Welcome to the privacy policy of Plyveo. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.
Latest update: July 18, 2026
Summary
Data we collect automatically
We automatically collect data from you for example when you visit Plyveo.
Federico Rossi - Viale Antonio Ciamarra 30 - 00173 Roma (Italia)
Owner contact email: plyveoapp@gmail.com
Type of Data we collect
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
first name
email address
profile picture
social media accounts
Trackers
Usage Data
device information
number of sessions
session duration
operating systems
Universally unique identifier (UUID)
crash data
User ID
last name
Microphone permission, without recording
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application. Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service. Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner. Any use of Cookies – or of other tracking tools — by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.
The purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
Registration and authentication
Analytics
Infrastructure monitoring
Hosting and backend infrastructure
Platform services and hosting
Device permissions for Personal Data access
Beta Testing
Provision of the Service
Spam and bots protection
Detailed information on the processing of Personal Data
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics for Firebase (for apps)
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: device information +5
Google Analytics for Firebase (for apps) or Firebase Analytics is an analytics service provided by Google Ireland Limited.
In order to understand Google's use of Data, consult Google's partner policy.
Firebase Analytics may share Data with other tools provided by Firebase, such as Crash Reporting, Authentication, Remote Config or Notifications. The User may check this privacy policy to find a detailed explanation about the other tools used by the Owner.
This Application uses identifiers for mobile devices and technologies similar to cookies to run the Firebase Analytics service.
Users may opt-out of certain Firebase features through applicable device settings, such as the device advertising settings for mobile phones or by following the instructions in other Firebase related sections of this privacy policy, if available.
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Consent and configuration for Google Analytics for Firebase
Company: this Application
Personal Data processed: Trackers
Plyveo uses Google Analytics for Firebase, an app-measurement service provided by Google Ireland Limited (Ireland), exclusively in production releases and only after the User has made a positive and specific choice for the Measurement purpose.
Activation and control: Analytics collection is disabled by default in the app's native configuration. Refusal does not restrict access to Plyveo or any of its core functions. The User can grant or withdraw consent during onboarding or at any time through the “Anonymous usage statistics” switch available in Settings. Despite the name currently displayed in the interface, the processed data is pseudonymous and is not anonymous in the strict technical or legal sense. Withdrawal stops future collection from that installation of the app but does not automatically delete data already transmitted. General device advertising settings do not replace the switch available within Plyveo.
Data processed automatically: when Analytics is enabled, Google generates a pseudonymous app-instance identifier associated with a specific installation and may process mobile-app Trackers and Usage Data, including app launches and updates, event dates and times, screens viewed, number and duration of sessions, platform, operating system, device model or category, app version, language or locale and approximate geographic location. The IP address is used during collection to derive approximate location and route the data; Google states that the raw IP address is discarded before the data is logged on its Analytics servers.
Events sent by Plyveo: successful sign-in without account details; onboarding started, completed or skipped; test and category identifiers and test kind; test opening; practice start, completion, duration and overtime; occurrence of a saved session, without transmitting its local identifier; viewing of the readiness summary and readiness percentage; answer-evaluation mode and the question's position within the test; display and selection of upgrade messages; and a yes/no vote concerning the usefulness of AI feedback.
Data not intentionally sent: Plyveo does not set a Google Analytics User-ID and does not send the Firebase UID, authentication-provider subject, name, email address, profile image, answer or draft text, transcripts, notes, local session ID, model answer, prompt or AI-feedback content to this service.
Device identifiers: on Android, Plyveo expressly removes from the app package the permission required to access the Android Advertising ID. On iOS, Plyveo does not request App Tracking Transparency authorization and does not intentionally use the IDFA. When the IDFA is unavailable, Google Analytics may use Apple's Identifier for Vendor (IDFV), in addition to the pseudonymous app-instance identifier. Plyveo does not use this data to display advertising, create employment profiles, make automated decisions or assess the User's suitability for employment.
Legal basis and optional nature: processing is based on the User's consent under Article 6(1)(a) GDPR and, where applicable, consent for access to or storage of mobile-app Trackers under ePrivacy rules. Providing consent is optional and refusal does not prevent the use of the app's core functions.
Retention: in the Google Analytics property connected to Plyveo, both event-level and user-level data retention are set to 2 months and “Reset user data on new activity” is disabled. Data reaching the end of that period is deleted by Google through a monthly process. This setting does not delete standard aggregated reports, which may remain available in aggregated form. The local app-instance identifier may persist for the duration of the installation, until it is reset, the app's data is cleared or the app is uninstalled. The consent choice, the date of that choice and the version of the notice are stored locally as described in the section concerning local preference storage.
Account deletion: when the User deletes their account, Plyveo disables Analytics collection, removes the locally stored consent choice, the date of that choice and the version of the privacy notice, and instructs the Firebase Analytics SDK to reset locally held Analytics data and the pseudonymous app-instance identifier. Collection remains disabled until the User makes a new positive choice.
This operation concerns the current installation and does not retroactively erase data already received by Google Analytics. Because Plyveo does not set a User-ID or associate this data with the Firebase UID, previously transmitted data cannot be selected and deleted by reference to the Plyveo account and remains subject to the 2-month retention period described above. Standard aggregated reports may remain available in aggregated form.
Provider and transfers: the service is provided by Google Ireland Limited. Any transfers are governed by Google's applicable terms and safeguards. Provider privacy policy: https://policies.google.com/privacy
Personal Data processed:
Trackers
Service provided by:
this Application
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Beta Testing
This type of service makes it possible to manage User access to this Application, or parts of it, for the purpose of testing a certain feature or the entire Application.
The service provider may automatically collect data related to crashes and statistics related to the User's use of this Application in a personally identifiable form.
TestFlight
Company: Apple Inc.
Place of processing: United States
Personal Data processed: device information +1
TestFlight is a beta testing service provided by Apple Inc.
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Device permissions for Personal Data access
This Application requests certain permissions from Users that allow it to access the User's device Data as described below.
Device permissions for Personal Data access
Personal Data processed: Microphone permission, without recording
This Application requests certain permissions from Users that allow it to access the User's device Data as summarized here and described within this document.
Personal Data processed:
Microphone permission, without recording
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Hosting and backend infrastructure
This type of service has the purpose of hosting Data and files that enable this Application to run and be distributed or to provide a ready-made infrastructure to run specific features or parts of this Application.
Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Firebase Cloud Functions
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: Usage Data +1
Firebase Cloud Functions is a hosting and backend service provided by Google Ireland Limited.
Personal Data processed:
Usage Data
various types of Data as specified in the privacy policy of the service
Category of Personal Information collected according to the CCPA
identifiers
internet or other electronic network activity information
Backend execution through Firebase Cloud Functions
Company: this Application
Plyveo uses Firebase Cloud Functions to operate the protected backend services required for answer evaluation and usage-quota retrieval. The functions, named “evaluateAnswer” and “getQuota”, are available only to authenticated Users and also require a valid Firebase App Check token.
Data processed by the “evaluateAnswer” function: Firebase UID and technical information contained in the authentication token; Firebase App Check token; IP address and technical request metadata; test question; evaluation-criterion title and description; strong-answer and weak-answer indicators; model answer; the User's answer text, limited to a maximum of 2,000 characters before being included in the prompt; answer language; requested feedback language; and the local practice-session identifier.
The function transmits to Vertex AI only the data required to generate the evaluation described in the relevant section of this Privacy Policy. The result returned to the app may include a score from 1 to 4, strengths, suggested improvements and, where applicable, English-language feedback.
Data processed by the “getQuota” function: this function does not receive answers, drafts, transcripts, notes, prompts or AI feedback. It receives only the Firebase Authentication context, Firebase App Check token and technical metadata required for the request, and returns the available usage quotas.
Purpose and legal basis: authenticating and validating requests, providing the AI evaluation requested by the User, displaying available quotas, enforcing usage limits and preserving the security and availability of the service. Provision of the requested functionality is based on performance of the contract under Article 6(1)(b) GDPR. Security checks, quota management and abuse prevention are based on the Owner's legitimate interest under Article 6(1)(f) GDPR.
Retention: Plyveo does not use Firebase Cloud Functions to permanently store answer text, the complete prompt or AI feedback. Such data is processed transiently to execute the request and return the result. The application code does not intentionally write answer text, prompts or generated feedback to logs. Firebase states that IP addresses processed by Cloud Functions are retained only temporarily to provide the service. Any counters and pseudonymous identifiers stored separately in Cloud Firestore are described in the section concerning usage-quota management.
Location: both functions are configured in the Google Cloud technical region “europe-west1”, corresponding to Belgium. This technical execution region is distinct from the provider's contracting entity. Subsequent AI processing takes place through the Vertex AI EU regional endpoint and is described in the relevant section.
Account deletion: Firebase Cloud Functions is not a permanent repository of account content and does not retain an independent copy of local sessions. After account deletion, the functions can no longer be invoked as an authenticated User. Any data separately retained by Firebase Authentication, Cloud Firestore, Analytics or other services follows the respective retention periods described in this Privacy Policy.
Provider and transfers: Firebase Cloud Functions is provided by Google. Any international transfers or technical processing occurring outside the selected region are governed by Google's applicable terms and safeguards, including, where applicable, Standard Contractual Clauses and the Data Privacy Framework.
Google Privacy Policy: https://policies.google.com/privacy
Infrastructure monitoring
This type of service allows this Application to monitor the use and behavior of its components so its performance, operation, maintenance and troubleshooting can be improved.
Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of this Application.
Crashlytics
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: crash data +3
Crashlytics is a monitoring service provided by Google Ireland Limited.
Category of Personal Information collected according to the CCPA
identifiers
internet or other electronic network activity information
Configuration and use of Firebase Crashlytics in Plyveo
Company: this Application
Personal Data processed: Trackers
Plyveo uses Firebase Crashlytics, a crash-diagnostics service provided by Google Ireland Limited, exclusively in native production releases of the app. Crashlytics collection is disabled in development and debug builds.
Crashlytics operates independently of Google Analytics for Firebase and of the User's related choice. The service is used exclusively to identify errors, crashes and technical problems and to improve the security, reliability and stability of Plyveo.
Data processed: Crashlytics may process a pseudonymous installation identifier, including the Firebase Installation ID and Crashlytics Installation UUID; a random technical Crashlytics session identifier, which is separate from Plyveo practice-session identifiers; the date and time of the error; stack traces; technical exception or crash details; the app identifier and version; operating system; device model, architecture and technical state; memory, available storage and other diagnostic information required to investigate the problem. Plyveo also forwards fatal and non-fatal errors intercepted by the app together with the corresponding stack trace.
Data not intentionally sent: Plyveo does not set a User identifier in Crashlytics and does not intentionally send the Firebase UID, authentication-provider subject, name, email address, profile image, answers, drafts, transcripts, notes, practice-session identifiers, prompts, model answers or AI-feedback content. Plyveo also does not add custom keys, custom logs or data intended to profile the User.
Legal basis and purpose: processing is based on the Owner's legitimate interest under Article 6(1)(f) GDPR in protecting Plyveo, diagnosing malfunctions and maintaining a secure, stable and reliable service. Crashlytics is not used for advertising, employment profiling, automated decision-making or assessing the User's professional suitability.
Retention and deletion: Google retains crash stack traces, diagnostic data and identifiers associated with Crashlytics reports for 90 days before starting their removal from live and backup systems. When the User deletes their Plyveo account, the app also requests deletion of the current Firebase Installation ID. This rotates the Crashlytics Installation UUID; Firebase states that data tied to the previous installation is removed from live and backup systems within 180 days. If Firebase services are subsequently used again, a new installation identifier unrelated to the previous one may be generated.
Transfers: data may be processed in countries where Google or its subprocessors maintain facilities. Any international transfers are governed by the safeguards provided by the Firebase Data Processing and Security Terms, including Standard Contractual Clauses or another applicable transfer solution.
Data processing terms: https://firebase.google.com/terms/data-processing-terms
Personal Data processed:
Trackers
Service provided by:
this Application
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Platform services and hosting
These services have the purpose of hosting and running key components of this Application, therefore allowing the provision of this Application from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data.
Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Google Play Store
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: Usage Data
This Application is distributed on the Google Play Store, a platform for the distribution of mobile apps, provided by Google Ireland Limited.
By virtue of being distributed via this app store, Google collects usage and diagnostics data and share aggregate information with the Owner. Much of this information is processed on an opt-in basis.
Users may opt-out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
App Store Connect
Company: Apple Inc.
Place of processing: United States
Personal Data processed: Usage Data
This Application is distributed on Apple's App Store, a platform for the distribution of mobile apps, provided by Apple Inc.
App Store Connect enables the Owner to manage this Application on Apple's App Store. Depending on the configuration, App Store Connect provides the Owner with analytics data on user engagement and app discovery, marketing campaigns, sales, in-app purchases, and payments to measure the performance of this Application.
App Store Connect only collects such data from Users who have agreed to share them with the Owner. Users may find more information on how to opt out via their device settings here.
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Provision of the Service
AI evaluation of answers through Google Cloud Vertex AI
When the User expressly requests evaluation of an answer, Plyveo uses Google Cloud Vertex AI and a Gemini model, currently Gemini 3.5 Flash, to generate a score and educational feedback. No data is transmitted to Vertex AI when the User does not request an evaluation.
The request is first received by the protected “evaluateAnswer” backend function hosted on Firebase Cloud Functions. The function builds the prompt and authenticates to Vertex AI through its Google Cloud service-account identity. The User's Google or Apple credentials and Firebase Authentication token are not transmitted to the model.
Data transmitted to Vertex AI: test question; evaluation-criterion title and description; description of a strong answer and a weak answer; model answer; answer text entered by the User, limited to a maximum of 2,000 characters; answer language; requested feedback language; and technical instructions required to obtain the result in the expected format.
Data not intentionally transmitted to Vertex AI: Firebase UID; authentication-provider identifier; pseudonymous identifier used for quota management; name; email address; profile image; authentication token; App Check token; local session identifier; quota counters; other answers or sessions; drafts not submitted for evaluation; notes; or transcripts not included in the submitted answer.
The local session identifier is used by the backend function for quota management but is not included in the prompt transmitted to Vertex AI.
Generated result: Vertex AI returns an integer score from 1 to 4, up to three strengths, up to three suggested improvements and, where applicable, feedback concerning English clarity. The result is transmitted to the app and stored locally in the User's practice session. Plyveo does not use Vertex AI as a permanent repository for sessions or results.
Purpose and legal basis: providing the educational evaluation requested by the User as part of the Plyveo service. Processing is based on performance of the contract under Article 6(1)(b) GDPR. The AI evaluation does not produce legal or similarly significant effects on the User, does not make hiring decisions, does not create profiles intended for employers and does not determine the User's professional suitability.
Evaluations are generated automatically, may contain errors or inaccuracies and are intended exclusively for educational and training purposes. They do not constitute professional advice or guarantee the outcome of an interview or hiring process. Users are advised not to include sensitive data, confidential information or third-party personal data in their answers.
Location: Plyveo uses the Vertex AI EU multi-regional endpoint, “aiplatform.eu.rep.googleapis.com”, with the technical location “eu”. Traffic directed to this endpoint is routed and TLS-terminated within the jurisdiction of the European Union. The technical region used is distinct from the provider's contracting entity and does not alter any contractual safeguards applicable to transfers.
Model training: Google states that Customer Data, including inputs and outputs, is not used to train or fine-tune artificial-intelligence or machine-learning models without the customer's prior permission or instruction. Plyveo does not authorize Google to use User answers or generated feedback to train or fine-tune models.
Ordinary caching and retention: Plyveo does not enable grounding with Google Search or Google Maps, session resumption, prompt saving or explicit context caching. However, under the standard configuration of Google's published Gemini models, inputs, outputs and derived data may be retained in an in-memory-only cache, not at rest, isolated at project level and subject to a maximum 24-hour time to live. Google states that this cache is used solely to improve service performance and complies with the data-residency requirements of the selected location.
Abuse monitoring: Google uses automated safety classifiers to detect possible abuse or violations of its policies. If those systems detect suspicious activity requiring further investigation, Google may log the relevant prompt solely to investigate a potential violation. Such prompts may be securely retained for up to 90 days in the same selected region or multi-region and may be reviewed by authorized Google personnel. Google states that this data is not used to train or fine-tune AI or machine-learning models.
Account deletion: because Plyveo does not include the Firebase UID, session identifier or other direct account identifiers in the prompt, Plyveo has no mechanism for locating and selectively deleting an already processed request from Vertex AI. Account deletion prevents new authenticated evaluations and removes the account's local results from the app, but does not shorten the expiration period of any in-memory cache or prompts retained by Google for abuse-monitoring purposes. Such data is deleted according to the maximum periods described above.
Provider and transfers: Vertex AI is provided by Google Cloud. Any international transfers are governed by Google's applicable terms and safeguards, including, where applicable, Standard Contractual Clauses and the Data Privacy Framework.
Information about data use and retention in Vertex AI: https://docs.cloud.google.com/vertex-ai/generative-ai/docs/vertex-ai-zero-data-retention
Cloud Data Processing Addendum: https://cloud.google.com/terms/data-processing-addendum
Google Privacy Policy: https://policies.google.com/privacy
Local storage of sessions and preferences
Company: this Application
Plyveo locally stores, in the app's private storage and application preferences, the data required to save and restore the User's practice activities.
Data processed: local session and test identifiers; answers and related drafts; any text transcripts produced through the dictation feature; notes; session progress; scores; individual criterion ratings; readiness indicators; feedback generated by artificial intelligence; dates and times associated with sessions; practice language; local onboarding and profile state; weekly goal; reminder and notification preferences; informational flags; and other local preferences associated with the account.
The User's Analytics choice, the date of that choice, the version of the privacy notice shown to the User, the quota displayed within the app and local technical data managed by the relevant SDK are also stored locally.
Purpose and legal basis: to enable automatic saving of answers and drafts, continuation of practice sessions, review of results and provision of the functions requested by the User. Processing required to provide these functions is based on performance of the requested service under Article 6(1)(b) GDPR. The Analytics choice is stored to respect and document the preference expressed by the User and does not enable Analytics without consent.
Ordinary retention: depending on the type of data and the relevant function, data remains on the device until it is deleted by the User, the account is deleted, the app's data is cleared or the app is uninstalled. Logging out does not delete local data, and signing in again with the same account may restore the User's existing activities.
Account deletion and account changes: after Firebase Authentication confirms deletion of the account, Plyveo removes from the current installation all app-managed local data associated with that account. This includes sessions, answers, drafts, transcripts, notes, scores, AI feedback, onboarding and profile state, the locally cached quota, goals, reminders, scheduled notifications, account preferences and temporary export or sharing files generated by Plyveo.
Plyveo also removes the Analytics choice, its date and notice version, locally held Analytics data and the pseudonymous app-instance identifier. Analytics collection returns to its disabled state and may be enabled again only after a new positive choice by the User.
Only the selected language and theme are preserved after deletion. Signing in with a different account also causes the previous account's data to be reset before the new account can use the app. If remote account deletion fails, local data is not removed. If local cleanup is interrupted after remote deletion, Plyveo automatically attempts to complete it safely.
Limitations of the local reset: resetting the installation does not immediately erase information already transmitted to providers, including Firebase Authentication, Firestore for quota and abuse prevention, Google Analytics, Firebase Crashlytics, Firebase App Check and Vertex AI. Such information remains subject to the retention periods described in the corresponding sections of this Privacy Policy.
Copies contained in operating-system backups may be retained separately according to the settings and terms of the relevant backup service. Files exported or shared by the User and copied outside the temporary storage controlled by Plyveo remain under the User's control and cannot be recalled or automatically deleted by the app.
Firebase Remote Config and operational app configuration
Plyveo uses Firebase Remote Config, a service provided by Google Ireland Limited, to distribute operational configuration without requiring an app update.
On the device, Remote Config provides the minimum and recommended app versions, the link for any required update, maintenance status and the availability of AI-based evaluation. The backend also uses a separate configuration template to manage the availability of the AI service and its usage limits.
Data processed: Firebase Remote Config uses a pseudonymous Firebase Installation ID (FID) and the technical data strictly necessary to return configuration values to the app installation. Retrieved configuration values may be temporarily stored on the device to enable the service to operate.
Plyveo does not intentionally send Remote Config the User's name, email address, profile image, Firebase UID, authentication-provider identifier, answers, drafts, transcripts, notes, local session identifiers, scores or AI-feedback content. Remote Config is not used for advertising, employment profiling or assessing the User's suitability for employment.
Legal basis: processing is necessary to perform the service requested by the User under Article 6(1)(b) GDPR and, for security, operational continuity, update management and protection of the service, for the Owner's legitimate interests under Article 6(1)(f) GDPR.
Retention and deletion: Firebase retains the Firebase Installation ID until deletion is requested through the applicable API. When the User deletes their Plyveo account, the app also requests deletion of the current Firebase installation. Google states that data associated with the deleted identifier is removed from the live and backup systems of the relevant Firebase services within 180 days. Subsequent use of Firebase services may generate a new installation identifier that is not associated with the previous one.
Processing location and transfers: Firebase Remote Config operates on Google's global infrastructure and data may also be processed outside the European Economic Area. Any transfers are governed by the Firebase Data Processing and Security Terms and, as applicable, the Data Privacy Framework, Standard Contractual Clauses or another transfer mechanism recognized under applicable law.
By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, this Application will be able to access some Data, stored by these third-party services, for registration or identification purposes.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.
Firebase Authentication
Company: Google LLC +1
Place of processing: United States +1
Personal Data processed: email address +3
Firebase Authentication is a registration and authentication service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing.
To simplify the registration and authentication process, Firebase Authentication can make use of third-party identity providers and save the information on its platform.
Category of Personal Information collected according to the CCPA
internet or other electronic network activity information
Sign in with Apple
Company: Apple Inc.
Place of processing: United States
Personal Data processed: email address +4
Sign in with Apple is a registration and authentication service provided by Apple Inc. In cases where Users are required to provide their email address, Sign in with Apple may generate a private relay address on behalf of Users that automatically forwards messages to their verified personal email account - therefore shielding their actual email address from the Owner.
Category of Personal Information collected according to the CCPA
identifiers
audio, electronic, visual, thermal, olfactory, or similar information
Firebase Authentication configuration and account management in Plyveo
Plyveo uses Firebase Authentication to provide registration, sign-in and account management exclusively through the Google or Apple providers available on the platform being used.
Data processed: Firebase UID; authentication provider and corresponding identifier; email address, name and profile image when made available by the provider; tokens and technical metadata required to maintain and verify the session; IP address and user-agent information processed by Firebase for security, abuse prevention and operation of the service.
Plyveo does not offer its own email-and-password authentication and does not request, receive or store the password of the User's Google or Apple account. Credentials are entered and managed directly by the selected provider.
Purpose and legal basis: to authenticate the User, create or retrieve the corresponding Firebase account, maintain the session and enable account management and deletion. Processing required to provide access and account functions is based on performance of the requested service under Article 6(1)(b) GDPR. Processing strictly necessary for authentication security and abuse prevention is based on the Owner's legitimate interest in protecting Plyveo and its Users under Article 6(1)(f) GDPR.
Account deletion, local reset and residual retention: account deletion performed through Plyveo initiates deletion of the associated user from Firebase Authentication. Google states that logged IP addresses are retained for a few weeks. Other authentication information is retained until deletion of the associated user is requested and is subsequently removed from live and backup systems within 180 days.
After deletion of the Firebase account has been confirmed, Plyveo deletes all account-related data from the device, including practice sessions, answers, drafts, transcripts, notes, scores, criterion ratings, readiness indicators, AI feedback, local onboarding and profile state, weekly goal, locally stored quota information, reminders, scheduled notifications, account preferences and temporary files managed by the app. Only the app-language and theme preferences are retained.
Plyveo also disables Analytics collection, resets the Analytics data associated with the installation and deletes the previously stored Analytics choice, the date of that choice and the version of the notice shown to the User. Deletion of the current Firebase Installation ID is also requested. Subsequent use of Firebase services may generate a new installation identifier that is not associated with the previous one and a new Crashlytics identifier.
Account deletion does not necessarily result in the immediate deletion of data already received by service providers. Previously transmitted Analytics data, which Plyveo does not associate with the Firebase UID, remains subject to the 2-month retention period described in the relevant section. Crashlytics reports remain subject to the 90-day retention period, while data associated with the deleted Firebase Installation ID may be removed from Firebase live and backup systems within 180 days.
The pseudonymous document used for quota management and abuse prevention may be retained separately in Firestore for up to 24 months after the last successfully completed evaluation, including after account deletion. This prevents account deletion and subsequent account creation from improperly resetting usage limits.
Copies included in operating-system backups remain subject to Google or Apple's settings and retention periods. Files exported, shared or copied by the User outside the storage controlled by Plyveo cannot be deleted by the app.
Merely signing out does not delete the Firebase account or local data. Deleting the Plyveo account does not delete the User's Google or Apple account. Where supported by the provider and platform, Plyveo may also request revocation or disconnection of the authorization used to access the app.
Provider, location and transfers: Firebase Authentication is provided by Google LLC or Google Ireland Limited according to the terms applicable to the Owner's account. The contracting entity must be distinguished from the technical processing location: Google states that Firebase Authentication is operated exclusively from data centers located in the United States.
International transfers, where applicable, are governed by the applicable Google and Firebase terms and transfer safeguards, including, where applicable, the Standard Contractual Clauses and the Data Privacy Framework.
This type of service analyzes the traffic of this Application, potentially containing Users' Personal Data, with the purpose of filtering it from unwanted parts of traffic, messages and content that are recognized as spam or protecting it from malicious bots activities.
Firebase App Check and app integrity verification
Plyveo uses Firebase App Check, a security service provided by Google, to verify that requests made to protected backend services originate from an authentic installation of the app and, to the extent supported by the relevant attestation provider, from an untampered device.
In production releases, verification uses Google Play Integrity on Android and Apple App Attest, with Apple DeviceCheck as a fallback, on iOS. Firebase App Check debug providers are used exclusively in development and debug builds and are not used in versions distributed to Users.
Plyveo requires a valid App Check token for both protected backend services, named “evaluateAnswer” and “getQuota”. Firebase App Check operates separately from Firebase Authentication: the App Check token attests to the authenticity of the app or device, while the authentication token separately identifies the account making the request.
Data processed: attestation material and signals required to verify the authenticity of the app or integrity of the device; Firebase App Check tokens obtained following successful verification; technical app and project identifiers; and other technical data required for the operation of the service and the relevant attestation provider.
Plyveo does not intentionally include answer or draft text, transcripts, notes, scores, AI-generated feedback, names, email addresses, profile images or other account content in the attestation material or token. The App Check token does not replace the Firebase Authentication token and is not used by Plyveo for advertising, profiling or assessing the User's suitability for employment.
Purpose and legal basis: verifying app integrity, preventing protected backend services from being accessed by unauthorized clients, combating bots, fraudulent requests and abuse, protecting usage quotas and preserving the security and availability of the evaluation service. Processing is based on the Owner's legitimate interest in securing the service and preventing abuse under Article 6(1)(f) GDPR.
Retention: Firebase App Check does not retain attestation material. When such material is transmitted to Google Play Integrity, Apple App Attest or Apple DeviceCheck, it is processed in accordance with the terms of the relevant provider. App Check tokens obtained following successful verification remain valid for their configured time to live, which cannot exceed 7 days, and may be temporarily cached on the device by the SDK until they expire or are refreshed.
Plyveo currently uses ordinary App Check tokens and does not configure the optional token-consumption or replay-protection feature. According to Firebase, App Check tokens that are not used with replay-protection features are not retained by Firebase services.
Account deletion: Firebase App Check protects the app installation and does not constitute an account-data repository. Account deletion separately terminates the Firebase Authentication session and causes the removal of local account data managed by Plyveo. An App Check token that has already been issued may remain technically valid until it expires, but it does not contain answers, sessions or other account content and does not permit access to services that also require a valid authenticated account.
Providers and transfers: Firebase App Check is provided by Google. Attestation is verified through Google Play Integrity on Android or Apple App Attest or Apple DeviceCheck on iOS. Any international transfers are governed by the applicable terms and safeguards of the respective providers, including, where applicable, Standard Contractual Clauses and the Data Privacy Framework.
Google Privacy Policy: https://policies.google.com/privacy
Apple Privacy Policy: https://www.apple.com/legal/privacy/
Usage quota management and abuse prevention
Company: this Application
Plyveo processes a minimal set of metadata to enforce AI-evaluation usage limits, display the remaining quota, and prevent free credits from being restored by deleting and subsequently recreating an account.
Data processed: a pseudonymous Firestore document key generated by applying the SHA-256 algorithm to the authentication provider name and the stable identifier supplied by that provider. If no suitable stable identifier is available, the Firebase UID is used as a fallback. Plyveo also stores the number of free credits used, the daily count of completed evaluations, the corresponding date, the identifiers of the 20 most recently counted sessions, the number of completed evaluations associated with each of those sessions, and the technical timestamp used for automatic deletion.
Data not stored: Firestore does not store answer text, drafts, notes, interview questions, rubrics, model answers, scores, strengths, improvement suggestions, or feedback generated by artificial intelligence.
Purpose and legal basis: to correctly enforce usage quotas, display the remaining quota, prevent abuse or fraudulent use, prevent the artificial resetting of free credits, and protect the availability and sustainability of the service. The processing is based on the Owner's legitimate interests under Article 6(1)(f) GDPR.
Retention: the document may be retained after account deletion so that deleting and subsequently recreating an account cannot reset the abuse-prevention limits. A new expiration date of 24 months is set after each successfully completed AI evaluation. If no new evaluation is successfully completed during that period, the document becomes eligible for automatic deletion through Firestore's TTL feature when the period expires. Deletion is not instantaneous and is normally performed within approximately 24 hours after expiration.
Further information about the processing of Personal Data
Device backup via iCloud
When the User enables iCloud Backup on their device, Apple may include Plyveo's local data in the backup, including sessions, answers, drafts, scores, feedback and preferences. Plyveo does not access iCloud credentials and does not directly control the timing and manner of backup retention or restoration, which are managed by the User and Apple.
Device dictation and speech recognition
When the User voluntarily activates the microphone, audio is processed by the speech-recognition service configured on the device. Processing may occur on the device or on the servers of the relevant provider, in particular Apple on iOS or the system-selected recognition service on Android. Plyveo receives the transcribed text and uses it as a draft or answer; it does not intentionally retain the original audio.
User-initiated export, import and sharing
Upon the User's request, Plyveo can generate a JSON export file or a scorecard image and hand it to the operating system's share menu. The JSON file does not contain the Firebase UID, but may contain answers, notes, scores and AI feedback. The User independently chooses the app or recipient; Plyveo does not control the subsequent processing carried out by the recipient. A temporary copy may remain on the device until cleaned up by the operating system.
Device backup via Android (Google)
On Android devices with system backup enabled, Google may include Plyveo's local data in the device backup, including sessions, answers, drafts, scores, feedback and preferences, through the Android Auto Backup feature. Plyveo does not use the Google Drive APIs and does not access the User's Google Drive account; the backup is managed by the operating system and the User's Google account.
Cookie Policy
This Application uses Trackers. To learn more, Users may consult the Cookie Policy.
Further Information for Users in the European Union
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
Users have given their consent for one or more specific purposes.
provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
processing is necessary for compliance with a legal obligation to which the Owner is subject;
processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Further information about retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The rights of Users based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner.
In particular, Users have the right to do the following, to the extent permitted by law:
Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner.
Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Users are also entitled to learn about the legal basis for Data transfers abroad including to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users’ request, the Owner will inform them about those recipients.
Further information for Users
in Switzerland
This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.
Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the personal data, if any, the retention period and further information about Personal Data can be found in the section titled “Detailed information on the processing of Personal Data” within this document.
The rights of Users according to the Swiss Federal Act on Data Protection
Users may exercise certain rights regarding their Data within the limits of law, including the following:
right of access to Personal Data;
right to object to the processing of their Personal Data (which also allows Users to demand that processing of Personal Data be restricted, Personal Data be deleted or destroyed, specific disclosures of Personal Data to third parties be prohibited);
right to receive their Personal Data and have it transferred to another controller (data portability);
right to ask for incorrect Personal Data to be corrected.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible, providing Users with the information required by law.
Further information for Users
in Brazil
This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the entity running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”). This section applies to all Users in Brazil (Users are referred to below, simply as “you”, “your”, “yours”), according to the "Lei Geral de Proteção de Dados" (the "LGPD"), and for such Users, it supersedes any other possibly divergent or conflicting information contained in the privacy policy. This part of the document uses the term “personal information“ as it is defined in the LGPD.
The grounds on which we process your personal information
We can process your personal information solely if we have a legal basis for such processing. Legal bases are as follows:
your consent to the relevant processing activities;
compliance with a legal or regulatory obligation that lies with us;
the carrying out of public policies provided in laws or regulations or based on contracts, agreements and similar legal instruments;
studies conducted by research entities, preferably carried out on anonymized personal information;
the carrying out of a contract and its preliminary procedures, in cases where you are a party to said contract;
the exercising of our rights in judicial, administrative or arbitration procedures;
protection or physical safety of yourself or a third party;
the protection of health – in procedures carried out by health entities or professionals;
our legitimate interests, provided that your fundamental rights and liberties do not prevail over such interests; and
credit protection.
To find out more about the legal bases, you can contact us at any time using the contact details provided in this document.
Categories of personal information processed
To find out what categories of your personal information are processed, you can read the section titled “Detailed information on the processing of Personal Data” within this document.
Why we process your personal information
To find out why we process your personal information, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.
Your Brazilian privacy rights, how to file a request and our response to your requests
Your Brazilian privacy rights
You have the right to:
obtain confirmation of the existence of processing activities on your personal information;
access to your personal information;
have incomplete, inaccurate or outdated personal information rectified;
obtain the anonymization, blocking or elimination of your unnecessary or excessive personal information, or of information that is not being processed in compliance with the LGPD;
obtain information on the possibility to provide or deny your consent and the consequences thereof;
obtain information about the third parties with whom we share your personal information;
obtain, upon your express request, the portability of your personal information (except for anonymized information) to another service or product provider, provided that our commercial and industrial secrets are safeguarded;
obtain the deletion of your personal information being processed if the processing was based upon your consent, unless one or more exceptions provided for in art. 16 of the LGPD apply;
revoke your consent at any time;
lodge a complaint related to your personal information with the ANPD (the National Data Protection Authority) or with consumer protection bodies;
oppose a processing activity in cases where the processing is not carried out in compliance with the provisions of the law;
request clear and adequate information regarding the criteria and procedures used for an automated decision; and
request the review of decisions made solely on the basis of the automated processing of your personal information, which affect your interests. These include decisions to define your personal, professional, consumer and credit profile, or aspects of your personality.
You will never be discriminated against, or otherwise suffer any sort of detriment, if you exercise your rights.
How to file your request
You can file your express request to exercise your rights free from any charge, at any time, by using the contact details provided in this document, or via your legal representative.
How and when we will respond to your request
We will strive to promptly respond to your requests. In any case, should it be impossible for us to do so, we’ll make sure to communicate to you the factual or legal reasons that prevent us from immediately, or otherwise ever, complying with your requests. In cases where we are not processing your personal information, we will indicate to you the physical or legal person to whom you should address your requests, if we are in the position to do so.
In the event that you file an access or personal information processing confirmation request, please make sure that you specify whether you’d like your personal information to be delivered in electronic or printed form. You will also need to let us know whether you want us to answer your request immediately, in which case we will answer in a simplified fashion, or if you need a complete disclosure instead. In the latter case, we’ll respond within 15 days from the time of your request, providing you with all the information on the origin of your personal information, confirmation on whether or not records exist, any criteria used for the processing and the purposes of the processing, while safeguarding our commercial and industrial secrets.
In the event that you file a rectification, deletion, anonymization or personal information blocking request, we will make sure to immediately communicate your request to other parties with whom we have shared your personal information in order to enable such third parties to also comply with your request — except in cases where such communication is proven impossible or involves disproportionate effort on our side.
Transfer of personal information outside of Brazil permitted by the law
We are allowed to transfer your personal information outside of the Brazilian territory in the following cases:
when the transfer is necessary for international legal cooperation between public intelligence, investigation and prosecution bodies, according to the legal means provided by the international law;
when the transfer is necessary to protect your life or physical security or those of a third party;
when the transfer is authorized by the ANPD;
when the transfer results from a commitment undertaken in an international cooperation agreement;
when the transfer is necessary for the execution of a public policy or legal attribution of public service;
when the transfer is necessary for compliance with a legal or regulatory obligation, the carrying out of a contract or preliminary procedures related to a contract, or the regular exercise of rights in judicial, administrative or arbitration procedures.
Further information for Users
in the United States
This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).
The information contained in this section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are residents in the following states: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana.
For such Users, this information supersedes any other possibly divergent or conflicting provisions contained in the privacy policy.
This part of the document uses the term Personal Information.
Notice at collection
The following Notice at collection provides you with timely notice about the categories of Personal Information collected or disclosed in the past 12 months so that you can exercise meaningful control over our use of that Information.
While such categorization of Personal Information is mainly based on California privacy laws, it can also be helpful for anyone who is not a California resident to get a general idea of what types of Personal Information are collected.
Identifiers
Personal Data processed: First name; Email address; Profile picture; Social media accounts + 8
Personal Information collected or disclosed:
first name
email address
profile picture
social media accounts
Universally unique identifier (UUID)
crash data
device information
Trackers
User ID
last name
Usage Data
various types of Data as specified in the privacy policy of the service
Purposes:
Registration and authentication
Infrastructure monitoring
Hosting and backend infrastructure
Retention period:
for the time necessary to fulfill the purpose
Sold or Shared:
No
Targeted Advertising:
No
Third-parties:
Google LLC, Google Ireland Limited, Apple Inc.
Audio, electronic, visual, thermal, olfactory, or similar information
Personal Data processed: First name; Email address; Profile picture; Social media accounts + 2
Personal Information collected or disclosed:
first name
email address
profile picture
social media accounts
User ID
last name
Purposes:
Registration and authentication
Retention period:
for the time necessary to fulfill the purpose
Sold or Shared:
No
Targeted Advertising:
No
Third-parties:
Google LLC, Apple Inc.
Internet or other electronic network activity information
Personal Data processed: Trackers; Usage data; Device information; Number of sessions + 6
Personal Information collected or disclosed:
Trackers
Usage Data
device information
number of sessions
session duration
operating systems
Universally unique identifier (UUID)
crash data
various types of Data as specified in the privacy policy of the service
Microphone permission, without recording
Purposes:
Analytics
Infrastructure monitoring
Registration and authentication
Hosting and backend infrastructure
Platform services and hosting
Device permissions for Personal Data access
Beta Testing
Retention period:
for the time necessary to fulfill the purpose
Sold or Shared:
No
Targeted Advertising:
No
Third-parties:
Google Ireland Limited, Apple Inc., this Application
We won’t process your Information for unexpected purposes, or for purposes that are not reasonably necessary to and compatible with the purposes originally disclosed, without your consent.
What are the sources of the Personal Information we collect?
We collect the above-mentioned categories of Personal Information, either directly or indirectly, from you when you use this Application.
For example, you directly provide your Personal Information when you submit requests via any forms on this Application. You also provide Personal Information indirectly when you navigate this Application, as Personal Information about you is automatically observed and collected.
Finally, we may collect your Personal Information from third parties that work with us in connection with the Service or with the functioning of this Application and features thereof.
Your privacy rights under US state laws
You may exercise certain rights regarding your Personal Information. In particular, to the extent permitted by applicable law, you have:
the right to access Personal Information: the right to know. You have the right to request that we confirm whether or not we are processing your Personal Information. You also have the right to access such Personal Information;
the right to correct inaccurate Personal Information. You have the right to request that we correct any inaccurate Personal Information we maintain about you;
the right to request the deletion of your Personal Information. You have the right to request that we delete any of your Personal Information;
the right to obtain a copy of your Personal Information. We will provide your Personal Information in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible;
the right to opt out from the Sale of your Personal Information; We will not discriminate against you for exercising your privacy rights.
the right to non-discrimination.
Additional rights for Users residing in California
In addition to the rights listed above common to all Users in the United States, as a User residing in California, you have:
The right to opt out of the Sharing of your Personal Information for cross-context behavioral advertising;
The right to request to limit our use or disclosure of your Sensitive Personal Information to only that which is necessary to perform the services or provide the goods, as is reasonably expected by an average consumer. Please note that certain exceptions outlined in the law may apply, such as, when the collection and processing of Sensitive Personal Information is necessary to verify or maintain the quality or safety of our service.
Additional rights for Users residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana
In addition to the rights listed above common to all Users in the United States, as a User residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana you have
The right to opt out of the processing of your personal information for Targeted Advertising or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
The right to freely give, deny or withdraw your consent for the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer. In Maryland, your Sensitive Personal Information will be collected or processed only if strictly necessary to provide or maintain a specific product or service requested by you.
In Minnesota and Maryland Users also have the right to obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data
* Note that in some states like Minnesota you have the following specific rights connected to profiling:
The right to question the results of the profiling;
The right to be informed of the reason that the profiling resulted in the decision; if feasible
The right to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future;
The right to review personal data used in the profiling;
If inaccurate, the right to have the data corrected and the profiling decision reevaluated based on the corrected data;
Additional rights for users residing in Utah and Iowa
In addition to the rights listed above common to all Users in the United States, as a User residing in Utah and Iowa, you have:
The right to opt out of the processing of your Personal Information for Targeted Advertising;
The right to opt out of the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer.
How to exercise your privacy rights under US state laws
To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.
For us to respond to your request, we must know who you are. We will not respond to any request if we are unable to verify your identity and therefore confirm the Personal Information in our possession relates to you. You are not required to create an account with us to submit your request. We will use any Personal Information collected from you in connection with the verification of your request solely for verification and shall not further disclose the Personal Information, retain it longer than necessary for purposes of verification, or use it for unrelated purposes.
If you are an adult, you can make a request on behalf of a child under your parental authority.
How to exercise your rights to opt out
In addition to what is stated above, to exercise your right to opt-out of Sale or Sharing and Targeted Advertising you can also use the privacy choices link provided on this Application.
If you want to submit requests to opt out of Sale or Sharing and Targeted Advertising activities via a user-enabled global privacy control, such as for example the Global Privacy Control (“GPC”), you are free to do so and we will abide by such request in a frictionless manner.
How and when we are expected to handle your request
We will respond to your request without undue delay, but in all cases within the timeframe required by applicable law. Should we need more time, we will explain to you the reasons why, and how much more time we need.
Should we deny your request, we will explain to you the reasons behind our denial (where envisaged by applicable law you may then contact the relevant authority to submit a complaint).
We do not charge a fee to process or respond to your request unless such request is manifestly unfounded or excessive and in all other cases where it is permitted by the applicable law. In such cases, we may charge a reasonable fee or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind them.
Additional information about Data collection and processing
Legal action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User's Personal Data
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data)
/ Personal Information (or Information)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Sensitive Personal Information
Sensitive Personal Information means any Personal Information that is not publicly available and reveals information considered sensitive according to the applicable privacy law.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) and on this site/application.
Sale
Sale means any exchange of Personal Information by the Owner to a third party, for monetary or other valuable consideration, as defined by the applicable privacy US state law. Please note that the exchange of Personal Information with a service provider pursuant to a written contract that meets the requirements set by the applicable law, does not constitute a Sale of your Personal Information.
Sharing
Sharing means any sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information by the business to a third party for cross-context behavioral advertising, whether for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged, as defined by the California privacy laws. Please note that the exchange of Personal Information with a service provider pursuant to a written contract that meets the requirements set by the California privacy laws, does not constitute sharing of your Personal Information.
Targeted advertising
Targeted advertising means displaying advertisements to a consumer where the advertisement is selected based on Personal Information obtained from that consumer’s activities over time and across nonaffiliated websites or online applications to predict such consumer’s preferences or interests, as defined by the applicable privacy US state law.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that enables the tracking of Users, for example by accessing or storing information on the User’s device.
Legal information
This policy has been prepared based on provisions of multiple legislations.
This policy relates solely to this Application, if not stated otherwise within this document.