Legal

Privacy Policy

1. Who processes data. The operator (data controller) is AnikinTech LLC, ID 402373267, Lochini str. 3, floor 2, apt. 5, Chugureti, Tbilisi 0101, Georgia. Data contact: milina@anitech.io. The service is offered to users in the EU among others, so processing is conducted with regard to the GDPR.

2. What data and why. (a) Account: email, password hash, display name (if provided) — for registration, sign-in and operation of the service (performance of contract). (b) Content: your questions, uploaded files, analysis history and reports — to produce results and personalise them (performance of contract). (c) Profile: aggregated counters of themes, industries, markets and an analytical portrait computed from your analyses — for personalisation (legitimate interest). (d) Technical data: IP addresses and request logs to the extent necessary for security and stability (legitimate interest). (e) Traffic: de-identified Vercel Analytics statistics without cookies and without profiling.

3. Processors. Data is processed on: Supabase (database and authentication, Frankfurt region, EU), Hetzner (compute server, Finland, EU), Vercel (frontend hosting and analytics), Anthropic (language model — processing query text to produce reports), Resend (transactional email). Transfers are limited to what each function requires, under the providers’ data-processing agreements.

4. Collective insights. The service uses de-identified aggregated patterns from user analyses to produce cross-industry insights. Your identity, email and the content of your analyses are not disclosed to other users.

5. Retention. Account data and analysis history are kept while the account exists. Database backups are kept for 14 days. After account deletion, data is deleted or de-identified within a reasonable period, except where retention is required by law.

6. Your rights. You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Requests: milina@anitech.io; response within 30 days. EU users may also lodge a complaint with their supervisory authority.

7. Security. Row Level Security isolation, cryptographic token verification, server-side secrets, encrypted connections (HTTPS).

8. Children. The service is intended for persons 18+; children’s data is not knowingly collected.

9. Changes. The current version is published on this page; material changes are notified via the service or email.

AnikinTech LLC · ID 402373267 · Effective: 17 July 2026 (draft)