Data Donation Privacy Notice
Version 1.0 · Effective 26 August 2026
Last updated: 27 August 2026
1. Controller
The controller is Jan Brožíček, registration no. IČO 08764832, registered address Rižská 1492/2, 102 00, Praha, privacy e-mail brozicekj@gmail.com, website https://llmpanel.cz (“we”, “us”).
2. Scope
This notice explains processing of personal data relating to your account, analytics profile and Data Donations. It also explains the local browser preparation of an export. The original export ZIP is not uploaded to our server as a Data Donation.
3. Personal data we process
Account/authentication
- e-mail address;
- internal account/authentication identifier;
- account creation, login and related authentication timestamps.
Analytics profile
- age group;
- gender;
- country and region;
- municipality size;
- employment status;
- employment area;
- seniority;
- education;
- frequency of AI use.
Data Donation
- selected sanitized human prompts;
- sanitized AI responses if included by you;
- provider, currently ChatGPT;
- safe technical record metadata;
- redaction metadata;
- metadata about source-code removal without the removed code;
- participant-scoped deterministic SHA-256 fingerprints used for deduplication;
- a historical analytics-profile snapshot valid at the time of the completed Data Donation;
- donation-process status such as completed or abandoned.
Operational/security data
- IP address, browser/device information and ordinary HTTP/server metadata;
- security, error and audit records;
- records of consent wording/version, withdrawal and deletion;
- support and privacy-rights communications.
4. Data we do not receive as Data Donation content
- the original export ZIP;
- a separate server copy of the original unsanitized text;
- raw ChatGPT message or conversation IDs;
- conversation titles;
- attachment content;
- removed source code;
- user.json content.
These elements may temporarily exist in your browser memory during local processing, but they are not intended to be transferred to our backend.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation, Magic Link and core account functions | Account/authentication data | Art. 6(1)(b) GDPR – performance of a contract / steps requested by you |
| Service security, abuse prevention and diagnostics | Operational/security data | Art. 6(1)(f) – our legitimate interests in secure and reliable operation |
| Creating and retaining an analytics profile for Data Donation | Profile data | Art. 6(1)(a) – your consent |
| Storing and analysing your selected sanitized Data Donation | Donation text, metadata, snapshot and fingerprints | Art. 6(1)(a) – your consent |
| Processing special-category data concerning you if it remains in the donation copy | Article 9 special categories | Art. 6(1)(a) + Art. 9(2)(a) GDPR – your explicit consent |
| AI-usage analytics, segmentation, benchmarking and development of aggregated/anonymised and commercial analytical products | Profile + donation data while personal | The same Art. 6(1)(a) consent and, where applicable, Art. 9(2)(a) explicit consent; the commercial purpose is expressly included in the consent request |
| Evidence of consent/withdrawal/deletion and legal claims | Audit/consent metadata | Art. 6(1)(f); and Art. 6(1)(c) where a specific legal duty applies |
| Narrow handling, assessment and deletion of incidental third-party data | Residual third-party data | Not an intended analytics purpose; only necessary security/request-handling/deletion steps may rely on Art. 6(1)(f) where its conditions are met |
Where processing is based on consent, refusal or withdrawal does not create unlawful consequences. Without the relevant consent, however, we cannot include the Data Donation in a personal/pseudonymised analytics dataset.
6. Special categories of personal data
AI conversations may contain special-category data. We process such data concerning you only on the basis of a separate explicit consent. Because sanitization cannot guarantee that all such information is removed, explicit consent forms part of completing a Data Donation. If you do not wish to give it, do not complete or submit that Data Donation.
7. Criminal convictions and offences
The service is not intended to collect or analyse personal data relating to criminal convictions, offences or related security measures under Article 10 GDPR. Users are instructed not to knowingly provide such data. If we identify it, we may restrict processing and delete it unless we have a specific legal authorisation for further processing.
8. Data about other people
Conversations may inadvertently contain information about another person. Before submission, we ask you to exclude identifiable third-party data, particularly sensitive data. If you learn that a Data Donation may contain personal data about you even though you do not have an account with us, contact brozicekj@gmail.com. See also Information for people mentioned in a Data Donation.
Where personal data is not obtained directly from the affected person, Article 14 GDPR may apply. Our privacy-by-design objective is to minimise such data rather than build a dataset of identifiable third parties.
9. Sanitization and pseudonymisation
Sanitization runs automatically in the browser and reduces the risk of transferring selected identifiers and sensitive technical data. It does not guarantee anonymisation. Pseudonymised fingerprints and donation records remain personal data while we can link them to your account or participant_id. We treat an output as anonymous only once identification is no longer reasonably possible considering means reasonably likely to be used.
10. Recipients and processors
Our processors and their subprocessors may access personal data only to the extent necessary to provide their services.
| Provider | Service | Production location |
|---|---|---|
| Hetzner Online GmbH | VPS / application hosting | Finland, Helsinki region (HEL1 / hel1-dc2), EEA |
| Supabase Pte. Ltd. | Authentication, database and platform | eu-west-1 (West EU - Ireland) |
| Supabase Auth built-in email provider | Magic Link authentication e-mail | Provided as part of the configured Supabase Auth service |
Under the launch model, our customers do not receive pseudonymised individual donation records. They receive aggregated or genuinely anonymised outputs. If this changes, we will update this notice and the legal/consent framework before the new disclosure begins.
11. International transfers
Primary VPS/application hosting is in Finland and the configured Supabase project is in West EU (Ireland), both within the EEA. We do not assert here that a particular Article 28 data-processing agreement, Standard Contractual Clauses, adequacy decision or other transfer mechanism applies unless that fact has been independently verified. If a provider or subprocessor makes a restricted international transfer, the transfer must use a safeguard required by GDPR. You may request current information at brozicekj@gmail.com.
12. Retention
| Category | Retention |
|---|---|
| Account/authentication | For the life of the account; after a valid deletion request can be implemented, removal from production is targeted without undue delay and within 30 days |
| Profile with no completed donation | While the account remains active; cleanup target after 24 months of inactivity following prior notice |
| Completed Data Donation, snapshot and fingerprints | Until consent withdrawal or maximum 36 months from that donation; then delete or irreversibly anonymise |
| Incomplete or abandoned Data Donations | We target deletion of incomplete or abandoned donation data within 30 days after abandonment or after the upload becomes stale. Depending on how far the upload progressed, this may include sanitized donated text and related metadata. The original export file and unsanitized conversation archive are not uploaded to our servers. |
| Ordinary security/server logs | Normally 90 days; longer only for an incident or legal claim |
| Consent/withdrawal/deletion evidence | Target 3 years after withdrawal/account closure, without donation text |
| Support/privacy correspondence | 3 years after case closure unless longer retention is necessary |
| Backups | Rolling maximum target 35 days; the deletion ledger is re-applied after a disaster restore |
| Genuinely anonymous aggregate outputs | Indefinitely, provided they are no longer personal data |
Retention periods described as targets require operational retention automation and backup-expiry controls. Until those controls are completed, they must not be understood as a claim that automated deletion is already implemented.
13. Withdrawal and deletion of Data Donations
You can withdraw consent at any time in your account using “Withdraw consent & delete my Data Donations” or by contacting brozicekj@gmail.com. Once the request is validly made, we stop further consent-based processing and remove participant-linked donation records from active systems, including donation text, optional AI responses, related metadata, historical profile snapshots and participant-linked fingerprints. Withdrawal does not affect the lawfulness of processing before withdrawal.
If data had already been genuinely anonymised and incorporated into aggregate statistics so that your contribution can no longer be identified, it cannot be reverse-extracted from that anonymous result.
14. Account deletion
Authenticated users can use “Delete my account and research data” from the account section of their dashboard. This deletes the authentication account and active participant-linked research, profile and account data, and signs the user out. The separate “Withdraw consent & delete my Data Donations” action deletes participant-linked Data Donation research data but leaves the account and Terms acceptance available.
Account deletion does not necessarily erase minimal consent, withdrawal and deletion evidence retained for accountability and legal claims; the target retention period for that evidence is 3 years after withdrawal or account closure, without donation text. Data may also remain temporarily in rolling backups until their normal expiry, with a rolling maximum target of 35 days. Genuinely anonymised aggregate outputs that can no longer be linked to you cannot be reverse-extracted and may be retained indefinitely while they remain anonymous.
15. Your rights
- right to information and access;
- right to rectification;
- right to erasure where conditions are met;
- right to restriction;
- right to data portability where Article 20 conditions are met;
- right to withdraw consent at any time;
- right to object, on grounds relating to your particular situation, to processing based on legitimate interests;
- right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ) or another competent EU/EEA supervisory authority.
Send requests to brozicekj@gmail.com. We may reasonably verify identity, especially for requests made outside an authenticated account.
16. Automated processing
We may automatically categorise, aggregate and statistically analyse profile data and Data Donations. We do not use them to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
17. Security
We use technical and organisational measures appropriate to the risk, including local sanitization before transfer, data minimisation, encrypted transmission, access controls, separation of operational roles, audit records, backups and incident procedures. No technical measure provides absolute security, so we review risks and controls on an ongoing basis.
18. Changes to this notice
We may update this notice. If a change materially alters a consent-based purpose or legal basis, we will not treat the new purpose as automatically covered by the old consent. Where fresh consent is required, we will obtain it before the new processing begins. The current version is published at https://llmpanel.cz/privacy with its effective date.