Legal

Privacy policy

What we collect, why, who else sees it, and what you can ask us to do about it.

Last updated 2026-07-28

01Who controls your data

The data controller is Roman Kot, a sole trader registered in the Polish CEIDG register. For anything in this policy, write to [email protected].

Controller
Roman Kot
Business address
[SERVICE ADDRESS (adres do doręczeń) — TODO]
Register
REGON 220879358
Privacy contact
[email protected]

We have not appointed a data protection officer; we are not required to.

02What we collect

  • Account data — your email address and a hashed password. Passwords are hashed with Argon2 and are never stored or transmitted in a readable form.
  • Conversations— the messages you send, the assistant’s replies, and any files you attach.
  • Drawing-derived data — this is the part worth being explicit about. To answer questions about your drawing, the assistant reads parts of it: entity geometry, layer names, block and text content, coordinates, and similar. That data is included in the request we send to the model provider handling your message. It can contain anything your drawing contains, including client names, addresses and project details in text objects or title blocks. We never receive or store your DWG file itself.
  • Usage data — message counts for metering, and aggregate cost and model telemetry so we can run the service sustainably.
  • Billing data — held by Stripe. We store only your Stripe customer id, plan, subscription status and renewal date. We never see your full card number.
  • Technical data — standard server logs, and a hashed form of your IP address used to rate-limit sign-ups. We do not keep raw IP addresses for that purpose.
  • Product analytics — how the product is used, so we can tell which parts work. Pages viewed, buttons clicked, which effort mode you chose, which tool the assistant ran and whether it succeeded, and rough device and country. This records the shape of what you did, never the content: no message text, no assistant replies, and none of the drawing-derived data above. Analytics is described in clause 8, and you can turn it off.

We do not run advertising or cross-site tracking of any kind, we do not sell or share analytics data with anyone, and we do not buy or enrich data about you from third parties.

03Why we process it, and on what basis

  • To provide the service — accounts, conversations, model requests, file storage. Legal basis: performance of our contract with you.
  • To bill you — subscriptions, invoices, tax. Legal basis: contract, and legal obligation for tax records.
  • To keep the service working and safe — metering, rate limits, anti-abuse, debugging. Legal basis: our legitimate interest in a service that stays available and is not abused.
  • To understand how the product is used— which features earn their place and where they fail. Legal basis: on this website, your consent, asked for by the banner and withdrawable at any time; inside the app, our legitimate interest in improving a product you are signed in to and paying for. Either way you can object — see clause 8.
  • To contact you about your account — password resets, security notices, changes to terms. Legal basis: contract and legal obligation.

We do not use your content to train models, and we do not sell your data. We do not make decisions with legal or similarly significant effects about you by automated means.

04Model providers

When you send a message, we route it to one of the model providers we operate with. You choose how much effort to spend on a request — Standard, Heavy or Extreme — and we decide which model serves that choice. The providers we may route to are named in the table below; today they are Anthropic and OpenAI, and we will not add one without updating that table first. The request contains your message, the relevant conversation history, and the drawing-derived data described above.

Those providers process the request to generate a response, under their own API terms. If you work with drawings containing personal data or material under a confidentiality obligation, consider that this is the point at which it leaves our systems, and satisfy yourself that the providers listed below are acceptable for that work — including any controller-to-processor arrangements your own clients require of you. If you need to know which provider handled a specific request, ask us.

05Who else processes your data

We use the following processors. Each is bound by a data processing agreement and may only act on our instructions.

ProcessorWhat it doesWhere
AnthropicClaude models — processes prompts, including drawing-derived dataUnited States
OpenAIGPT models — processes prompts, including drawing-derived dataUnited States
VercelApplication hosting and request logsUnited States / EU
NeonManaged Postgres — accounts, conversations, message contentEU
CloudflareR2 object storage for files you attach, and Turnstile anti-abuse on sign-upEU / global edge
StripePayments, invoicing and tax calculation; holds your billing detailsUnited States / EU
ZeptoMail (Zoho)Transactional email — password reset, invites, account noticesEU
PostHogProduct analytics — which features are used and where they fail; never message or drawing contentEU

06International transfers

Some processors above are in the United States. Where that is the case, transfers are covered by the European Commission’s standard contractual clauses, or by the EU–US Data Privacy Framework where the provider is certified under it. You can ask us for details of the safeguards that apply to a specific provider.

07How long we keep it

  • Conversations and files — until you delete them, or until your account is closed.
  • Account data — for as long as the account exists. After closure we delete it within 30 days.
  • Billing records — kept for as long as tax law requires, currently five years from the end of the accounting year in Poland. These survive account closure because we are obliged to keep them.
  • Usage and cost records — aggregate figures we keep to run the business; not linked to conversation content.
  • Product analytics — kept for 12 months, then deleted by our analytics provider on a rolling basis.
  • Password reset tokens — one hour, and single-use.
  • Server logs — a short rolling window at our hosting provider.

08Cookies and analytics

Two cookies are strictly necessary and are always set:

  • a session cookie, which keeps you signed in;
  • NEXT_LOCALE, which remembers whether you chose English or Polish.

Strictly necessary cookies do not require consent. Cloudflare Turnstile, used on the sign-up form to block automated abuse, may set its own short-lived technical token for the same purpose.

Analytics cookies are set by PostHog, our product analytics provider, and they are not strictly necessary. We treat the two surfaces differently, and it is worth being plain about which is which:

  • On this website — nothing is stored on your device and nothing is sent until you accept the banner. Decline and no analytics cookie is ever set.
  • Inside the app, once you are signed in, analytics runs by default without a separate banner, on the legitimate interest described in clause 3. You can switch it off at any time in Settings, and if you declined on this website, that decision carries over — we do not re-enable analytics for someone who has already said no.

Analytics data is processed in the EU and is never used for advertising, never sold, and never combined with data from other sites. If you would rather we deleted the analytics history associated with your account, email [email protected] and we will.

09Your rights

Under the GDPR you can ask us to:

  • give you a copy of the data we hold about you;
  • correct it if it is wrong;
  • delete it (subject to records we must keep by law);
  • restrict or object to processing based on our legitimate interests;
  • export your data in a portable form.

Email [email protected] and we will respond within one month. You can delete conversations yourself at any time from the app.

If you think we have handled your data badly, please tell us first — but you have the right to complain to a supervisory authority. Ours is the Prezes Urzędu Ochrony Danych Osobowych (UODO), and you may also complain to the authority where you live.

10Security

Traffic is encrypted in transit. Passwords are hashed with Argon2. Uploaded files live in a private bucket and are only readable through an authenticated route — never a public link. Signing in from a new device ends the previous session, and changing your password ends every session and tells you by email that it happened.

No system is perfectly secure. If you find a vulnerability, please report it to [email protected] rather than disclosing it publicly, and we will work with you on it.

11Children

cadssistant is a professional tool and is not directed at children. You must be at least 16 to hold an account.

12Changes to this policy

If we change this policy materially — a new category of data, a new purpose, or a new processor with access to your content — we will tell you by email before it takes effect. The date at the top always reflects the current version. See also our terms of service.