Your data belongs to you
Dopomo was built to help people in an unfamiliar system. That is why we take privacy seriously — we collect as little data as possible and tell you plainly what happens to it.
Data controller and contact
The controller of your personal data is RunProven AI Sp. z o.o., based in Wrocław (ul. Leszczyńskiego 4/25, 50-078 Wrocław), NIP: 8971972885, the operator of the Dopomo brand. For data protection matters, write to privacy@dopomo.pl.
We have not appointed a Data Protection Officer (DPO) — at our scale and type of activity this is not required (GDPR Art. 37). The contact point for data protection matters is privacy@dopomo.pl. The supervisory authority is the President of the Personal Data Protection Office (PUODO, uodo.gov.pl).
Dopomo is an independent AI assistant. We are not a public administration authority or a law firm, and we do not file applications on your behalf. The official government portal is mos.cudzoziemcy.gov.pl/en/.
What data we process
We process only the data needed for the assistant to work and for you to return to your conversations:
- ·Account data — your email address (for magic-link login) and, after the first login, your name and citizenship, which you provide voluntarily.
- ·The content of your conversations with the assistant — the questions you ask and the answers you receive. This is the most sensitive category of data; we store it so that you can access your account history.
- ·Settings — your chosen language and email notification preferences.
- ·Technical session data — your IP address, browser information (user agent) and timestamps, and a record of the consents you have given.
- ·Passkey data — if you turn on passkey sign-in (WebAuthn/passkey), we store a public key, a credential ID and device metadata: the AAGUID (authenticator model), a sign counter and the available transports. For passkeys we never receive or store biometric data — fingerprint or face matching happens entirely on your device.
- ·Application data — if you use the paper-application creator or the paid case assistants (CUKR, TRC), we store the data you enter into the form: identity data (names, surname, date and place of birth), travel-document data (e.g. series and number), residential address, residence status and contact details. We store it only in encrypted form; retention periods are described in section 06, and the data we never record — in section 05.
Purposes and legal bases (GDPR)
We process your data on the basis of the GDPR (EU Regulation 2016/679):
- ·Providing the service — Art. 6(1)(b): maintaining your account and giving access to your conversation history. Passkey sign-in, if you enable it, rests on the same basis — it is an authentication method within the account-use contract.
- ·Security and operation of the service — Art. 6(1)(f): our legitimate interest in protecting the account and the service against abuse, including rate-limiting and chat cost and abuse protection.
- ·Chat content — Art. 9(2)(a): you cannot use chat without your explicit consent; it is a prerequisite to using the assistant, not an option (see the special-category data section for details).
- ·Optional notifications and news — Art. 6(1)(a): solely with your consent, which you can withdraw at any time.
AI assistant — how it works
You are talking to an AI-based assistant, not a human (AI Act Art. 50). So that the assistant can respond, the content of your conversation is sent to our language-model provider. Our primary model provider for chat is Google Vertex AI (Gemini), in a European Union region (europe-west4). We may also, at the choice of our administrators, use AWS Bedrock (an EU region) as an alternative model provider. Both providers operate in the EU under data-processing agreements (DPAs) and standard contractual clauses (SCCs), so the data does not leave the EEA in order to generate an answer.
Under our AI provider’s terms of service, the content of your conversations is not used to train its models.
To find sources relevant to your question, the text of your query is sent to AWS Bedrock (an EU region) for knowledge-base retrieval and to compute vector representations (embeddings). The provider of this service does not use the text it receives to train its models.
Special-category data (GDPR Art. 9 and 10)
In ordinary use of the chat assistant we do not ask for special-category data (e.g. about health, origin, religion) or criminal-record data (GDPR Art. 9 and 10) — we do not need them to help you.
If you nonetheless voluntarily provide such data in a conversation, the basis for processing it is your explicit consent (GDPR Art. 9(2)(a)). We ask for this consent in a simple, one-time way before you send your first message to the assistant — we explain what the model processes and ask you to confirm. It is a prerequisite to using chat: without giving it, you cannot send a message to the assistant. You can withdraw the consent at any time in Settings (Privacy & Data); withdrawal is as easy as giving it and does not affect the lawfulness of processing before withdrawal. You can also write to privacy@dopomo.pl.
Files uploaded in the paid CUKR Assistant (e.g. scans of application attachments, fee confirmations) are stored encrypted in EU object storage (Amazon S3) and deleted at the latest 7 days after upload, as well as when you confirm your UPO download and on account deletion.
How long we keep data
- ·Conversation history — for up to 24 months from your last activity in a conversation, after which it is deleted automatically. You can also clear your whole history yourself at any time (Settings → Privacy & Data).
- ·Account data — for the lifetime of the account. When you ask to delete your account, we deactivate it immediately and, after a 14-day grace period, permanently erase all related data. During those 14 days you can restore the account by logging in again.
- ·Passkey data — if you enable it, we keep it until you remove that passkey in settings or delete your account.
- ·Chat cost and abuse telemetry (the counters used for cost and abuse protection) — for 90 days, after which it is deleted; we also delete it when you delete your account.
- ·Erasure receipts — kept indefinitely for accountability (GDPR Art. 5(2)). They contain only a one-way hash (HMAC) of the email address, timestamps and a count of the records deleted — no other personal data.
- ·Operational and security logs — for limited periods: application logs around 30 days, infrastructure logs around 90 days, audit logs up to about 13 months.
- ·Paper-application drafts (the application creator) — stored encrypted for the lifetime of your account and permanently deleted together with the account. If you download the finished PDF and don’t return to edit it, after 30 days we remove the most sensitive data from the draft (travel-document and previous-card series and number, parents’ names, place of birth). The PDF file itself is never stored on our servers: we generate it on demand and the only copy is yours. You can also have a draft deleted earlier by writing to privacy@dopomo.pl.
- ·Payment data (when you use a paid service) — billing data and accounting documents (e.g. invoices) are kept for the period required by accounting law (Art. 74 of the Accounting Act — about 5 years from the end of the financial year); the basis is our legal obligation (GDPR Art. 6(1)(c)).
- ·Recurring-payment token (recurring BLIK — a planned feature) — if you activate a subscription, we store only an opaque, encrypted payment-mandate token until the subscription ends; we also delete it when you delete your account.
- ·CUKR case data (paid assistant) — application sections are stored encrypted. When you confirm your UPO download, we remove the most sensitive data from the application (PESEL number, travel-document series and number, parents’ names, place of birth) and the uploaded files. The remaining case data stays encrypted on your account; we delete it on account deletion, and — once your access to the service lapses — automatically after 30 days.
- ·TRC case data (paid assistant) — application sections are stored encrypted; after your access to the service lapses we delete them automatically after 30 days, and earlier on account deletion.
Who we share your data with — sub-processors
We do not sell your data. We use carefully selected providers (processors) who act on our instructions, under data-processing agreements compliant with the GDPR:
Transfers outside the EEA
As a rule, we process all data within the European Economic Area (EEA). One exception is the Amazon CloudFront content-delivery network, which operates at the global network edge; this takes place under our data-processing agreement with AWS, with appropriate safeguards. DNS and edge-protection functions are provided by Cloudflare, a US-based provider operating on a global network; this transfer is covered by Cloudflare’s data-processing agreement (DPA) and Standard Contractual Clauses (SCC, GDPR Art. 46(2)(c)). Apart from these, we do not transfer your data outside the EEA.
Your rights (GDPR)
At any time you have the right to:
- ·access your data and obtain a copy of it,
- ·rectify data that is incorrect,
- ·erase data (the “right to be forgotten”),
- ·restrict or object to processing,
- ·transfer your data (data portability),
- ·withdraw consent without affecting earlier processing.
You can exercise most of these rights yourself in the app (Settings → Privacy & Data): download a copy of your data (export to a file), clear your conversation history, delete your account, and withdraw consent to processing your chat messages. If you prefer, write to privacy@dopomo.pl — we will respond within the one-month period set by the GDPR. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO, uodo.gov.pl).
Cookies
We use strictly-necessary cookies and a single cookie that remembers your interface language; these are always on. We also use optional Google advertising and measurement cookies (for ad attribution and conversion measurement) that are denied by default under Google Consent Mode v2 and load only with your consent via our cookie banner; you can withdraw that consent at any time. You will find the details in the Cookie Policy.
Security
Login is by a magic link sent to your email — we do not store any passwords. We encrypt data in transit (TLS) and at rest (encryption managed by our cloud provider), and access to it is restricted and monitored. For reliability monitoring we use Sentry, in which session replays are masked.
Where this feature is available, you can additionally turn on passkey sign-in (passkey / WebAuthn) — for example with Face ID or a fingerprint. It relies on public-key cryptography: there is no shared secret on our servers that could be stolen. Your passkey biometrics never leave your device — the fingerprint or face match used to unlock the passkey is performed by the device itself, and we only receive a cryptographic confirmation. The magic link sent to your email remains the way to recover access if you lose the device holding the passkey.
To protect the service from bots and abuse, we use Cloudflare Turnstile in the background in an invisible mode (no widget and no logo) on sign-up, the first chat message in signed-out mode, and the magic-link request. To check that you are human, only technical signals are sent to Cloudflare: your IP address, a TLS connection fingerprint, browser information (user agent), and our public site key and page origin. They are used solely to detect and block bots — not to profile or identify you — and Cloudflare cannot directly identify you from them. The legal basis is our legitimate interest in security (GDPR Art. 6(1)(f)); Cloudflare acts as a processor under a data-processing agreement (DPA) and Standard Contractual Clauses (SCC).
Analytics
To understand how you use the service and to improve it, we measure traffic with Matomo configured in a cookieless mode. We remain the controller (Dopomo); Matomo (InnoCraft) acts as a processor, hosted in the European Union, under a data-processing agreement (DPA).
Within analytics we process only an anonymised IP address and page/event metadata (e.g. pages visited, funnel steps, campaign parameters). We do not build profiles, we do not use a User-ID, and we do not track you across services. The legal basis is our legitimate interest (GDPR Art. 6(1)(f)) in measuring and improving the service; because the analytics store nothing on your device, the ePrivacy consent requirement is not triggered.
We keep raw analytics data for at most 6 months, after which it is deleted; only aggregated, summary reports — which cannot identify an individual — are kept longer. You have the same rights as set out above. You can opt out of measurement by turning on the “Do Not Track” setting in your browser (which we honour) or by using the Matomo opt-out form — see the Cookie Policy for details.
Payments and our payment provider
If you use a paid service (e.g. the CUKR case), payment is handled by Autopay S.A. (formerly Blue Media S.A.), based in Sopot. For carrying out and settling the payment and the related anti-abuse obligations, Autopay is an independent controller of your data — it processes the data for its own purposes and under its own privacy policy, not as our processor.
We send Autopay only the data needed to initiate the payment: your email address, an internal user identifier and product identifier, and the amount and currency. We do not send Autopay your PESEL number, your citizenship, the content of your conversations, or any documents from your case.
Billing data and accounting documents related to payments are kept for the period required by accounting law (Art. 74 of the Accounting Act — about 5 years), on the basis of a legal obligation (GDPR Art. 6(1)(c)); see "How long we keep data".
Changes to the policy
If we change this policy, we will update the date at the top, and we will inform you of material changes in the app or by email. Continued use of Dopomo means acceptance of the updated version.