← Data Donation

Data Donation Privacy Notice

Version 1.0 · Effective 26 August 2026

Last updated: 27 August 2026

1. Controller

The controller is Jan Brožíček, registration no. IČO 08764832, registered address Rižská 1492/2, 102 00, Praha, privacy e-mail brozicekj@gmail.com, website https://llmpanel.cz (“we”, “us”).

2. Scope

This notice explains processing of personal data relating to your account, analytics profile and Data Donations. It also explains the local browser preparation of an export. The original export ZIP is not uploaded to our server as a Data Donation.

3. Personal data we process

Account/authentication

  • e-mail address;
  • internal account/authentication identifier;
  • account creation, login and related authentication timestamps.

Analytics profile

  • age group;
  • gender;
  • country and region;
  • municipality size;
  • employment status;
  • employment area;
  • seniority;
  • education;
  • frequency of AI use.

Data Donation

  • selected sanitized human prompts;
  • sanitized AI responses if included by you;
  • provider, currently ChatGPT;
  • safe technical record metadata;
  • redaction metadata;
  • metadata about source-code removal without the removed code;
  • participant-scoped deterministic SHA-256 fingerprints used for deduplication;
  • a historical analytics-profile snapshot valid at the time of the completed Data Donation;
  • donation-process status such as completed or abandoned.

Operational/security data

  • IP address, browser/device information and ordinary HTTP/server metadata;
  • security, error and audit records;
  • records of consent wording/version, withdrawal and deletion;
  • support and privacy-rights communications.

4. Data we do not receive as Data Donation content

  • the original export ZIP;
  • a separate server copy of the original unsanitized text;
  • raw ChatGPT message or conversation IDs;
  • conversation titles;
  • attachment content;
  • removed source code;
  • user.json content.

These elements may temporarily exist in your browser memory during local processing, but they are not intended to be transferred to our backend.

5. Purposes and legal bases

PurposeDataLegal basis
Account creation, Magic Link and core account functionsAccount/authentication dataArt. 6(1)(b) GDPR – performance of a contract / steps requested by you
Service security, abuse prevention and diagnosticsOperational/security dataArt. 6(1)(f) – our legitimate interests in secure and reliable operation
Creating and retaining an analytics profile for Data DonationProfile dataArt. 6(1)(a) – your consent
Storing and analysing your selected sanitized Data DonationDonation text, metadata, snapshot and fingerprintsArt. 6(1)(a) – your consent
Processing special-category data concerning you if it remains in the donation copyArticle 9 special categoriesArt. 6(1)(a) + Art. 9(2)(a) GDPR – your explicit consent
AI-usage analytics, segmentation, benchmarking and development of aggregated/anonymised and commercial analytical productsProfile + donation data while personalThe same Art. 6(1)(a) consent and, where applicable, Art. 9(2)(a) explicit consent; the commercial purpose is expressly included in the consent request
Evidence of consent/withdrawal/deletion and legal claimsAudit/consent metadataArt. 6(1)(f); and Art. 6(1)(c) where a specific legal duty applies
Narrow handling, assessment and deletion of incidental third-party dataResidual third-party dataNot an intended analytics purpose; only necessary security/request-handling/deletion steps may rely on Art. 6(1)(f) where its conditions are met

Where processing is based on consent, refusal or withdrawal does not create unlawful consequences. Without the relevant consent, however, we cannot include the Data Donation in a personal/pseudonymised analytics dataset.

6. Special categories of personal data

AI conversations may contain special-category data. We process such data concerning you only on the basis of a separate explicit consent. Because sanitization cannot guarantee that all such information is removed, explicit consent forms part of completing a Data Donation. If you do not wish to give it, do not complete or submit that Data Donation.

7. Criminal convictions and offences

The service is not intended to collect or analyse personal data relating to criminal convictions, offences or related security measures under Article 10 GDPR. Users are instructed not to knowingly provide such data. If we identify it, we may restrict processing and delete it unless we have a specific legal authorisation for further processing.

8. Data about other people

Conversations may inadvertently contain information about another person. Before submission, we ask you to exclude identifiable third-party data, particularly sensitive data. If you learn that a Data Donation may contain personal data about you even though you do not have an account with us, contact brozicekj@gmail.com. See also Information for people mentioned in a Data Donation.

Where personal data is not obtained directly from the affected person, Article 14 GDPR may apply. Our privacy-by-design objective is to minimise such data rather than build a dataset of identifiable third parties.

9. Sanitization and pseudonymisation

Sanitization runs automatically in the browser and reduces the risk of transferring selected identifiers and sensitive technical data. It does not guarantee anonymisation. Pseudonymised fingerprints and donation records remain personal data while we can link them to your account or participant_id. We treat an output as anonymous only once identification is no longer reasonably possible considering means reasonably likely to be used.

10. Recipients and processors

Our processors and their subprocessors may access personal data only to the extent necessary to provide their services.

ProviderServiceProduction location
Hetzner Online GmbHVPS / application hostingFinland, Helsinki region (HEL1 / hel1-dc2), EEA
Supabase Pte. Ltd.Authentication, database and platformeu-west-1 (West EU - Ireland)
Supabase Auth built-in email providerMagic Link authentication e-mailProvided as part of the configured Supabase Auth service

Under the launch model, our customers do not receive pseudonymised individual donation records. They receive aggregated or genuinely anonymised outputs. If this changes, we will update this notice and the legal/consent framework before the new disclosure begins.

11. International transfers

Primary VPS/application hosting is in Finland and the configured Supabase project is in West EU (Ireland), both within the EEA. We do not assert here that a particular Article 28 data-processing agreement, Standard Contractual Clauses, adequacy decision or other transfer mechanism applies unless that fact has been independently verified. If a provider or subprocessor makes a restricted international transfer, the transfer must use a safeguard required by GDPR. You may request current information at brozicekj@gmail.com.

12. Retention

CategoryRetention
Account/authenticationFor the life of the account; after a valid deletion request can be implemented, removal from production is targeted without undue delay and within 30 days
Profile with no completed donationWhile the account remains active; cleanup target after 24 months of inactivity following prior notice
Completed Data Donation, snapshot and fingerprintsUntil consent withdrawal or maximum 36 months from that donation; then delete or irreversibly anonymise
Incomplete or abandoned Data DonationsWe target deletion of incomplete or abandoned donation data within 30 days after abandonment or after the upload becomes stale. Depending on how far the upload progressed, this may include sanitized donated text and related metadata. The original export file and unsanitized conversation archive are not uploaded to our servers.
Ordinary security/server logsNormally 90 days; longer only for an incident or legal claim
Consent/withdrawal/deletion evidenceTarget 3 years after withdrawal/account closure, without donation text
Support/privacy correspondence3 years after case closure unless longer retention is necessary
BackupsRolling maximum target 35 days; the deletion ledger is re-applied after a disaster restore
Genuinely anonymous aggregate outputsIndefinitely, provided they are no longer personal data

Retention periods described as targets require operational retention automation and backup-expiry controls. Until those controls are completed, they must not be understood as a claim that automated deletion is already implemented.

13. Withdrawal and deletion of Data Donations

You can withdraw consent at any time in your account using “Withdraw consent & delete my Data Donations” or by contacting brozicekj@gmail.com. Once the request is validly made, we stop further consent-based processing and remove participant-linked donation records from active systems, including donation text, optional AI responses, related metadata, historical profile snapshots and participant-linked fingerprints. Withdrawal does not affect the lawfulness of processing before withdrawal.

If data had already been genuinely anonymised and incorporated into aggregate statistics so that your contribution can no longer be identified, it cannot be reverse-extracted from that anonymous result.

14. Account deletion

Authenticated users can use “Delete my account and research data” from the account section of their dashboard. This deletes the authentication account and active participant-linked research, profile and account data, and signs the user out. The separate “Withdraw consent & delete my Data Donations” action deletes participant-linked Data Donation research data but leaves the account and Terms acceptance available.

Account deletion does not necessarily erase minimal consent, withdrawal and deletion evidence retained for accountability and legal claims; the target retention period for that evidence is 3 years after withdrawal or account closure, without donation text. Data may also remain temporarily in rolling backups until their normal expiry, with a rolling maximum target of 35 days. Genuinely anonymised aggregate outputs that can no longer be linked to you cannot be reverse-extracted and may be retained indefinitely while they remain anonymous.

15. Your rights

  • right to information and access;
  • right to rectification;
  • right to erasure where conditions are met;
  • right to restriction;
  • right to data portability where Article 20 conditions are met;
  • right to withdraw consent at any time;
  • right to object, on grounds relating to your particular situation, to processing based on legitimate interests;
  • right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ) or another competent EU/EEA supervisory authority.

Send requests to brozicekj@gmail.com. We may reasonably verify identity, especially for requests made outside an authenticated account.

16. Automated processing

We may automatically categorise, aggregate and statistically analyse profile data and Data Donations. We do not use them to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

17. Security

We use technical and organisational measures appropriate to the risk, including local sanitization before transfer, data minimisation, encrypted transmission, access controls, separation of operational roles, audit records, backups and incident procedures. No technical measure provides absolute security, so we review risks and controls on an ongoing basis.

18. Changes to this notice

We may update this notice. If a change materially alters a consent-based purpose or legal basis, we will not treat the new purpose as automatically covered by the old consent. Where fresh consent is required, we will obtain it before the new processing begins. The current version is published at https://llmpanel.cz/privacy with its effective date.