.
| Service | Provider | Why we use it | What it receives | Where it processes data |
|---|---|---|---|---|
| Cloudflare | Cloudflare, Inc. | CDN, DNS, security filtering, edge compute, and the AI model that drafts optional clause suggestions from the notes you type | IP addresses, request headers, security events, and — for the drafting step only — the notes you type, the detected service list and your multiple-choice answers | Edge locations worldwide |
| Firebase | Google LLC | Sign-in, app data storage and push messaging | Email, auth tokens, device push tokens, app usage events, stored documents | United States |
| PostHog | PostHog, Inc. | Product analytics and error monitoring on our public marketing pages only — never on the signed-in dashboard, and never on a customer's Trust Center | IP address, page URL, referrer, clicked element text, error reports | European Union |
| PayPal | PayPal (Europe) S.à r.l. et Cie, S.C.A. | Subscription billing and payment processing | Name, email, billing address, subscription and transaction records | European Union and United States |
| Groq | Groq, Inc. | Drafts the same optional clause suggestions when Cloudflare is unavailable | The notes you type, the detected service list and your multiple-choice answers — never free-text fields holding personal details, never source code | United States |
A note on the AI drafting step. If you describe how your business operates in your own words, those words are sent to an AI model so it can draft extra clauses for you to review. That model runs at Cloudflare, which already provides our infrastructure; if Cloudflare is unavailable the request goes to Groq instead. We send the notes, the detected service list and your multiple-choice answers. We do not send free-text fields that hold personal details, and we never send your source code. Under the written terms we have with each of them, neither provider is permitted to train a model on what we send. The draft is shown to you before it is added to your document, and it is stored as your own text. Detecting your stack does not use AI at all — that step is pattern matching on our own servers. Nothing is sent unless you type into that box, and the rest of the service works without it.
Google's Gemini API and OpenRouter served this step until September 11, 2026. They were removed on that date and receive nothing.
A note on PostHog. It runs in memory-only mode, which means it stores nothing at all on your device — no cookie, no local storage, no session storage — and a page reload starts a new anonymous session. It is loaded on our marketing pages only: it is switched off inside the product, and it never runs on a Trust Center served from a customer's own domain.
Every provider above is bound by a data processing agreement that limits them to our instructions. We also disclose personal data when a law, court order or regulator requires it, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.
8. International transfers
Our infrastructure runs in more than one region. Some of the providers above process data outside your country, including in the United States. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework, and we assess the destination country's laws before we do so. For transfers out of mainland China we rely on the mechanisms permitted by the PIPL.
9. How we protect your data
- Access to production systems is limited to the people who need it, on the principle of least privilege.
- Data is encrypted in transit and at rest by our infrastructure providers.
- Passwords are stored only as one-way hashes — we never hold the password itself.
- Input is validated on the server before it is stored, to keep records accurate.
- A documented incident process: if a breach is likely to put you at risk we notify the competent authority within 72 hours and tell you without undue delay.
No system is perfectly secure, so we cannot promise absolute security.
10. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account is open, then 30 days after deletion |
| Server and security logs | 90 days, rolling |
| Content you uploaded | Until you delete it, then removed from backups within 30 days |
| Support conversations | 24 months after the conversation is closed |
| Analytics and cookie data | As stated in the cookie table in section 6 |
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.
11. Your rights
| Right | What it means | Where it applies |
|---|---|---|
| Access | Get a copy of your data, its sources and who received it | GDPR Art. 15 · CCPA § 1798.100 · LGPD · PIPL |
| Deletion | Have your data erased, including at our processors | GDPR Art. 17 · CCPA § 1798.105 · DPDPA |
| Correction | Fix data that is wrong or out of date | GDPR Art. 16 · CCPA § 1798.106 |
| Portability | Receive your data in a machine-readable file (JSON or CSV) | GDPR Art. 20 · CCPA § 1798.130 |
| Opt out of sale, sharing and targeted ads | Stop advertising-related sharing, including via GPC | CCPA/CPRA · VCDPA · CPA · CTDPA |
| Limit use of sensitive data | Restrict use beyond what the service needs | CPRA § 1798.121 |
| Object or restrict | Object to processing based on legitimate interests | GDPR Art. 18 and 21 |
| Withdraw consent | Withdraw consent at any time, without affecting past processing | GDPR Art. 7(3) · LGPD · PIPL |
| No retaliation | We will never degrade your service because you exercised a right | CCPA § 1798.125 |
In the product you can already send us a privacy request through our request form without asking us. To exercise any of these, email support.polio.ai@gmail.com or use the request form in our Trust Center. We verify your identity through the email address on your account before we act. We answer within 30 days (GDPR) or 45 days (CCPA), and tell you if we need the extension the law allows. An authorised agent may submit a request with written proof of authority. You can also complain to your data protection authority — in the EU, the one where you live or work; in the UK, the ICO.
12. Children
The service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe someone below that age has given us data, write to support.polio.ai@gmail.com and we will delete it. Where we know a user is under 16 we do not sell or share their data without opt-in consent, as California and EU member state law require.
13. Regional information
We have users in the EU, the UK and the United States. The sections below apply to you wherever you live.
California (CCPA/CPRA)
In the last 12 months we collected the categories in section 2 for the purposes in section 4, and disclosed them to the providers in section 7. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond the purposes permitted by § 7027(m). California residents may also request the "Shine the Light" disclosure under Civ. Code § 1798.83.
EEA and United Kingdom
Our legal bases are in section 4 and our transfer safeguards in section 8. You may lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office.
Brazil (LGPD)
You may confirm whether we process your data, request anonymisation of unnecessary data, ask who we shared it with, and revoke consent — write to support.polio.ai@gmail.com.
China (PIPL)
Where the PIPL applies we obtain separate consent before processing sensitive personal information, before sharing data with third parties and before transferring data outside mainland China.
Other regions
Residents of Virginia, Colorado, Connecticut, Utah, Texas and Florida have equivalent access, deletion, correction, portability and opt-out rights, plus a right to appeal a refused request by replying to our decision email.
14. Changes to this policy
We update this policy when what we do changes. The date at the top always reflects the current version, and previous versions are kept for audit. If a change is material we tell you by email or an in-app notice at least 30 days before it takes effect.