Legal
Privacy Policy
This Privacy Policy explains how personal data is processed when you use fovio-app.com, purchase a guide, communicate with us or use the Fovio mobile application.
Last updated: August 31, 2026
1. Scope and data controller
This Policy applies to the Fovio website, digital guides and mobile application (together, the "Service"). The Service is operated by BL17 Group Borys Lenartowicz, a sole proprietorship established in Poland. We are the controller of the personal data described in this Policy unless a section states otherwise. Full company details are available in the Terms of Service.
Questions and requests concerning personal data should be sent to privacy@fovio-app.com.
2. Personal data processed on the website
2.1 Waitlist and marketing communications
If you join the app waitlist, we process your email address to register your request and notify you about the launch. Marketing communications require a separate, optional consent. You may withdraw that consent at any time by using the unsubscribe link in an email or contacting us.
2.2 Purchases of Guides
Paddle.com acts as merchant of record for Guide purchases. Paddle processes information required to complete the transaction, including your name, email address, payment information, billing country and tax information. Paddle acts as an independent controller for its payment processing activities. Its practices are described in the Paddle Privacy Notice.
We receive the information required to fulfil and support the order, including your email address, order number, purchased Guide and transaction status. We do not receive full payment card details.
2.3 Browser-based tests
Tests offered on the website are completed entirely in your browser. Test answers and results are not transmitted to our servers and are not stored by us.
2.4 Cookies, analytics and advertising measurement
We store the cookie required to remember your consent choice. Google Analytics 4, Microsoft Clarity and Meta Pixel are made available through Google Tag Manager only after you consent. Further information is provided in the Cookie Policy.
2.5 Correspondence
When you contact us, we process your contact details, the content of the correspondence and any information needed to answer the request, provide support, establish what was agreed or protect legal claims.
3. Personal data processed in the App
This section applies when the Fovio mobile application becomes available.
3.1 Account data
We process your email address, authentication information, account identifiers and account settings to create, secure and administer your account.
3.2 User content and special-category data
The App processes your episode answers, diary entries, situation analyses, confirmations and personal map. This content may reveal information about your health, sex life, sexual orientation, religious or philosophical beliefs, or other special categories of personal data within Article 9 of the GDPR. We process this content only on the basis of your explicit consent under Article 9(2)(a). You may withdraw that consent at any time, but the App will then be unable to provide the features that depend on this content.
App content is stored in the European Union using Supabase infrastructure in Frankfurt, Germany. We do not sell this content, disclose it to advertisers or use it for advertising.
3.3 Subscriptions and technical data
Apple or Google processes the payment for an in-app subscription. We and RevenueCat receive the purchase and entitlement information needed to activate and manage access, but not your full card details. We may also process device type, operating system, App version, diagnostic events and crash information to maintain security and reliability.
3.4 AI-assisted features
Some features use artificial intelligence to analyse user content, personalise output and operate the situation-analysis chat. Requests are sent through our servers and are not made directly from the App to an AI provider. We require the provider not to use Fovio user content to train models made available to other customers. We will identify the selected AI provider in this Policy before the App launches.
4. Purposes and legal bases
| Purpose | Personal data | Legal basis |
|---|---|---|
| Administering the waitlist and optional marketing | Email address and consent record | Consent, Article 6(1)(a) GDPR |
| Fulfilling and supporting Guide orders | Contact, order and transaction data | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c) |
| Remembering cookie choices and protecting the website | Consent choice and limited technical data | Legitimate interests, Article 6(1)(f) |
| Analytics and advertising measurement | Cookie identifiers and website usage data | Consent, Article 6(1)(a) |
| Responding to correspondence and protecting claims | Contact details and message content | Contract, Article 6(1)(b), or legitimate interests, Article 6(1)(f) |
| Providing and securing an App account and subscription | Account, entitlement and technical data | Contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f) |
| Building the personal map and providing AI-assisted features | User content and derived observations | Consent, Article 6(1)(a), and explicit consent, Article 9(2)(a) |
| Maintaining statutory accounting and tax records | Required transaction records | Legal obligation, Article 6(1)(c) |
5. Whether providing data is required
Providing personal data is voluntary. An email address is required to join the waitlist, receive a purchased Guide or create an App account. Transaction information is required to complete and support a purchase. If you do not provide explicit consent for App content, Fovio cannot analyse that content or build your personal map. Refusing optional marketing, analytics or marketing cookies does not prevent use of the remaining Service.
6. Profiling and automated decision-making
The App uses a scoring engine and AI-assisted processing to identify patterns and build a personal map from your answers and content. This constitutes profiling for GDPR purposes. It does not produce decisions that have legal effects or similarly significant effects within Article 22 GDPR. The map is shown only to you, is not used to determine access to employment, credit, insurance or other services, and is not disclosed to advertisers. The App presents its observations for you to confirm, partially confirm or reject.
7. Recipients of personal data
We disclose personal data only where necessary to operate the Service, fulfil a transaction, comply with law or protect legal rights. Relevant recipients are Supabase for EU-hosted database and authentication services; Vercel for website hosting; Paddle as merchant of record for Guides; and RevenueCat for subscription entitlement management. Apple and Google process in-app purchases under their own platform terms and privacy notices.
Only after cookie consent, Google receives analytics and tag-management data, Microsoft receives Clarity usage data, and Meta receives advertising-measurement data. We will identify the selected email delivery provider and AI provider in this Policy before the App launches and before either provider receives personal data.
8. International data transfers
Some recipients may process personal data outside the European Economic Area, including in the United States. Where such a transfer occurs, we use an applicable adequacy decision, including the EU-US Data Privacy Framework for participating recipients, or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required. You may request information about the safeguards by contacting privacy@fovio-app.com.
9. Retention periods
| Data | Retention period or criterion |
|---|---|
| Waitlist and marketing data | Until you withdraw consent, unsubscribe or the relevant list is closed |
| Guide purchase records | Five full years where required by Polish tax and accounting law |
| Correspondence | For as long as required to resolve the matter and, where necessary, establish or defend claims |
| App account and user content | Until account deletion; deletion from active systems is completed within 30 days, subject to records required by law |
| Technical and security data | For no longer than necessary to maintain, secure and diagnose the Service, after which it is deleted or aggregated |
| Cookies | For the periods specified in the Cookie Policy |
10. Your data-protection rights
Subject to the conditions in applicable law, you may request access to and a copy of your personal data; rectification; erasure; restriction of processing; data portability; or information about international-transfer safeguards. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting processing carried out before withdrawal.
Send a request to privacy@fovio-app.com. We may request information reasonably necessary to verify your identity and will respond within the period required by law, normally one month under the GDPR.
You may lodge a complaint with the Polish supervisory authority, the UODO, or with the competent authority in the country where you live, work or believe an infringement occurred. If the UK GDPR applies, you may complain to the ICO.
11. Account and data deletion
When the App is available, you may delete your account from the App settings. You may also request deletion without access to the App by emailing privacy@fovio-app.com from the address associated with the account. Deletion covers the account, diary entries, episode answers, situation analyses, confirmations and personal map. We retain only records that must be kept by law. Account data is removed from active systems within 30 days after a valid deletion request.
12. Age requirement
The Service is intended for persons aged 16 or over. We do not knowingly collect personal data from anyone under 16. If you believe that a person under 16 has provided personal data, contact us so that we can investigate and delete it where appropriate.
13. Security and personal-data breaches
We use technical and organisational measures appropriate to the nature of the data, including encryption in transit, EU hosting for App content, access controls and row-level isolation so that each user can access only their own records. No system can be guaranteed to be completely secure. If a personal-data breach creates a risk that requires notification, we will notify the competent supervisory authority and affected individuals within the periods required by law.
14. Changes to this Policy
We may update this Policy to reflect changes to the Service, providers or legal requirements. The revision date identifies the current version. Where a change materially affects the processing of App data, we will provide additional notice through the App, by email or by another appropriate method before the change takes effect where required.