CityChat Privacy Policy
This policy explains what personal data the CityChat mobile app (iOS and Android) and the CityChat for Business portal process, why, and what rights you have. Business-specific processing is described in section 7. It is written to be read, not skimmed past — it is short because the service collects little.
Last updated: 24 July 2026 · wersja polska
1. Who is responsible (controller)
Applied AI sp. z o.o.
ul. Marcina Bielskiego 44C/15, 37-700 Przemyśl, Poland
KRS 0001187092 · NIP 7952588091
E-mail: [email protected]
2. What we process, why, and on what legal basis
| Data | Why we process it | Legal basis (GDPR) |
|---|---|---|
| E-mail address | Creating and signing in to your account (magic link, Sign in with Apple on iOS, or Sign in with Google on Android) | Art. 6(1)(b) — performance of a contract |
| Account identifier | Linking your chats, subscription status, and settings to your account | Art. 6(1)(b) |
| Chat messages | Generating answers about the city you are exploring | Art. 6(1)(b) |
| Photos you take in visual search | Recognising the landmark or place in the photo and answering about it | Art. 6(1)(b) — processed only when you take a photo for that purpose |
| AI memory — durable preferences you reveal in chat (optional, off by default) | Personalising future answers: when you switch AI memory on, the app can remember facts you state in chat — dietary preferences, accessibility needs, who you travel with, lasting interests. Because such facts can reveal health information or religious beliefs, they are stored only with your explicit consent and you can view and delete every remembered fact in Settings → AI memory | Art. 6(1)(a) and Art. 9(2)(a) — explicit consent via the AI memory switch; withdraw any time by switching it off or deleting entries |
| Visual-search query log (what a scan identified) | Enforcing daily scan limits and improving recognition quality | Art. 6(1)(b); Art. 6(1)(f) for quality review |
| Usage statistics; aggregate analysis of questions and searches | Understanding which features are used and what people ask, to improve the app | Art. 6(1)(f) — our legitimate interest; you can object at any time (Art. 21) |
| Precise location | Showing and answering about places near you; notifications when you walk past notable places, including clearly labelled partner (sponsored) places — active once you grant the location and notification permissions the app asks for after sign-in | Art. 6(1)(a) — consent, given through the iOS or Android location permission and withdrawable any time: switch off "Geofence notifications" in the app's Settings or revoke the permission in your device's Settings |
| Push notification token | Delivering notifications you have enabled | Art. 6(1)(a) — consent via the iOS or Android notification permission |
| E-mail address — newsletter (optional, off by default) | Sending our occasional newsletter: news from your cities, new features, and CityChat offers. Sent only if you sign up for it; every message contains an unsubscribe link | Art. 6(1)(a) — consent, which is also the consent for commercial e-mail required by art. 398 of the Polish Electronic Communications Law (Dz.U. 2024 item 1221); withdraw any time via the unsubscribe link or in the app — withdrawing is as easy as signing up |
| IP address and technical request logs | Keeping the service secure: abuse prevention, rate limiting, fault diagnosis | Art. 6(1)(f) — our legitimate interest in running a secure service |
| Subscription status | Unlocking PRO features you purchased | Art. 6(1)(b). Payment itself is handled entirely by Apple (iOS) or Google (Android) — we never see your payment details |
We do not show ads, do not sell or share data for advertising, do not track you across other apps or websites, and do not make automated decisions that produce legal effects about you. The only marketing e-mails we ever send are our own newsletter — and only to users who signed up for it.
3. Who receives your data (processors)
We use a small number of service providers, each bound by a data processing agreement:
- Google (Gemini API) — processes your chat messages and visual-search photos to generate answers. If you enable AI memory, your remembered facts are included alongside your chat messages; Visual Search also sends a short list of catalogued places near your device location so answers can be grounded in your surroundings. Under our paid API agreement Google acts as our processor and does not use this content to train or improve its models. Processing may involve transfers outside the EEA, safeguarded by the EU Standard Contractual Clauses and Google's participation in the EU–US Data Privacy Framework.
- Apple — Sign in with Apple, push notification delivery (APNs), and subscription payments on iOS.
- Google (Firebase Cloud Messaging, Google Play) — on Android, push notification delivery and subscription payments. (Separate from the Gemini API processing above; the same provider, different services.)
- Resend (Plus Five Five, Inc., USA) — delivery of sign-in (magic link) and account e-mails and — if you sign up for it — our newsletter; it processes your e-mail address and the message content. We send through Resend's EU region (Ireland); as a US provider it may process some data in the United States, safeguarded by the EU Standard Contractual Clauses incorporated in its data processing agreement.
- Cloudflare — database backups, encrypted in transit (TLS) and at rest by the storage provider, stored exclusively under Cloudflare R2's European Union jurisdiction.
Web search (optional). When you explicitly accept the app's offer to search the web about a place in chat, our server sends a search query to Tavily (AlphaAI Technologies Inc., USA). The query consists of the catalogued place name and city only — it never includes your message text, your account identifier, your IP address, or any other personal data, so no personal data is disclosed to Tavily.
The application servers and database are operated by us in Poland (EU).
4. How long we keep data
- Account data, chat history, and AI-memory entries: until you delete them or delete your account.
- Sign-in tokens and expired sessions — including the IP address recorded when a sign-in link is requested: deleted automatically within 7 days of the token expiring or being used.
- Usage logs (visual-search queries and notification history): kept for up to 90 days, then deleted automatically.
- Newsletter consent records: your opt-in status is kept while you stay subscribed; after you unsubscribe or delete your account we keep only a minimal record of when consent was given and withdrawn, for as long as needed to demonstrate GDPR compliance (accountability, Art. 5(2)).
- Advertising-transparency records (which sponsored result was shown, kept to meet ad-disclosure obligations): retained for up to 2 years; the link to your account is removed as soon as your account is deleted.
- Database backups: rotated automatically; any backup is deleted no later than 30 days after it was made, so deleted data leaves backups within 30 days.
- Technical logs: short-lived and rotated automatically; not archived.
5. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), and the right to withdraw consent at any time (nearby-place notifications have a dedicated toggle in the app's Settings, location and notifications can be switched off in your device's Settings, and every newsletter e-mail contains an unsubscribe link; withdrawal does not affect processing that happened before it).
To exercise any of these, e-mail [email protected]. You also have the right to lodge a complaint with a supervisory authority (Art. 77) — in Poland this is the President of the Personal Data Protection Office (PUODO, uodo.gov.pl), or the authority in your own EU country.
6. Children
CityChat is not directed at children. We do not knowingly process personal data of children below 16; if you believe a child has created an account, contact us and we will delete it.
7. CityChat for Business (B2B portal)
If you register a business on the CityChat for Business portal, we process additional data about you and your business. The controller (section 1), your rights (section 5), and our processors (section 3) are the same as for the app, with one difference: business subscriptions are invoiced by us directly — they do not go through Apple or Google. Invoicing and accounting records may additionally be shared with our accounting service providers and with public authorities (for example, tax authorities) where the law requires it.
Providing the registration data (e-mail, business name, NIP, contact details) is necessary to create a business account and, for paid plans, to issue invoices — without it we cannot open the account.
| Data | Why we process it | Legal basis (GDPR) |
|---|---|---|
| Business owner e-mail address | Creating and signing in to your business account (magic link); operational contact | Art. 6(1)(b) — performance of a contract |
| Business details you enter — name, NIP, contact e-mail, phone, address | Operating your business listing and issuing invoices; for sole traders (JDG) the NIP and address are personal data | Art. 6(1)(b); Art. 6(1)(c) — compliance with our accounting and tax obligations |
| Place-ownership claim evidence — the official e-mail, social-media profile, phone, and note you submit to prove you represent a place | Manually verifying that you are entitled to manage the place you claim | Art. 6(1)(b); Art. 6(1)(f) — our legitimate interest in preventing false claims |
| Sign-in IP address and last-sign-in time | Keeping the portal secure: abuse prevention, rate limiting, fault diagnosis | Art. 6(1)(f) — our legitimate interest in running a secure service |
How long we keep it:
- Business account and listing data: kept while your business account is active; deleted when the account is closed, subject to the invoicing retention below.
- Invoicing and accounting records: kept for the 5 years Polish accounting and tax law requires — counted from the beginning of the year following the financial year the document concerns, and in any case until the related tax liability's limitation period ends, i.e. 5 years from the end of the calendar year in which the tax payment deadline fell (art. 74 of the Accounting Act; art. 86 § 1 and art. 70 § 1 of the Tax Ordinance).
- Sign-in tokens and the IP recorded when a sign-in link is requested: deleted automatically within 7 days of the token expiring or being used.
- Place-claim evidence: a pending claim is kept until it is decided; an approved claim is kept while your ownership of the place remains active, as the record that it was verified. A rejected claim — including an ownership that was later removed — is deleted automatically 2 years after the decision (kept that long so we can recognise repeated false claims). Closing your business account deletes all your claims immediately.
To exercise any of your rights, or to close your business account, e-mail [email protected].
8. Changes
We will update this policy when the service's data processing changes and show the new version here with a new "last updated" date before it takes effect.