Privacy Notice

pp-v2.2
Effective: 24 September 2026Updated: 24 September 2026

1.Controller and contact

VirtualArtist Oskar Lendzion, Niepołomicka 34C/28, 80-180 Gdańsk, Poland, NIP PL5833494394 is the controller for account, website, billing-support and product-operation data described here. Contact [email protected] for privacy requests. No data protection officer has been appointed. We normally respond to rights requests within one month, subject to lawful extensions and identity verification.

2.Data, purposes and legal bases

We process account identifiers, authentication and security records, buyer and transaction data, service settings, brand context, instructions, conversations, voice recordings submitted for transcription and the resulting transcripts, uploaded and generated content, publishing tokens and results, consent evidence and support correspondence.

The main bases are performance of the service contract, compliance with tax and other legal duties, consent for optional analytics or marketing storage, and legitimate interests in security, fraud prevention, service diagnostics and legal claims. We assess and limit legitimate-interest processing. Data not needed for a requested function should not be submitted.

3.Connections to external assistants (MCP)

When you authorize an external assistant to connect through MCP to one SMAT brand or, as the account owner, to all brands of your account, it sends the arguments of your tool requests to SMAT. SMAT checks the connection, brand, permissions and current account conditions, then returns the data needed for an authorized request. Depending on the tool, this may include saved brand context, strategy, insights, competitor information, drafts, media previews and links, operation status or publication results. A connection alone does not transfer the entire account or brand. The assistant provider handles data it receives under your account settings and its own privacy terms.

SMAT keeps a connection record linked to the user, tenant and brand (or all brands of the account), including scopes, expiry or revocation status and any per-action credit limit. OAuth artifacts and operation receipts can record the tool, a request fingerprint, outcome and references needed to reconcile a result. Raw access credentials are not returned as part of ordinary tool results. These records support the service, security, accounting and investigation of failures or abuse.

An AI action requested through the assistant may send the needed task context and selected media to the configured AI provider for that function. When preparing a publication, SMAT may also send its text to the configured AI provider to assess whether a disclosure is required. This system check is funded by SMAT and does not consume your credits; it does not order new text or an image. An authorized publication sends selected content and media to the connected social platform. Reading saved data, obtaining an estimate and preparing a publication do not themselves order AI generation or publish content.

You can revoke the MCP connection in SMAT and remove it from the assistant. Revocation blocks new authorized requests through that connection. It does not automatically erase saved drafts, already accepted operations, scheduled or published posts, or copies previously received by the assistant provider. Cancel scheduled publications separately in SMAT. The table below gives the retention criteria for MCP data held by SMAT. An expired preview link is not deletion of its underlying media. The assistant provider controls its own copies and conversation history. For SMAT data requests, contact [email protected].

MCP dataRetention start and end criterionExceptions and limits
Connection recordCreated with authorization; retained until account erasure or the applicable brand/tenant purge. Revocation or expiry ends access but does not itself delete the row.Separate records required for legal duties, security or claims may remain under the general retention rules.
Account-linked OAuth artifactsCreated during authorization; removed by the relevant protocol deletion, grant revocation where linked, or account erasure. Expiry stops use but does not itself guarantee immediate deletion of the stored artifact.A separately registered OAuth client can outlive one grant; copies held by the assistant provider follow its own policy.
Operation receipts and result summariesCreated when an operation is attempted; the receipt remains until account erasure or deletion of the connection. A result summary may be removed earlier when the operation is pruned or tombstoned. Revocation or expiry does not itself delete the receipt.Separate billing, security or dispute records may remain where required.
Uploaded or generated mediaStored from upload or generation while associated with a brand. Brand or tenant purge removes the files of content that still exists and brand files such as logos and style references. When you delete an unpublished draft, its record is deleted immediately and a background job removes every file stored for that draft (uploads, generated and edited images, text-on-image renders and previews, videos and thumbnails) about one hour later, retrying automatically; if the files still cannot be removed, the SMAT team is alerted and removes them manually. Brand files and files of other content stay.Published platform copies are controlled by that platform. Preview-link expiry does not delete the underlying file.

4.Automated processing

SMAT sends the minimum context needed for selected text, image, audio-transcription, embedding and visual-analysis functions to configured OpenAI or Google services. When you use voice dictation, SMAT sends the recorded audio to OpenAI to produce a transcript. The transcript is inserted into the message composer for your review and is not sent as a chat message automatically. The active path depends on the feature. There is no active Anthropic fallback. We do not state that provider training is contractually disabled unless a current provider receipt establishes it.

SMAT profiles brand and content signals to provide suggestions and outputs. These product recommendations do not by themselves produce legal or similarly significant effects about a person. Some publishing flows can act on account configuration; therefore this Notice does not promise blanket human review. Selective AI transparency controls are described in the AI Disclosure.

5.Payments, email and social platforms

Stripe receives buyer, payment and transaction data to run checkout, subscriptions, refunds and invoices. Resend receives the email address and confirmation content needed to send transactional messages. Meta receives OAuth credentials, publication content and platform results when a user connects Facebook or Instagram and asks SMAT to publish or synchronize. These providers act under their own terms where they determine processing and as processors where the applicable arrangement says so.

6.Cookies and marketing measurement

Necessary and functional browser storage supports sessions, security, language and consent choices. Optional analytics and marketing storage is blocked until the relevant consent. The marketing implementation can use Google Tag Manager and Meta measurement after opt-in, including Meta _fbp and _fbc cookies and SMAT attribution keys. Withdrawal prevents future optional use and clears storage owned by SMAT where technically available. See the Cookie Policy for the current inventory.

7.Recipients and international transfers

The current product code integrates the providers listed below for the stated functions. A code integration is not proof of a signed data-processing agreement, Data Privacy Framework participation or Standard Contractual Clauses. SMAT must verify current contractual role, location and transfer mechanism before activating a dependent production flow. We do not publish an unverified transfer claim.

8.Retention and security

We keep data only while needed for the account and requested features, applicable legal retention, security, dispute handling and demonstrated consent. Account erasure removes or anonymises data through the service’s registered cleanup paths, except records that must be retained or isolated by law. Provider-side deletion may take the time allowed by the applicable service.

Controls include access restrictions, session security, audit records, encryption in transit, secret management, tenant scoping, safe outbound fetching and incident procedures. No internet service can promise absolute security.

9.Your rights

Where the GDPR applies, you may request access, correction, erasure, restriction, portability and information about processing, and object to legitimate-interest processing. You may withdraw consent at any time without affecting earlier lawful processing. The application provides account export and deletion paths; you may also email [email protected].

You may complain to the competent supervisory authority. For the controller in Poland, this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

10.Current product providers and evidence status

The table states only functions verified in the repository. A product integration does not establish whether a provider is a controller, processor or sub-processor. Each dependent production flow remains blocked until the owner retains evidence of the provider’s contractual role and transfer position. Changes that materially affect this Notice require a new document version rather than silently changing the archived version.

ProviderVerified product functionData involvedContractual role / statusIntegration evidence
OpenAIText generation, assistant, voice transcription, publication-text disclosure assessment and selected image processingVoice recordings submitted for transcription, instructions, brand context, publication text, generated content and limited telemetryunverified — dependent production flow blockedRepository integration verified; contractual and transfer receipt absent
GoogleSelected image generation, embeddings and visual analysisInstructions, media, brand context and limited telemetryunverified — dependent production flow blockedRepository integration verified; contractual and transfer receipt absent
StripeCheckout, subscriptions, refunds and invoicesBuyer, tax, payment and transaction dataunverified — dependent production flow blockedRepository integration verified; contractual role receipt absent
ResendTransactional and purchase-confirmation emailRecipient address and message contentunverified — dependent production flow blockedRepository integration verified; contractual and transfer receipt absent
CloudflareBot protection and object storageNetwork/browser signals and stored media, depending on featureunverified — dependent production flow blockedRepository integrations verified; scope-specific contractual receipt absent
MetaFacebook and Instagram connection, publishing and result syncOAuth token, selected content and platform identifiersunverified — dependent production flow blockedRepository integration verified; contractual role receipt absent