Privacy Policy — Return

Version: 2.6.4
Effective Date: 2026-06-02

The data controller is the sole proprietorship operating Return, registered in Poland. Full identification, registry details, and contact channels are in §12 (Contact).


Language

This Policy is written in English. Polish consumers: see Section 11 for required Polish-language summary. Mandatory data protection rights under GDPR, UK GDPR, and applicable consumer law remain in force regardless of language.


TL;DR

This is a plain-language summary of this Policy, not a substitute for it. The full policy is in the numbered sections below. Your rights under GDPR, UK GDPR, and applicable consumer law apply regardless of this summary.

In Return, privacy isn’t an add-on — it’s the foundation. Quick facts:

Two surfaces, two rules. This Policy covers two separate things. (1) The Return desktop app has zero client-side telemetry and zero advertising trackers — nothing about how you use the app, and none of your documents, is ever sent to any advertising platform. That is an absolute guarantee and the rest of this Policy never qualifies it. (2) The marketing website returneditor.ai is a separate surface: with your consent, it measures ad-campaign conversions via Google and Meta; without your consent, nothing is shared with them. See the website bullet below and §2.4.


1. Who we are

The controller of your personal data is the sole proprietorship operating Return. Full legal name, Tax ID (NIP), Business Registry (REGON), and registered address are in §12 (Contact).

For data protection matters contact us at: support@returneditor.ai.

We have not appointed a Data Protection Officer because GDPR Article 37 does not require it for our processing operations.

2. What data we collect

2.1. Free Plan (Local Mode) — almost nothing

The Free Plan runs entirely on your computer. The only data we may receive:

That’s it. Beyond the aggregate update-check counts described above, we collect no usage analytics, no document metadata, and no behavioral data — and the update check never carries your IP, account, or any device identifier.

2.2. Paid Plans (Pro and Counsel)

To provide paid Plans we process:

CategoryDataPurposeLegal basis
Account dataEmailOTP login, service communicationGDPR Art. 6(1)(b) — contract
Billing dataName / company, Tax ID, billing address, countryVAT invoice, tax complianceGDPR Art. 6(1)(c) — legal obligation
Payment dataCard token, transaction history (held by Paddle, not by us)Payment processingGDPR Art. 6(1)(b) — contract
AI usage metadataAccount ID, timestamp, token count, request typePlan limits, abuse preventionGDPR Art. 6(1)(b) + 6(1)(f) — legitimate interest
Proxy IP logsIP, timestamp, request statusSecurity, rate limiting, debuggingGDPR Art. 6(1)(f) — legitimate interest
Support communicationsEmail, message contentHandling tickets and complaintsGDPR Art. 6(1)(b)
Marketing (opt-in only)Email, preferencesNewsletter, product updatesGDPR Art. 6(1)(a) — consent

2.3. What we DO NOT collect

2.4. The returneditor.ai website

This section is about the marketing website only. It has nothing to do with the desktop app, which never sends anything to advertising platforms (see the “Two surfaces, two rules” note in the TL;DR).

The website sets no tracking cookies and loads no third-party analytics scripts (no Google Analytics, Posthog, Mixpanel, or similar). Only strictly necessary storage is used (e.g., a language preference and the consent record described below); this does not require consent under GDPR Article 6 and ePrivacy Directive interpretations.

No device storage before consent (consent regions). In the EU/EEA/UK — and wherever we cannot determine your location — we go further than “cookieless”: until you opt in, nothing else is written to your device. We do not store a session identifier or any captured ad click identifiers in your browser; for that visit we use an identifier held only in memory and read any click identifier from the page URL solely to process the current request. Persistent browser storage of those identifiers begins only after you allow ad-conversion measurement. The two always-allowed exceptions are your language preference and the consent record itself (both strictly necessary).

First-party measurement (always on, no advertising partners involved). We record our own anonymous page and conversion events (e.g., “page viewed”, “download clicked”) on our server. This data set contains the event name, any ad click identifiers present in the URL (Google gclid, Meta fbclid, Microsoft msclkid), UTM campaign tags, a random per-session identifier, the page URL and referrer. It does not contain your IP address, your User-Agent, your name, or your email. Lawful basis: our legitimate interest in measuring our own marketing (GDPR Art. 6(1)(f)). Declining the consent below does not turn this off — it is first-party and stays anonymous either way.

Conversion forwarding to advertising partners (consent-gated). To measure the performance of paid ads, we can forward conversion events to two named advertising partners:

What we send, and only when forwarding is permitted:

For Conversion API purposes Google and Meta act as independent (or joint) controllers, not as our Article 28 processors; they are disclosed as advertising partners on our Subprocessors page rather than in the subprocessor tables.

Lawful basis and geography. Forwarding to Google/Meta relies on your consent (GDPR Art. 6(1)(a)). In the EU, EEA, and UK — and wherever we cannot determine your location — we ask first with a clear banner and forward nothing until you agree. Outside that region we operate on an opt-out basis (no banner; you can still opt out at any time, which we honor globally).

Withdrawal. You can change or withdraw your decision at any time, as easily as you gave it, via the “Privacy choices” link in the website footer. Withdrawal stops all further forwarding to Google and Meta. We also recognize the Global Privacy Control (GPC) signal: a browser sending Sec-GPC is treated as an opt-out, so nothing is forwarded to Google or Meta unless you have explicitly opted in here. (Our server enforces this independently of your browser — the decision, including GPC, is re-checked on every event.)

3. Subprocessors

We use a minimal set of subprocessors. Full details and locations in Appendix A below. Current list also at returneditor.ai/sub-processors.

For transfers outside the EEA, we rely on appropriate safeguards: for Anthropic and Cloudflare (USA) we rely on EU Standard Contractual Clauses (Commission Decision 2021/914) supplemented by no-content-logging architecture and contractual no-training commitments; for Paddle (United Kingdom, our Merchant of Record) we rely on the European Commission’s UK adequacy decision. Where a subprocessor is certified under the EU-US Data Privacy Framework, we rely on that certification as an additional safeguard.

For material subprocessor changes we give you 30 days’ prior notice by email and via the Application.

4. Retention

DataPeriod
Account data (email)Until contract termination + 30 days for download
Billing data (invoices)5 years from end of tax year (Polish Tax Ordinance)
AI usage metadata90 days (rolling)
Proxy logs (IP, timestamp)7 days
Support communications3 years from case closure
Content transiting Anthropic API7 days (per Anthropic Commercial Terms)
Crash reports (with consent)90 days
Marketing (newsletter consent)Until withdrawal
Website event analytics (events table; §2.4) — anonymous, no IP/UA/email14 months from collection, then deleted or aggregated
Ad-consent record (website, browser localStorage)Until you change or clear it; re-asked when our purposes/partners change

After these periods, data is deleted or anonymized.

5. Your rights

5.1. Under GDPR (EU/EEA users)

RightHow to exercise
Access (Art. 15)Email support@returneditor.ai. Response within 30 days.
Rectification (Art. 16)Email or directly in Account panel.
Erasure / “right to be forgotten” (Art. 17)Email. We don’t delete data required by law (e.g., invoices).
Restriction (Art. 18)Email.
Portability (Art. 20)Email. We export in JSON or CSV.
Objection (Art. 21)Email. Applies to processing on legitimate interest basis.
Withdrawal of consent (Art. 7(3))In-app (marketing preferences) or by email.
Complaint to supervisory authorityPresident of UODO (Poland), Stawki 2, 00-193 Warsaw, uodo.gov.pl. Or your local DPA in the EU.

We respond within 30 days (extendable by 60 days for complex requests — we’ll tell you).

5.2. Under UK GDPR (UK users)

Equivalent rights apply. You may complain to the Information Commissioner’s Office (ico.org.uk).

5.3. Under CCPA/CPRA (California users)

To exercise the website opt-out, use “Privacy choices” in the footer. For all other requests, email support@returneditor.ai; we verify your identity before responding.

Note: we currently do not meet CCPA applicability thresholds (revenue, consumer volume, or data-sale revenue), but we extend these rights voluntarily as a privacy posture.

6. Security

We apply technical and organizational measures appropriate to the risk:

In case of a personal data breach we notify the supervisory authority within 72 hours (GDPR Art. 33) and affected individuals where there is high risk (GDPR Art. 34).

7. Third-party data in your documents (processor role)

If you input documents containing personal data of third parties (e.g., your law firm’s clients), you are the controller of that data and we act as a processor under GDPR Article 28.

In that case:

8. Children

The Application is not directed to children under 16. We do not knowingly collect personal data from children. If we learn of such, we will delete it promptly.

9. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects or significantly affect you (GDPR Art. 22).

AI Outputs are generated by machine learning models, but they are not “decisions” within GDPR Art. 22 — they are tools that support your work, which you control.

10. Changes to this Policy

We may amend this Privacy Policy when law, subprocessors, or Service scope changes. Updates are published at this URL; we notify you of material changes by email.

11. Informacje dla polskiego konsumenta (Polish summary)

Niniejsza sekcja zawiera kluczowe informacje w języku polskim dla polskich konsumentów i podmiotów danych. Pełne brzmienie polityki jest w języku angielskim powyżej. Bezwzględne prawa wynikające z RODO pozostają w mocy niezależnie od języka.

Administrator: Michał Jantos, NIP 9452094429, Szlak 77/222, 31-153 Kraków. Email: support@returneditor.ai.

Dwie powierzchnie, dwie zasady: (1) Aplikacja desktopowa Return — zero telemetrii po stronie klienta i zero trackerów reklamowych; nic o korzystaniu z aplikacji ani żaden dokument nigdy nie trafia do platform reklamowych (gwarancja bezwarunkowa). (2) Strona returneditor.ai — odrębna powierzchnia: za Twoją zgodą mierzy konwersje reklamowe przez Google i Meta; bez zgody nic do nich nie trafia.

Czego nie zbieramy: Aplikacja nie ma telemetrii po stronie klienta (brak SDK analitycznego, brak śledzenia, brak fingerprintingu, brak trackerów reklamowych). Plan Free łączy się z naszym serwerem wyłącznie w celu sprawdzenia aktualizacji — zapytanie zawiera wersję aplikacji i system/architekturę (bez IP, bez konta, bez identyfikatora urządzenia), a my zliczamy jedynie dzienne agregaty wersji (podstawa: uzasadniony interes, Art. 6(1)(f) RODO); można je wyłączyć w ustawieniach. Strona returneditor.ai nie ustawia cookies trackingowych i nie ładuje zewnętrznych skryptów analitycznych (Google Analytics, Posthog, Mixpanel itp.).

Strona — pomiar reklam (za zgodą): Stronowy pomiar własny (tabela events: nazwa zdarzenia, identyfikatory kliknięć reklam gclid/fbclid/msclkid, tagi UTM, losowy identyfikator sesji, URL, referrer — bez IP, User-Agent, imienia i e-maila) działa zawsze, anonimowo, na podstawie uzasadnionego interesu (Art. 6(1)(f) RODO). Przekazywanie konwersji do Google (Google Ads) i Meta (Conversions API) odbywa się wyłącznie na podstawie zgody (Art. 6(1)(a) RODO): w UE/EOG/UK (oraz gdy nie możemy ustalić lokalizacji) pytamy najpierw bannerem i nie wysyłamy nic bez akceptacji. Do Meta przekazujemy też IP i User-Agent — wyłącznie chwilowo, do dopasowania zdarzenia, bez zapisu w naszej bazie. Nie przekazujemy obecnie zakupów ani żadnego e-maila do Google/Meta; gdybyśmy w przyszłości włączyli pomiar konwersji zakupowych, jedynym dodatkiem byłby zhashowany (nieodwracalny) e-mail wyłącznie do Meta, z procesu płatności (nigdy ze zwykłego przeglądania) — zaktualizujemy wtedy najpierw tę Politykę. Google i Meta są w tym zakresie niezależnymi/współadministratorami (nie procesorami z Art. 28). Zgodę możesz zmienić lub cofnąć w każdej chwili — tak samo łatwo jak udzielić — linkiem „Privacy choices” w stopce strony. Honorujemy też sygnał Global Privacy Control (GPC): przeglądarka wysyłająca Sec-GPC jest traktowana jak opt-out — nie przekazujemy nic do Google/Meta, chyba że wyraziłeś tu wyraźną zgodę. W UE/EOG/UK (oraz gdy nie możemy ustalić lokalizacji) przed wyrażeniem zgody nie zapisujemy niczego na Twoim urządzeniu poza preferencją języka i samym zapisem zgody: identyfikator sesji trzymamy tylko w pamięci, a identyfikatory kliknięć odczytujemy z adresu URL wyłącznie na potrzeby bieżącego żądania. Trwały zapis w przeglądarce zaczyna się dopiero po Twojej zgodzie.

Co zbieramy w planach płatnych: Email Konta, dane do faktury (imię/nazwa, NIP, adres), metadane operacji AI (ID konta, znacznik czasu, liczba tokenów), logi IP serwera proxy (7 dni). Treść dokumentów NIE jest logowana.

Cele i podstawy prawne: Wykonanie umowy (Art. 6(1)(b) RODO), obowiązek prawny - faktury (Art. 6(1)(c)), uzasadniony interes - bezpieczeństwo (Art. 6(1)(f)), zgoda - marketing (Art. 6(1)(a)).

Sub-procesorzy poza EOG: Anthropic (USA) — Standardowe Klauzule Umowne + EU-US DPF; Cloudflare (USA) — SCC; Paddle.com Market Ltd (Wielka Brytania, Merchant of Record) — decyzja adekwatności KE dla UK. Lista w Appendix A poniżej oraz na returneditor.ai/sub-processors.

Retencja: Faktury 5 lat (obowiązek podatkowy). Metadane AI 90 dni. Logi IP 7 dni. Treść przekazywana do API Anthropic: do 7 dni (zgodnie z Anthropic Commercial Terms). Anonimowe zdarzenia strony (tabela events): 14 miesięcy.

Twoje prawa RODO: Dostęp, sprostowanie, usunięcie, ograniczenie, przenoszenie, sprzeciw, cofnięcie zgody, skarga do UODO (ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). Realizujemy w 30 dni.

Brak decyzji zautomatyzowanych (Art. 22 RODO): Wyniki AI nie są decyzjami w rozumieniu RODO — są narzędziem wspierającym Twoją pracę.

This Section summarizes the Policy in Polish for Polish data subjects. The full Policy is in English above. Mandatory GDPR rights apply regardless of language.

12. Contact

Data controller

Contact channels

PurposeEmail
Data protection (GDPR/RODO)support@returneditor.ai
General supportsupport@returneditor.ai
B2B Data Processing Agreementsecurity@returneditor.ai
Security reportssecurity@returneditor.ai

Postal correspondence may be sent to the registered address above.

Supervisory authorities


Appendix A — Subprocessor list

The list at the Effective Date. Current list always at returneditor.ai/sub-processors. We give 30 days’ prior notice of material changes by email.

Tier 1: Critical infrastructure

SubprocessorPurposeDataLocationTransfer mechanism
Anthropic PBCAI model inference (Claude) for Cloud ModeCustomer prompts, AI Outputs (transient, max 7-day retention)USASCCs + EU-US DPF
Hetzner Online GmbHProxy server hostingServer logs (IP, timestamp, max 7 days); ephemeral request dataGermany (Falkenstein)Within EEA
Supabase Inc.Authentication (OTP), Account databaseEmail addresses, Account metadataEU region (Frankfurt); HQ USASCCs + Supabase DPA
Cloudflare, Inc.CDN, DDoS protection for returneditor.aiHashed IP, request metadataGlobal PoPs; HQ USASCCs + Cloudflare DPA

Tier 2: Payment and tax

SubprocessorPurposeDataLocationTransfer mechanism
Paddle.com Market LtdMerchant of Record: payment processing, subscription management, billing, sales-tax/VAT collection and remittance, customer invoicingCustomer payment tokens, billing data, transaction metadataUnited KingdomUK adequacy decision (Commission Implementing Decision (EU) 2021/1772) + SCCs where applicable
inFakt sp. z o.o.The Provider’s own accounting and Polish KSeF e-invoicing (Provider-side bookkeeping; not customer payment data)Provider’s accounting records, payout/settlement dataPolandWithin EEA

inFakt is listed for transparency: it supports the Provider’s own bookkeeping and Polish e-invoicing and does not receive end-customer payment instruments or end-customer personal data (which are handled by Paddle as Merchant of Record).

Tier 3: Operational

SubprocessorPurposeDataLocationTransfer mechanism
GitHub, Inc. (Microsoft)Source code hostingNo customer data; only application codeUSASCCs (Microsoft EU DPA)
Error tracking (if enabled)Crash reports (only with user consent)Anonymized stack traces, OS versionEU region preferredWithin EEA (if EU-only configuration)

Not subprocessors (clarification)

Subprocessor selection criteria

Before adding a subprocessor, we verify:

  1. Adequate data protection guarantees under GDPR Article 28 and Article 32.
  2. Signed DPA with the subprocessor.
  3. For non-EEA subprocessors: valid transfer mechanism (SCCs, DPF certification where applicable, supplementary measures per Schrems II).
  4. No-training commitment for any AI subprocessor.
  5. Reasonable security posture (SOC 2, ISO 27001, or equivalent preferred).
  6. Compatibility with Customer’s privilege and confidentiality requirements for legal professional use cases.

Version history:

VersionDateChanges
1.0(superseded)Initial bilingual EN+PL version
2.0(superseded pre-launch)Consolidated: EN-only with Polish summary section. Subprocessor list moved to Appendix A. Telemetry-free architecture emphasized throughout.
2.1(superseded pre-launch)Header minimized: controller’s full identification moved to §12 (Contact). §1 (Who we are) updated to reference §12 instead of inline data.
2.2(superseded pre-launch)Replaced “A short note up front” preamble with explicit “TL;DR” section + non-binding disclaimer. Same factual content, clearer signaling.
2.32026-05-23Removed internal ⚠️ review markers and “to be decided” placeholders from the published text (crash reporting, DPF status, error tracking). Removed forward-looking “Zero Data Retention for Counsel” from retention table and Polish summary, since ZDR requires a separate signed agreement with Anthropic and is not yet offered.
2.42026-05-24Corrected the update-check endpoint to returneditor.ai/latest.json (Tauri updater convention) and clarified that the request is unauthenticated and carries no identifying data beyond a standard User-Agent.
2.4.22026-05-26Clarified update-check timing (each app start, not “once every 24 hours”). Added that the signed bundle is fetched from cdn.returneditor.ai when the user accepts the update. Corrected the IP-logging claim — hosting is on Cloudflare, we don’t have access to per-request IP logs.
2.5.02026-05-26Billing subprocessor changed to Paddle.com Market Ltd (UK) as Merchant of Record, replacing Stripe and the Stripe→inFakt bridge. §2.2 payment-data row, §3 transfer-safeguards, §11 Polish summary, and Appendix A Tier 2 updated. inFakt repositioned as the Provider’s own bookkeeping/KSeF tool (Provider-side data), not a holder of customer payment data. UK transfers covered by the EU→UK adequacy decision.
2.5.12026-05-31Update check moved from the static returneditor.ai/latest.json to the dynamic endpoint api.returneditor.ai. Disclosed honestly: the request now carries the app version + OS/architecture in the URL, and we record daily aggregate counts (version + platform) for update-adoption analytics and staged rollout — still anonymous (no IP, no User-Agent, no account, no device ID), lawful basis Art. 6(1)(f). Static latest.json on Cloudflare retained as fallback. §2.1, TL;DR, and §11 Polish summary updated.
2.6.02026-05-31Website ad-conversion measurement (consent-gated). Added a “Two surfaces, two rules” scoping note (app = zero ad-tracking, absolute; website = consent-gated). Rewrote §2.4 to disclose first-party events measurement (legitimate interest) and consent-gated forwarding to Google and Meta (Art. 6(1)(a)), naming exactly what is sent (click IDs; IP/User-Agent to Meta in-memory only, not stored; hashed email only from the billing flow), the EU/EEA/UK geo-gate, and withdrawal via the footer “Privacy choices” link. Corrected the CCPA §5.3 “sale/sharing” statement (forwarding may be “sharing” under CPRA; opt-out honored globally). Added retention rows for the events table (14 months) and the browser consent record. Mirrored all changes in the §11 Polish summary. The desktop app’s zero-telemetry / zero-ad-tracking guarantee is unchanged.
2.6.12026-06-02Disclosed that we honor the Global Privacy Control (GPC) browser signal (Sec-GPC) as an opt-out for website ad-conversion forwarding; an explicit on-site opt-in still overrides it. Updated §2.4 (Withdrawal), §5.3 (CCPA opt-out), and the §11 Polish summary. No change to what data is shared, the geo-gate, or the app’s zero-ad-tracking guarantee.
2.6.22026-06-02Stated the no-device-storage-before-consent posture for consent regions (EU/EEA/UK and unknown geo): until you opt in, the website writes nothing to your device beyond the language preference and consent record — the session identifier is held in memory only and click identifiers are read from the page URL for the current request, with persistent browser storage beginning only after consent. Strengthens the ePrivacy Art. 5(3) position over a “cookieless = consent-free” exemption. Updated §2.4 and the §11 Polish summary. No change to what data is shared or to the app’s zero-ad-tracking guarantee.
2.6.32026-06-02Accuracy: clarified that we do not currently forward purchases to Google or Meta and therefore send no email to them; the previous wording described a hashed-email-on-purchase path that exists only as a dormant capability, not active behavior. Reworded §2.4 and the §11 Polish summary to state this conditionally (email would be added only if purchase-conversion measurement is ever enabled, with a prior Policy update). Mirrored in the Subprocessors page (Meta row). No change to what is actually shared today.
2.6.42026-06-11Local-engine accuracy update: “Ollama” replaced by the built-in local AI engine (bundled llama.cpp, following its removal — ADR-0007) in the “Not subprocessors” clarification, and Hugging Face added there as the direct, Customer-initiated source of optional local model downloads (Customer IP visible to Hugging Face; no Content or personal data held by us is transmitted). No change to actual data flows.