Privacy Policy — Return
Version: 2.6.4
Effective Date: 2026-06-02
The data controller is the sole proprietorship operating Return, registered in Poland. Full identification, registry details, and contact channels are in §12 (Contact).
Language
This Policy is written in English. Polish consumers: see Section 11 for required Polish-language summary. Mandatory data protection rights under GDPR, UK GDPR, and applicable consumer law remain in force regardless of language.
TL;DR
This is a plain-language summary of this Policy, not a substitute for it. The full policy is in the numbered sections below. Your rights under GDPR, UK GDPR, and applicable consumer law apply regardless of this summary.
In Return, privacy isn’t an add-on — it’s the foundation. Quick facts:
Two surfaces, two rules. This Policy covers two separate things. (1) The Return desktop app has zero client-side telemetry and zero advertising trackers — nothing about how you use the app, and none of your documents, is ever sent to any advertising platform. That is an absolute guarantee and the rest of this Policy never qualifies it. (2) The marketing website
returneditor.aiis a separate surface: with your consent, it measures ad-campaign conversions via Google and Meta; without your consent, nothing is shared with them. See the website bullet below and §2.4.
- No client-side telemetry in the app. No in-app analytics SDK, no usage tracking, no fingerprinting, no advertising trackers. The Free tier connects to our servers only for the update check, which reports your app version and OS so we can serve the right update and count versions in aggregate (no IP, no account, no device ID) — and you can disable it (see §2.1).
- In Free (Local Mode), your documents NEVER leave your computer. We don’t collect them, see them, or analyze them.
- In Pro/Counsel (Cloud Mode), your documents pass through our proxy on the way to Anthropic, but our proxy does not store them. We log only metadata (who, when, how many tokens) for billing and abuse prevention.
- No training on your data. Neither we nor Anthropic train AI models on your content. This is contractually binding (see §3 and §7).
- The website
returneditor.aisets no tracking cookies and runs no third-party analytics scripts. Our own page metrics are anonymous and server-side. The one exception is ad-conversion measurement: if you allow it, the website sends conversion events to Google and Meta to measure our ads; in the EU/EEA/UK we ask first and send nothing unless you agree, and you can withdraw any time via “Privacy choices” in the footer (see §2.4). This is the website only — never the app. - You have the full set of GDPR rights: access, rectification, erasure, restriction, portability, objection (see §5).
1. Who we are
The controller of your personal data is the sole proprietorship operating Return. Full legal name, Tax ID (NIP), Business Registry (REGON), and registered address are in §12 (Contact).
For data protection matters contact us at: support@returneditor.ai.
We have not appointed a Data Protection Officer because GDPR Article 37 does not require it for our processing operations.
2. What data we collect
2.1. Free Plan (Local Mode) — almost nothing
The Free Plan runs entirely on your computer. The only data we may receive:
- Update check: A few seconds after each app start, the app asks our server
api.returneditor.aiwhether a newer version exists. This request carries your current app version and operating system / processor architecture (e.g. “macOS, Apple Silicon”) in the URL so we can return the right update. It is unauthenticated — not tied to your account, email, or any installation identifier. We record only daily aggregate counts of these requests (how many checks came from each version + platform on a given day); we do not store your IP address, User-Agent, or any per-device record. We use these aggregates to understand which versions are still in use and to roll out updates gradually. The lawful basis is our legitimate interest in maintaining and securely updating the Service (GDPR Art. 6(1)(f)). If our server is unreachable, the app falls back to a static file on Cloudflare (returneditor.ai/latest.json). If you choose to download an update, the signed bundle is fetched fromcdn.returneditor.ai. You can disable update checks entirely in settings. - Crash reports (optional): With your explicit consent, on crash the app may send us an anonymized error log (stack trace, OS version). It does not include the content of your documents. If we have not enabled crash reporting in your version of the app, no such data is collected.
That’s it. Beyond the aggregate update-check counts described above, we collect no usage analytics, no document metadata, and no behavioral data — and the update check never carries your IP, account, or any device identifier.
2.2. Paid Plans (Pro and Counsel)
To provide paid Plans we process:
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account data | OTP login, service communication | GDPR Art. 6(1)(b) — contract | |
| Billing data | Name / company, Tax ID, billing address, country | VAT invoice, tax compliance | GDPR Art. 6(1)(c) — legal obligation |
| Payment data | Card token, transaction history (held by Paddle, not by us) | Payment processing | GDPR Art. 6(1)(b) — contract |
| AI usage metadata | Account ID, timestamp, token count, request type | Plan limits, abuse prevention | GDPR Art. 6(1)(b) + 6(1)(f) — legitimate interest |
| Proxy IP logs | IP, timestamp, request status | Security, rate limiting, debugging | GDPR Art. 6(1)(f) — legitimate interest |
| Support communications | Email, message content | Handling tickets and complaints | GDPR Art. 6(1)(b) |
| Marketing (opt-in only) | Email, preferences | Newsletter, product updates | GDPR Art. 6(1)(a) — consent |
2.3. What we DO NOT collect
- The content of your documents. Our proxy does not log content sent to Anthropic or responses received. Content passes through the server in ephemeral memory and is not written to disk or database.
- Prompts and AI responses. Same — flow without storage.
- Files stored on your computer. We have no access to them.
- Browser fingerprinting, device IDs, behavioral data. None.
2.4. The returneditor.ai website
This section is about the marketing website only. It has nothing to do with the desktop app, which never sends anything to advertising platforms (see the “Two surfaces, two rules” note in the TL;DR).
The website sets no tracking cookies and loads no third-party analytics scripts (no Google Analytics, Posthog, Mixpanel, or similar). Only strictly necessary storage is used (e.g., a language preference and the consent record described below); this does not require consent under GDPR Article 6 and ePrivacy Directive interpretations.
No device storage before consent (consent regions). In the EU/EEA/UK — and wherever we cannot determine your location — we go further than “cookieless”: until you opt in, nothing else is written to your device. We do not store a session identifier or any captured ad click identifiers in your browser; for that visit we use an identifier held only in memory and read any click identifier from the page URL solely to process the current request. Persistent browser storage of those identifiers begins only after you allow ad-conversion measurement. The two always-allowed exceptions are your language preference and the consent record itself (both strictly necessary).
First-party measurement (always on, no advertising partners involved). We record our own anonymous page and conversion events (e.g., “page viewed”, “download clicked”) on our server. This data set contains the event name, any ad click identifiers present in the URL (Google gclid, Meta fbclid, Microsoft msclkid), UTM campaign tags, a random per-session identifier, the page URL and referrer. It does not contain your IP address, your User-Agent, your name, or your email. Lawful basis: our legitimate interest in measuring our own marketing (GDPR Art. 6(1)(f)). Declining the consent below does not turn this off — it is first-party and stays anonymous either way.
Conversion forwarding to advertising partners (consent-gated). To measure the performance of paid ads, we can forward conversion events to two named advertising partners:
- Google (Google Ads Conversion API), and
- Meta (Meta Conversions API).
What we send, and only when forwarding is permitted:
- the relevant click identifier (
gclidto Google,fbclidto Meta) and the event details above; - to Meta only, your IP address and User-Agent, used in-memory at the moment of forwarding solely to match the event — we do not store them in our database;
- no email, and no purchase data. We do not currently forward purchases to Google or Meta, so no email address is ever sent to them. The website never collects your email for advertising. (If we ever enable purchase-conversion measurement, the only addition would be a hashed, irreversible email sent to Meta only, originating from our billing flow — never from ordinary browsing — and we would update this Policy first.)
For Conversion API purposes Google and Meta act as independent (or joint) controllers, not as our Article 28 processors; they are disclosed as advertising partners on our Subprocessors page rather than in the subprocessor tables.
Lawful basis and geography. Forwarding to Google/Meta relies on your consent (GDPR Art. 6(1)(a)). In the EU, EEA, and UK — and wherever we cannot determine your location — we ask first with a clear banner and forward nothing until you agree. Outside that region we operate on an opt-out basis (no banner; you can still opt out at any time, which we honor globally).
Withdrawal. You can change or withdraw your decision at any time, as easily as you gave it, via the “Privacy choices” link in the website footer. Withdrawal stops all further forwarding to Google and Meta. We also recognize the Global Privacy Control (GPC) signal: a browser sending Sec-GPC is treated as an opt-out, so nothing is forwarded to Google or Meta unless you have explicitly opted in here. (Our server enforces this independently of your browser — the decision, including GPC, is re-checked on every event.)
3. Subprocessors
We use a minimal set of subprocessors. Full details and locations in Appendix A below. Current list also at returneditor.ai/sub-processors.
For transfers outside the EEA, we rely on appropriate safeguards: for Anthropic and Cloudflare (USA) we rely on EU Standard Contractual Clauses (Commission Decision 2021/914) supplemented by no-content-logging architecture and contractual no-training commitments; for Paddle (United Kingdom, our Merchant of Record) we rely on the European Commission’s UK adequacy decision. Where a subprocessor is certified under the EU-US Data Privacy Framework, we rely on that certification as an additional safeguard.
For material subprocessor changes we give you 30 days’ prior notice by email and via the Application.
4. Retention
| Data | Period |
|---|---|
| Account data (email) | Until contract termination + 30 days for download |
| Billing data (invoices) | 5 years from end of tax year (Polish Tax Ordinance) |
| AI usage metadata | 90 days (rolling) |
| Proxy logs (IP, timestamp) | 7 days |
| Support communications | 3 years from case closure |
| Content transiting Anthropic API | 7 days (per Anthropic Commercial Terms) |
| Crash reports (with consent) | 90 days |
| Marketing (newsletter consent) | Until withdrawal |
Website event analytics (events table; §2.4) — anonymous, no IP/UA/email | 14 months from collection, then deleted or aggregated |
Ad-consent record (website, browser localStorage) | Until you change or clear it; re-asked when our purposes/partners change |
After these periods, data is deleted or anonymized.
5. Your rights
5.1. Under GDPR (EU/EEA users)
| Right | How to exercise |
|---|---|
| Access (Art. 15) | Email support@returneditor.ai. Response within 30 days. |
| Rectification (Art. 16) | Email or directly in Account panel. |
| Erasure / “right to be forgotten” (Art. 17) | Email. We don’t delete data required by law (e.g., invoices). |
| Restriction (Art. 18) | Email. |
| Portability (Art. 20) | Email. We export in JSON or CSV. |
| Objection (Art. 21) | Email. Applies to processing on legitimate interest basis. |
| Withdrawal of consent (Art. 7(3)) | In-app (marketing preferences) or by email. |
| Complaint to supervisory authority | President of UODO (Poland), Stawki 2, 00-193 Warsaw, uodo.gov.pl. Or your local DPA in the EU. |
We respond within 30 days (extendable by 60 days for complex requests — we’ll tell you).
5.2. Under UK GDPR (UK users)
Equivalent rights apply. You may complain to the Information Commissioner’s Office (ico.org.uk).
5.3. Under CCPA/CPRA (California users)
- Right to know what personal information we collect and how we use it.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt-out of “sale” or “sharing.” We do not “sell” personal information for money. However, when you consent to ad-conversion measurement on our website (see §2.4), our forwarding of conversion events to Google and Meta may qualify as “sharing” for cross-context behavioral advertising under the CPRA. You can opt out at any time — and decline up front — using the “Privacy choices” link in the website footer; we honor that choice globally. We also honor the Global Privacy Control (GPC) browser signal as an opt-out: if your browser sends GPC, we do not forward to Google or Meta unless you have explicitly opted in on this site. The desktop app never shares any information for advertising.
- Right to non-discrimination for exercising your rights.
To exercise the website opt-out, use “Privacy choices” in the footer. For all other requests, email support@returneditor.ai; we verify your identity before responding.
Note: we currently do not meet CCPA applicability thresholds (revenue, consumer volume, or data-sale revenue), but we extend these rights voluntarily as a privacy posture.
6. Security
We apply technical and organizational measures appropriate to the risk:
- In transit: TLS 1.3 for all connections.
- At rest: Server disks encrypted at filesystem level (LUKS). Subprocessor databases use industry-standard encryption (AES-256).
- No content storage: Proxy operates on ephemeral memory.
- Access control: Infrastructure access via SSH keys only; MFA where possible.
- Monitoring: Logs audited for anomalies.
- Security updates: Continuous patching of critical CVEs.
In case of a personal data breach we notify the supervisory authority within 72 hours (GDPR Art. 33) and affected individuals where there is high risk (GDPR Art. 34).
7. Third-party data in your documents (processor role)
If you input documents containing personal data of third parties (e.g., your law firm’s clients), you are the controller of that data and we act as a processor under GDPR Article 28.
In that case:
- The relationship is governed by a Data Processing Agreement (DPA) — template at
returneditor.ai/dpa. - On request we sign a DPA with you.
- Anthropic, Hetzner, Supabase, and Cloudflare are our subprocessors in that chain.
- The DPA describes detailed obligations, subprocessors, audits, and breach notification.
8. Children
The Application is not directed to children under 16. We do not knowingly collect personal data from children. If we learn of such, we will delete it promptly.
9. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects or significantly affect you (GDPR Art. 22).
AI Outputs are generated by machine learning models, but they are not “decisions” within GDPR Art. 22 — they are tools that support your work, which you control.
10. Changes to this Policy
We may amend this Privacy Policy when law, subprocessors, or Service scope changes. Updates are published at this URL; we notify you of material changes by email.
11. Informacje dla polskiego konsumenta (Polish summary)
Niniejsza sekcja zawiera kluczowe informacje w języku polskim dla polskich konsumentów i podmiotów danych. Pełne brzmienie polityki jest w języku angielskim powyżej. Bezwzględne prawa wynikające z RODO pozostają w mocy niezależnie od języka.
Administrator: Michał Jantos, NIP 9452094429, Szlak 77/222, 31-153 Kraków. Email: support@returneditor.ai.
Dwie powierzchnie, dwie zasady: (1) Aplikacja desktopowa Return — zero telemetrii po stronie klienta i zero trackerów reklamowych; nic o korzystaniu z aplikacji ani żaden dokument nigdy nie trafia do platform reklamowych (gwarancja bezwarunkowa). (2) Strona
returneditor.ai— odrębna powierzchnia: za Twoją zgodą mierzy konwersje reklamowe przez Google i Meta; bez zgody nic do nich nie trafia.Czego nie zbieramy: Aplikacja nie ma telemetrii po stronie klienta (brak SDK analitycznego, brak śledzenia, brak fingerprintingu, brak trackerów reklamowych). Plan Free łączy się z naszym serwerem wyłącznie w celu sprawdzenia aktualizacji — zapytanie zawiera wersję aplikacji i system/architekturę (bez IP, bez konta, bez identyfikatora urządzenia), a my zliczamy jedynie dzienne agregaty wersji (podstawa: uzasadniony interes, Art. 6(1)(f) RODO); można je wyłączyć w ustawieniach. Strona
returneditor.ainie ustawia cookies trackingowych i nie ładuje zewnętrznych skryptów analitycznych (Google Analytics, Posthog, Mixpanel itp.).Strona — pomiar reklam (za zgodą): Stronowy pomiar własny (tabela
events: nazwa zdarzenia, identyfikatory kliknięć reklamgclid/fbclid/msclkid, tagi UTM, losowy identyfikator sesji, URL, referrer — bez IP, User-Agent, imienia i e-maila) działa zawsze, anonimowo, na podstawie uzasadnionego interesu (Art. 6(1)(f) RODO). Przekazywanie konwersji do Google (Google Ads) i Meta (Conversions API) odbywa się wyłącznie na podstawie zgody (Art. 6(1)(a) RODO): w UE/EOG/UK (oraz gdy nie możemy ustalić lokalizacji) pytamy najpierw bannerem i nie wysyłamy nic bez akceptacji. Do Meta przekazujemy też IP i User-Agent — wyłącznie chwilowo, do dopasowania zdarzenia, bez zapisu w naszej bazie. Nie przekazujemy obecnie zakupów ani żadnego e-maila do Google/Meta; gdybyśmy w przyszłości włączyli pomiar konwersji zakupowych, jedynym dodatkiem byłby zhashowany (nieodwracalny) e-mail wyłącznie do Meta, z procesu płatności (nigdy ze zwykłego przeglądania) — zaktualizujemy wtedy najpierw tę Politykę. Google i Meta są w tym zakresie niezależnymi/współadministratorami (nie procesorami z Art. 28). Zgodę możesz zmienić lub cofnąć w każdej chwili — tak samo łatwo jak udzielić — linkiem „Privacy choices” w stopce strony. Honorujemy też sygnał Global Privacy Control (GPC): przeglądarka wysyłającaSec-GPCjest traktowana jak opt-out — nie przekazujemy nic do Google/Meta, chyba że wyraziłeś tu wyraźną zgodę. W UE/EOG/UK (oraz gdy nie możemy ustalić lokalizacji) przed wyrażeniem zgody nie zapisujemy niczego na Twoim urządzeniu poza preferencją języka i samym zapisem zgody: identyfikator sesji trzymamy tylko w pamięci, a identyfikatory kliknięć odczytujemy z adresu URL wyłącznie na potrzeby bieżącego żądania. Trwały zapis w przeglądarce zaczyna się dopiero po Twojej zgodzie.Co zbieramy w planach płatnych: Email Konta, dane do faktury (imię/nazwa, NIP, adres), metadane operacji AI (ID konta, znacznik czasu, liczba tokenów), logi IP serwera proxy (7 dni). Treść dokumentów NIE jest logowana.
Cele i podstawy prawne: Wykonanie umowy (Art. 6(1)(b) RODO), obowiązek prawny - faktury (Art. 6(1)(c)), uzasadniony interes - bezpieczeństwo (Art. 6(1)(f)), zgoda - marketing (Art. 6(1)(a)).
Sub-procesorzy poza EOG: Anthropic (USA) — Standardowe Klauzule Umowne + EU-US DPF; Cloudflare (USA) — SCC; Paddle.com Market Ltd (Wielka Brytania, Merchant of Record) — decyzja adekwatności KE dla UK. Lista w Appendix A poniżej oraz na
returneditor.ai/sub-processors.Retencja: Faktury 5 lat (obowiązek podatkowy). Metadane AI 90 dni. Logi IP 7 dni. Treść przekazywana do API Anthropic: do 7 dni (zgodnie z Anthropic Commercial Terms). Anonimowe zdarzenia strony (tabela
events): 14 miesięcy.Twoje prawa RODO: Dostęp, sprostowanie, usunięcie, ograniczenie, przenoszenie, sprzeciw, cofnięcie zgody, skarga do UODO (ul. Stawki 2, 00-193 Warszawa,
uodo.gov.pl). Realizujemy w 30 dni.Brak decyzji zautomatyzowanych (Art. 22 RODO): Wyniki AI nie są decyzjami w rozumieniu RODO — są narzędziem wspierającym Twoją pracę.
This Section summarizes the Policy in Polish for Polish data subjects. The full Policy is in English above. Mandatory GDPR rights apply regardless of language.
12. Contact
Data controller
- Trading name: Return
- Legal name: Michał Jantos
- Legal form: Sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland
- Polish Tax ID (NIP): 9452094429
- Polish Business Registry (REGON): 361993412
- Registered address: Szlak 77/222, 31-153 Kraków
Contact channels
| Purpose | |
|---|---|
| Data protection (GDPR/RODO) | support@returneditor.ai |
| General support | support@returneditor.ai |
| B2B Data Processing Agreement | security@returneditor.ai |
| Security reports | security@returneditor.ai |
Postal correspondence may be sent to the registered address above.
Supervisory authorities
- Poland: President of UODO, ul. Stawki 2, 00-193 Warsaw,
uodo.gov.pl - UK: Information Commissioner’s Office,
ico.org.uk - California: California Privacy Protection Agency,
cppa.ca.gov - Other EU/EEA users: Your local data protection authority
Appendix A — Subprocessor list
The list at the Effective Date. Current list always at returneditor.ai/sub-processors. We give 30 days’ prior notice of material changes by email.
Tier 1: Critical infrastructure
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Anthropic PBC | AI model inference (Claude) for Cloud Mode | Customer prompts, AI Outputs (transient, max 7-day retention) | USA | SCCs + EU-US DPF |
| Hetzner Online GmbH | Proxy server hosting | Server logs (IP, timestamp, max 7 days); ephemeral request data | Germany (Falkenstein) | Within EEA |
| Supabase Inc. | Authentication (OTP), Account database | Email addresses, Account metadata | EU region (Frankfurt); HQ USA | SCCs + Supabase DPA |
| Cloudflare, Inc. | CDN, DDoS protection for returneditor.ai | Hashed IP, request metadata | Global PoPs; HQ USA | SCCs + Cloudflare DPA |
Tier 2: Payment and tax
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Paddle.com Market Ltd | Merchant of Record: payment processing, subscription management, billing, sales-tax/VAT collection and remittance, customer invoicing | Customer payment tokens, billing data, transaction metadata | United Kingdom | UK adequacy decision (Commission Implementing Decision (EU) 2021/1772) + SCCs where applicable |
| inFakt sp. z o.o. | The Provider’s own accounting and Polish KSeF e-invoicing (Provider-side bookkeeping; not customer payment data) | Provider’s accounting records, payout/settlement data | Poland | Within EEA |
inFakt is listed for transparency: it supports the Provider’s own bookkeeping and Polish e-invoicing and does not receive end-customer payment instruments or end-customer personal data (which are handled by Paddle as Merchant of Record).
Tier 3: Operational
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| GitHub, Inc. (Microsoft) | Source code hosting | No customer data; only application code | USA | SCCs (Microsoft EU DPA) |
| Error tracking (if enabled) | Crash reports (only with user consent) | Anonymized stack traces, OS version | EU region preferred | Within EEA (if EU-only configuration) |
Not subprocessors (clarification)
- Built-in local AI engine (Free mode) — bundled with the Application; runs entirely on Customer’s computer; no data transmission. Not a subprocessor.
- Hugging Face, Inc. (model downloads) — optional local AI model files are downloaded by the Application directly from Hugging Face’s servers at the Customer’s explicit request; as with any direct download, the Customer’s IP address is visible to Hugging Face. No Content, account data, or other personal data held by us is transmitted, and Hugging Face does not process data on our behalf. Not a subprocessor.
- Apple, Microsoft, Linux distributions — OS providers; data on Customer device does not pass through them in connection with our Service.
- Customer’s own infrastructure — not a subprocessor; outside our control.
Subprocessor selection criteria
Before adding a subprocessor, we verify:
- Adequate data protection guarantees under GDPR Article 28 and Article 32.
- Signed DPA with the subprocessor.
- For non-EEA subprocessors: valid transfer mechanism (SCCs, DPF certification where applicable, supplementary measures per Schrems II).
- No-training commitment for any AI subprocessor.
- Reasonable security posture (SOC 2, ISO 27001, or equivalent preferred).
- Compatibility with Customer’s privilege and confidentiality requirements for legal professional use cases.
Version history:
| Version | Date | Changes |
|---|---|---|
| 1.0 | (superseded) | Initial bilingual EN+PL version |
| 2.0 | (superseded pre-launch) | Consolidated: EN-only with Polish summary section. Subprocessor list moved to Appendix A. Telemetry-free architecture emphasized throughout. |
| 2.1 | (superseded pre-launch) | Header minimized: controller’s full identification moved to §12 (Contact). §1 (Who we are) updated to reference §12 instead of inline data. |
| 2.2 | (superseded pre-launch) | Replaced “A short note up front” preamble with explicit “TL;DR” section + non-binding disclaimer. Same factual content, clearer signaling. |
| 2.3 | 2026-05-23 | Removed internal ⚠️ review markers and “to be decided” placeholders from the published text (crash reporting, DPF status, error tracking). Removed forward-looking “Zero Data Retention for Counsel” from retention table and Polish summary, since ZDR requires a separate signed agreement with Anthropic and is not yet offered. |
| 2.4 | 2026-05-24 | Corrected the update-check endpoint to returneditor.ai/latest.json (Tauri updater convention) and clarified that the request is unauthenticated and carries no identifying data beyond a standard User-Agent. |
| 2.4.2 | 2026-05-26 | Clarified update-check timing (each app start, not “once every 24 hours”). Added that the signed bundle is fetched from cdn.returneditor.ai when the user accepts the update. Corrected the IP-logging claim — hosting is on Cloudflare, we don’t have access to per-request IP logs. |
| 2.5.0 | 2026-05-26 | Billing subprocessor changed to Paddle.com Market Ltd (UK) as Merchant of Record, replacing Stripe and the Stripe→inFakt bridge. §2.2 payment-data row, §3 transfer-safeguards, §11 Polish summary, and Appendix A Tier 2 updated. inFakt repositioned as the Provider’s own bookkeeping/KSeF tool (Provider-side data), not a holder of customer payment data. UK transfers covered by the EU→UK adequacy decision. |
| 2.5.1 | 2026-05-31 | Update check moved from the static returneditor.ai/latest.json to the dynamic endpoint api.returneditor.ai. Disclosed honestly: the request now carries the app version + OS/architecture in the URL, and we record daily aggregate counts (version + platform) for update-adoption analytics and staged rollout — still anonymous (no IP, no User-Agent, no account, no device ID), lawful basis Art. 6(1)(f). Static latest.json on Cloudflare retained as fallback. §2.1, TL;DR, and §11 Polish summary updated. |
| 2.6.0 | 2026-05-31 | Website ad-conversion measurement (consent-gated). Added a “Two surfaces, two rules” scoping note (app = zero ad-tracking, absolute; website = consent-gated). Rewrote §2.4 to disclose first-party events measurement (legitimate interest) and consent-gated forwarding to Google and Meta (Art. 6(1)(a)), naming exactly what is sent (click IDs; IP/User-Agent to Meta in-memory only, not stored; hashed email only from the billing flow), the EU/EEA/UK geo-gate, and withdrawal via the footer “Privacy choices” link. Corrected the CCPA §5.3 “sale/sharing” statement (forwarding may be “sharing” under CPRA; opt-out honored globally). Added retention rows for the events table (14 months) and the browser consent record. Mirrored all changes in the §11 Polish summary. The desktop app’s zero-telemetry / zero-ad-tracking guarantee is unchanged. |
| 2.6.1 | 2026-06-02 | Disclosed that we honor the Global Privacy Control (GPC) browser signal (Sec-GPC) as an opt-out for website ad-conversion forwarding; an explicit on-site opt-in still overrides it. Updated §2.4 (Withdrawal), §5.3 (CCPA opt-out), and the §11 Polish summary. No change to what data is shared, the geo-gate, or the app’s zero-ad-tracking guarantee. |
| 2.6.2 | 2026-06-02 | Stated the no-device-storage-before-consent posture for consent regions (EU/EEA/UK and unknown geo): until you opt in, the website writes nothing to your device beyond the language preference and consent record — the session identifier is held in memory only and click identifiers are read from the page URL for the current request, with persistent browser storage beginning only after consent. Strengthens the ePrivacy Art. 5(3) position over a “cookieless = consent-free” exemption. Updated §2.4 and the §11 Polish summary. No change to what data is shared or to the app’s zero-ad-tracking guarantee. |
| 2.6.3 | 2026-06-02 | Accuracy: clarified that we do not currently forward purchases to Google or Meta and therefore send no email to them; the previous wording described a hashed-email-on-purchase path that exists only as a dormant capability, not active behavior. Reworded §2.4 and the §11 Polish summary to state this conditionally (email would be added only if purchase-conversion measurement is ever enabled, with a prior Policy update). Mirrored in the Subprocessors page (Meta row). No change to what is actually shared today. |
| 2.6.4 | 2026-06-11 | Local-engine accuracy update: “Ollama” replaced by the built-in local AI engine (bundled llama.cpp, following its removal — ADR-0007) in the “Not subprocessors” clarification, and Hugging Face added there as the direct, Customer-initiated source of optional local model downloads (Customer IP visible to Hugging Face; no Content or personal data held by us is transmitted). No change to actual data flows. |