This Policy explains what data the Qelmar service (the “Service”) processes, why, and how you can control it. By using the Service and creating an account, you agree to this Policy.
The data controller is Igor Pylypenko, Ukraine.
For data enquiries and to exercise your rights, write to [email protected]. The “Report a bug” form inside the app does the same job, but email also works when you cannot sign in.
The legal basis is your consent (given at registration) and the necessity to perform the user agreement.
Some features process the text you enter via third-party AI providers to return a result (analysis, recommendations, help). Only the text needed for a given request is sent. We do not intentionally provide your data for model training; providers’ policies may differ (see below).
The Service does not ask for symptoms, diagnoses, medical history or any other health data and has no fields for them. The Energy section holds only what you tick off yourself: intake, daily rhythm, your own rating of your energy, and free-form notes about the day.
Those records are not analysed for your condition: there are no AI health reviews in the Service, we give no intake recommendations and draw no conclusions about how you feel. Free-form notes are your own text; we do not process them as medical information.
Energy level and mood are values you set yourself. The Service does not infer your state from your voice, face or any other biometric data.
If you do write something about your health into a free-form field, it stays a record in your account, visible only to you, and is not used to draw any conclusions about you.
We do not sell your data. The Service relies on third-party processors:
Data may be processed on servers outside your country, including outside the EEA. Such transfers rely on a European Commission adequacy decision or on Standard Contractual Clauses (SCCs) in our agreements with the relevant processors.
Dashboard content is retained while your account exists. After you delete the account, records are deleted within 30 days, except anything we are legally required to keep.
The session log (IP, device, sign-in time) is kept for up to 12 months so that you can spot someone else signing in to your account. AI usage statistics are kept for up to 24 months for quota accounting.
Local browser storage holds the session token, your language choice and a flag that you are signed in. All of it is strictly necessary for the Service and therefore needs no consent. We run no advertising or analytics trackers, no third-party cookies and no pixels.
Passwords are stored hashed and access to privileged data is restricted. No method of transmission over the internet is fully secure; we apply reasonable safeguards.
We answer any such request within 30 days.
The Service is not intended for anyone under 16.
We may update this Policy. The current version is always available at this address; the update date is shown at the top.