Your data belongs to you
Dopomo was built to help people in an unfamiliar system. That is why we take privacy seriously — we collect as little data as possible and tell you plainly what happens to it.
Data controller and contact
The controller of your personal data is RunProven AI Sp. z o.o., based in Wrocław (ul. Leszczyńskiego 4/25, 50-078 Wrocław), entered in the register of entrepreneurs of the National Court Register (KRS) under number 0001244275, NIP: 8971972885, REGON: 544874284, share capital 20,000 zł, the operator of the Dopomo brand; email: pomoc@dopomo.pl, tel. +48 797 106 646. For data protection matters, write to privacy@dopomo.pl.
We have not appointed a Data Protection Officer (DPO) — at our scale and type of activity this is not required (GDPR Art. 37). The contact point for data protection matters is privacy@dopomo.pl. The supervisory authority is the President of the Personal Data Protection Office (PUODO, uodo.gov.pl).
Dopomo is an independent AI assistant. We are not a public administration authority or a law firm, and we do not file applications on your behalf. The official government portal is mos.cudzoziemcy.gov.pl/en/.
What data we process
We process only the data needed for the assistant to work and for you to return to your conversations:
- ·Account data — your email address (used to sign in) and, after the first login, your name and citizenship, which you provide voluntarily. If you pass the CUKR qualification for your own case, we may pre-fill your citizenship (Ukraine) from that qualification result — you can change the field at any time, and we never overwrite a value you have entered yourself.
- ·The content of your conversations with the assistant — the questions you ask and the answers you receive. This is the most sensitive category of data; we store it so that you can access your account history. If you attach a file to a conversation, its content is sent to the model in the same way as a message; we delete the file itself from our servers after about an hour, and its metadata (name, type, size) together with the conversation history.
- ·Settings and notifications — your chosen language, your email notification preferences and, if you turn on deadline reminders on your device, your browser’s push-subscription data: the push service endpoint address and that subscription’s encryption keys (p256dh, auth). We delete them when you turn notifications off in Dopomo settings and when you delete your account; if you revoke the permission in your browser, we mark the subscription inactive once the push service reports that it has expired, and from that moment we send nothing to it.
- ·Technical session data — your IP address, browser information (user agent) and timestamps, and a record of the consents you have given.
- ·Passkey data — if you turn on passkey sign-in (WebAuthn/passkey), we store a public key, a credential ID and device metadata: the AAGUID (authenticator model), a sign counter and the available transports. For passkeys we never receive or store biometric data — fingerprint or face matching happens entirely on your device.
- ·Application data — if you use the paper-application creator or the paid cases (the CUKR case and the temporary residence case — TRC), we store the data you enter into the form, including: identity data (names, surname, date and place of birth, PESEL number if you have one), travel-document data (e.g. series and number — in the temporary residence case we may read them automatically from the MRZ zone of the passport scan you upload), residential address, residence status, marital status and family members’ details where the application concerns them, contact details and any discount codes used. We store it only in encrypted form; retention periods are described in section 06, and the data we never record — in section 05.
- ·Entity data (employer, university, etc.) in the temporary residence case — if your application requires an attachment signed by an entity, you give us its name, email address and, optionally, phone number, and the entity may give us the addresses of its signatories, a power-of-attorney file and its role. This is third-party data: we process it on the basis of our legitimate interest (GDPR Art. 6(1)(f)) — the efficient preparation of your case — solely to deliver the link to the entity, confirm by phone or text message where necessary that it arrived, and record the entity’s reply. The entity receives information about the processing (GDPR Art. 14) in the first message we send it. We store the contact details, the signatories’ addresses and the power-of-attorney file encrypted together with your case and delete them together with it (section 06).
A child’s data. If you prepare an application for your child in the CUKR case, you enter the child’s data to the same extent as your own. You then act as the parent or legal guardian on the child’s behalf (GDPR Art. 6(1)(b) — the service you are asking for), and we store and delete the child’s data exactly as we do the data of your own case (section 06).
Purposes and legal bases (GDPR)
We process your data on the basis of the GDPR (EU Regulation 2016/679):
- ·Providing the service — Art. 6(1)(b): maintaining your account and giving access to your conversation history. Passkey sign-in, if you enable it, rests on the same basis — it is an authentication method within the account-use contract.
- ·Security and operation of the service — Art. 6(1)(f): our legitimate interest in protecting the account and the service against abuse, including rate-limiting and chat cost and abuse protection.
- ·Chat content — Art. 9(2)(a): you cannot use chat without your explicit consent; it is a prerequisite to using the assistant, not an option (see the special-category data section for details).
- ·Optional notifications (including push reminders on your device) and news — Art. 6(1)(a): solely with your consent, which you can withdraw at any time.
- ·Paid services and the application creator — Art. 6(1)(b): we process your application data, facial photo and uploaded files in order to perform the service you ask for (details in sections 02, 05 and 06).
- ·Accounting — Art. 6(1)(c): we keep accounting documents because accounting law requires it (sections 06 and 13).
- ·Analytics, pursuing and defending legal claims, and entity data in the temporary residence case — Art. 6(1)(f): our legitimate interest in improving the service, defending against claims and preparing your case efficiently (sections 02 and 12).
- ·Marketing cookies and the ad-click identifier (gclid) passed to Google for conversion measurement — Art. 6(1)(a): solely with your consent in the cookie banner.
AI assistant — how it works
You are talking to an AI-based assistant, not a human (AI Act Art. 50). So that the assistant can respond, the content of your conversation is sent to our language-model provider. Our primary model provider for chat is Google Vertex AI (Gemini), in a European Union region (europe-west4). We may also, at the choice of our administrators, use AWS Bedrock (an EU region) as an alternative model provider. Both providers operate in the EU under data-processing agreements (DPAs) and standard contractual clauses (SCCs), so the data does not leave the EEA in order to generate an answer.
Under our AI provider’s terms of service, the content of your conversations is not used to train its models.
To find sources relevant to your question, the text of your query is sent to AWS Bedrock (an EU region) for knowledge-base retrieval and to compute vector representations (embeddings). The provider of this service does not use the text it receives to train its models.
Special-category data (GDPR Art. 9 and 10)
In ordinary use of the chat assistant we do not ask for special-category data (e.g. about health, origin, religion) or criminal-record data (GDPR Art. 9 and 10) — we do not need them to help you.
If you nonetheless voluntarily provide such data in a conversation, the basis for processing it is your explicit consent (GDPR Art. 9(2)(a)). We ask for this consent in a simple, one-time way before you send your first message to the assistant — we explain what the model processes and ask you to confirm. It is a prerequisite to using chat: without giving it, you cannot send a message to the assistant. You can withdraw the consent at any time in Settings (Privacy & Data); withdrawal is as easy as giving it and does not affect the lawfulness of processing before withdrawal. You can also write to privacy@dopomo.pl.
Files uploaded in the paid cases — in the CUKR case (e.g. scans of application attachments, fee confirmations), and in the temporary residence case also a passport scan (all pages) and application attachments — are stored encrypted in EU object storage (Amazon S3). One rule applies in both paid cases: a file is deleted when you confirm your UPO download, at the latest 60 days after the last change to your case, or 30 days after your access to the service ends — whichever comes first. Ten days before an inactivity deletion we email you a reminder; you can also delete a file yourself in the form. Temporary residence case files additionally go to a separate, versioned bucket encrypted with its own key (AWS KMS), kept apart from CUKR case data. In both paid cases we erase them immediately on account deletion, together with every version of the files.
How long we keep data
- ·Conversation history — for up to 24 months from your last activity in a conversation, after which it is deleted automatically. You can also clear your whole history yourself at any time (Settings → Privacy & Data).
- ·Chat attachments — the file for about 1 hour from upload; metadata — the same as the conversation history (24 months), and on account deletion.
- ·Account data — for the lifetime of the account. When you ask to delete your account, we deactivate it immediately and, after a 14-day grace period, permanently erase all related data — except data we must keep by law (accounting documents, section 06 of the Privacy Policy) and an erasure receipt containing only a one-way hash of your email address (section 06). During those 14 days you can restore the account by logging in again. An anonymous account (chat without registration), together with its conversations, is deleted automatically after 24 hours.
- ·Passkey data — if you enable it, we keep it until you remove that passkey in settings or delete your account.
- ·Chat cost and abuse telemetry (the counters used for cost and abuse protection) — for 90 days, after which it is deleted; we also delete it when you delete your account.
- ·Erasure receipts — kept indefinitely for accountability (GDPR Art. 5(2)). They contain only a one-way hash (HMAC) of the email address, timestamps and a count of the records deleted — no other personal data.
- ·Operational and security logs — for limited periods: application logs around 30 days, infrastructure logs around 90 days, audit logs up to about 13 months.
- ·Paper-application drafts (the application creator) — stored encrypted for the lifetime of your account and permanently deleted together with the account. If you download the finished PDF and don’t return to edit it, after 30 days we remove the most sensitive data from the draft (travel-document and previous-card series and number, parents’ names, place of birth). The PDF file itself is never stored on our servers: we generate it on demand and the only copy is yours. You can also have a draft deleted earlier by writing to privacy@dopomo.pl.
- ·Payment data (when you use a paid service) — billing data and accounting documents (e.g. invoices) are kept for the period required by accounting law (Art. 74 of the Accounting Act — about 5 years from the end of the financial year); the basis is our legal obligation (GDPR Art. 6(1)(c)).
- ·Recurring-payment token (recurring BLIK — a planned feature) — if you activate a subscription, we store only an opaque, encrypted payment-mandate token until the subscription ends; we also delete it when you delete your account.
- ·CUKR case data (paid service) — application sections are stored encrypted. When you confirm your UPO download, we remove the most sensitive data from the application (PESEL number, travel-document series and number, parents’ names, place of birth) and the uploaded files; independently of that, uploaded files are deleted at the latest 60 days after the last change to your case. The remaining case data stays encrypted on your account. Paid access has no expiry date, so we keep the data until you delete your account; if your access lapses or is revoked, we delete it automatically after 30 days. A free case not used for 12 months without a purchase is deleted automatically.
- ·Temporary residence case data (paid service) — application sections are stored encrypted for as long as you have access to the service. Paid access has no expiry date, so we keep the data until you delete your account; if your access lapses or is revoked, we delete it automatically after 30 days. A free case not used for 12 months without a purchase is deleted automatically.
- ·Files uploaded in the temporary residence case (passport scan, application attachments) — stored encrypted in a separate EU bucket and deleted when you confirm your UPO download, at the latest 60 days after the last change to your case, or 30 days after your access to the service ends — whichever comes first; we send a reminder 10 days before. You can also delete a file yourself in the form. On account deletion we erase them immediately, together with every version of the files.
- ·The facial photo uploaded in the CUKR case or the temporary residence case — stored encrypted in the EU under the same rule as every other uploaded file: the original photo from your device is deleted after 7 days at the latest, and the finished photo when you confirm your UPO download, at the latest 60 days after the last change to your case (if you run two CUKR cases at the same time, e.g. your own and your child's, we keep the finished photo until both cases are closed, but no longer than 90 days from its upload). On account deletion we erase it immediately.
Who we share your data with — sub-processors
We do not sell your data. Three groups of recipients see it. First — providers (processors) who act on our instructions, under data-processing agreements compliant with the GDPR; we list them in the table below. Second — people who work with the controller on user support and communication, described under the table. Third — independent recipients, listed further below: companies that use what they receive on their own terms rather than on our instructions — if you use the optional address-abroad search or turn on push reminders.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, logs | EU — Frankfurt (eu-central-1) |
| Google Cloud — Vertex AI (Gemini) | The AI model that generates answers | EU (europe-west4) |
| AWS Bedrock | Knowledge-base search support; may also act as an alternative AI model provider for chat (operator-selected) | EU |
| Brevo (Sendinblue) | Sends the email with your one-time sign-in code | EU (Paris) |
| Sentry | Error monitoring (replay masked) | EU (Germany) |
| Matomo (InnoCraft, Matomo Cloud EU) | Traffic analytics — cookieless by default; with cookies only if you consent to analytics cookies | EU — under a data-processing agreement (DPA) |
| Upstash | Durable rate-limit / abuse-protection store (transient IP for the active window) | EU — under the Upstash DPA and Standard Contractual Clauses (SCC) |
| Amazon CloudFront | Content delivery / reverse proxy | Global edge (under the AWS agreement) |
| Cloudflare | DNS and edge security on a global network; bot protection (Turnstile) on sign-up and chat forms | US-based processor — under the Cloudflare DPA and Standard Contractual Clauses (SCC, GDPR Art. 46(2)(c)) |
People we work with. Beyond the providers listed in the table, some of your data may be accessible to people who work with the controller on user support and communication — under a data-processing agreement (Article 28 GDPR) and bound by a duty of confidentiality. Scope: the account and case data visible in the support panel, in particular your name, e-mail address, case progress, product qualification result and any discount codes used, as well as the content of the correspondence you have with us on social media and in messaging apps. These people have no access to the content of your conversations with the assistant or to the encrypted data from application forms; if, at your request, they help you fill in an application, they do so on your account, in your presence and inside the app, and they do not ask for document scans.
Independent recipients. In the temporary residence case, an optional address search may be available. What you type into it, and the address you then pick, are sent from our server to Google Maps Platform. For this Google is an independent controller: it processes that data on its own terms, described in Google’s privacy policy, not on our instructions. We do not send Google your account identifier, your IP address, or any other field from your application. The search is optional — type the address by hand and nothing goes to Google at all. Google retains this data under its own privacy policy and on its own schedule, which we do not control.
| Independent recipient | Purpose | Region and safeguard |
|---|---|---|
| Google Maps Platform (Google Cloud Poland Sp. z o.o.) | Address suggestions for your address abroad in the temporary residence case (only if you use the optional search) — the text you type in the search box and the address you select | Ireland (EU) and the USA — independent controller under Google’s Maps Platform controller-to-controller terms; transfer under the EU–US Data Privacy Framework and Standard Contractual Clauses (SCC) |
| Browser push service providers (Google, Apple or Mozilla — depending on your browser) | Delivering deadline reminders to your device, if you turn notifications on. The provider receives your subscription’s endpoint address and the encrypted content of the notification — only your browser can decrypt it. | USA or a global network — the service is chosen by your browser, not by us. Google LLC: European Commission adequacy decision (EU–US Data Privacy Framework). In the case of Apple Inc. and Mozilla, we do not base the transfer on an adequacy decision or on an agreement with that provider; they receive only the subscription identifier they themselves issued to your browser, plus encrypted content they cannot read. You turn reminders on yourself and can turn them off at any time. |
Transfers outside the EEA
As a rule, we process all data within the European Economic Area (EEA). There are four exceptions. The first is the Amazon CloudFront content-delivery network, which operates at the global network edge; this takes place under our data-processing agreement with AWS, with appropriate safeguards. The second is Cloudflare, a US-based provider that handles DNS and edge protection on a global network; that transfer is covered by Cloudflare’s data-processing agreement (DPA) and Standard Contractual Clauses (SCC, GDPR Art. 46(2)(c)). The third applies only if you use the optional address-abroad search in the temporary residence case: the text you type and the address you pick are disclosed by us to Google Maps Platform (Google Cloud Poland Sp. z o.o.), an EU-established company — so our disclosure stays within the EU. Google, as independent controller, may then process that data on its own infrastructure in the USA — under Google’s own EU–US Data Privacy Framework basis and Google’s own Standard Contractual Clauses (SCC, GDPR Art. 46(2)(c)). The fourth arises if you turn on push reminders: your subscription address and the encrypted content of the notification are delivered by the push service your browser has chosen. If that is Google LLC, the transfer rests on the European Commission’s adequacy decision (EU–US Data Privacy Framework); if it is Apple Inc. or Mozilla, we do not base the transfer on an adequacy decision or on an agreement with that provider — it receives only the subscription identifier that the provider itself issued to your browser, and encrypted content it cannot read. Apart from these, we do not transfer your data outside the EEA.
Your rights (GDPR)
At any time you have the right to:
- ·access your data and obtain a copy of it,
- ·rectify data that is incorrect,
- ·erase data (the “right to be forgotten”),
- ·restrict or object to processing,
- ·transfer your data (data portability),
- ·withdraw consent without affecting earlier processing.
You can exercise most of these rights yourself in the app (Settings → Privacy & Data): download a copy of your data (export to a file), clear your conversation history, delete your account, and withdraw consent to processing your chat messages. If you prefer, write to privacy@dopomo.pl — we will respond within the one-month period set by the GDPR. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO, uodo.gov.pl).
Cookies
We use strictly-necessary cookies and a single cookie that remembers your interface language; these are always on. In the cookie banner you can additionally turn on two optional categories: Matomo analytics cookies (by default the analytics run without cookies; that consent is handled by our banner) and Google advertising and measurement cookies (for ad attribution and conversion measurement), which are denied by default under Google Consent Mode v2 and load only after you consent to marketing cookies. You can withdraw each consent at any time. You will find the details in the Cookie Policy.
Security
Login is by a one-time code sent to your email — we do not store any passwords. We encrypt data in transit (TLS) and at rest (encryption managed by our cloud provider), and access to it is restricted and monitored. For reliability monitoring we use Sentry, in which session replays are masked.
Where this feature is available, you can additionally turn on passkey sign-in (passkey / WebAuthn) — for example with Face ID or a fingerprint. It relies on public-key cryptography: there is no shared secret on our servers that could be stolen. Your passkey biometrics never leave your device — the fingerprint or face match used to unlock the passkey is performed by the device itself, and we only receive a cryptographic confirmation. Email sign-in (a one-time code) remains the way to recover access if you lose the device holding the passkey.
To protect the service from bots and abuse, we use Cloudflare Turnstile in the background in an invisible mode (no widget and no logo) on sign-up, the first chat message in signed-out mode, and the email sign-in request. To check that you are human, only technical signals are sent to Cloudflare: your IP address, a TLS connection fingerprint, browser information (user agent), and our public site key and page origin. They are used solely to detect and block bots — not to profile or identify you — and Cloudflare cannot directly identify you from them. The legal basis is our legitimate interest in security (GDPR Art. 6(1)(f)); Cloudflare acts as a processor under a data-processing agreement (DPA) and Standard Contractual Clauses (SCC).
Analytics
To understand how you use the service and to improve it, we measure traffic with Matomo configured by default in a cookieless mode. We remain the controller (Dopomo); Matomo (InnoCraft) acts as a processor, hosted in the European Union, under a data-processing agreement (DPA).
Within analytics we process only an anonymised IP address and page/event metadata (e.g. pages visited, funnel steps, campaign parameters). We do not build profiles, we do not use a User-ID, and we do not track you across services. The legal basis is our legitimate interest (GDPR Art. 6(1)(f)) in measuring and improving the service; because in its default mode the analytics store nothing on your device, the ePrivacy consent requirement is not triggered; we enable Matomo analytics cookies only after you consent in the banner.
We delete raw analytics data after the period set in our Matomo Cloud account (currently 6 months); only aggregated, summary reports — which cannot identify an individual — are kept longer. You have the same rights as set out above. You can opt out of measurement by turning on the “Do Not Track” setting in your browser (which we honour) or by switching off “Measurement without cookies” in the cookie settings (the “Cookie settings” link in the footer) — see the Cookie Policy for details.
When you start using the assistant (including without an account) or create an account, we record once how you reached the service: the first page you visited and where you came from — a search engine, a link on another site or campaign parameters. This happens on our server, with no cookies and nothing stored in your browser, solely so we know which channels bring people to us (legitimate interest, GDPR Art. 6(1)(f)). Advertising click identifiers (e.g. gclid) are stored only if you have previously consented to marketing cookies, and are removed as soon as you withdraw that consent. If you switch off “Measurement without cookies”, none of this is recorded at all. We keep it for as long as the account exists and delete it together with the account.
Payments and our payment provider
If you use a paid service (the CUKR case, the temporary residence case or the Plus access pass), payment is handled by Autopay S.A. (formerly Blue Media S.A.), based in Sopot. For carrying out and settling the payment and the related anti-abuse obligations, Autopay is an independent controller of your data — it processes the data for its own purposes and under its own privacy policy, not as our processor.
We send Autopay only the data needed to initiate the payment: your email address, an internal user identifier and product identifier, and the amount and currency. We do not send Autopay your PESEL number, your citizenship, the content of your conversations, or any documents from your case.
Billing data and accounting documents related to payments are kept for the period required by accounting law (Art. 74 of the Accounting Act — about 5 years), on the basis of a legal obligation (GDPR Art. 6(1)(c)); see "How long we keep data".
Changes to the policy
If we change this policy, we will update the date at the top, and we will inform you of material changes in the app or by email. Continued use of Dopomo means acceptance of the updated version.