Privacy Policy

1. Scope

This policy covers the Android version of Enigma AI and explains what data we collect, why, how long we keep it, and what rights you have.

2. Key Principles

PrincipleImplementation in Enigma AI
Data minimisationWe collect only what is strictly necessary: an e-mail address (if you choose to register) plus the prompts you send to obtain AI responses.
Local-first storageChat history remains on your device only.
Transparent processingPrompts are forwarded—after pseudonymisation—to external AI providers solely to generate answers.
Security by designTLS 1.2+ in transit, AES-256 for stored data, salted-hash for e-mail addresses at rest.
User controlDelete chats, export data, or delete your account at any time from in-app settings.

3. What Data the App Handles

Data categoryExamplesSource Stored on deviceStored on our server Sent to AI providersPurpose
E-mail address (optional) you@example.com Registration form ✔ (hashed, EU data-centre) Account creation; password-less sign-in & service continuity
User-provided text Prompts, messages You ✔ (pseudonymised) Generate AI responses
Technical metadata (minimal) Random request ID, model name, latency App Abuse-prevention & QoS

We do not collect or share: names, phone numbers, location, advertising ID, device ID, photos, contacts, analytics, crash logs, usage profiling, ads data.

4. Legal Basis & Purposes

Processing activityLegal basis (GDPR Art. 6)Why we need it
Account creation & login with e-mail (b) Contractual necessity To give you persistent access across devices and enable password-less “magic-link” log-ins.
AI inference on your prompts (b) Contractual necessity Without sending the prompt, the service cannot reply.
Abuse-prevention logs (max 30 days) (f) Legitimate interest Stop malicious use (spam, denial-of-service, etc.).

5. Data Sharing & International Transfers

RecipientData sharedSafeguard
External AI model providers (e.g., OpenAI, Anthropic) Pseudonymised prompt text & random request ID Standard Contractual Clauses (SCCs) + GDPR-compatible DPAs
No other third parties

We never sell or rent your information.

6. Retention & Deletion

DataWhere keptRetention ruleHow to delete
E-mail address (hashed) Secure EU server Until you delete your account Settings › Profile > Delete Account
Chat history Local device storage Until you clear chats or uninstall the App Settings › Clear Data or uninstall
Provider abuse-prevention logs Provider side ≤ 30 days Auto-deleted; you may also request early erasure via Contact Us

7. Your Rights (GDPR)

Exercise any right via Settings or the “Contact Us” form on our website.

8. Security Measures

9. Children’s Privacy

Enigma AI is intended for users aged 16 and older. We do not knowingly process data from children under 16.

10. Changes to This Policy

Material updates trigger an in-app notice and a new effective date.

11. Contact

Data Controller: Enigma Technology, Radom, Poland

Privacy inquiries & data-subject requests: Use the “Contact Us” form linked in the App settings.

12. Google Play Data-Safety Summary

Data typeCollectedSharedPurposeUser-controlled deletion
Personal info › E-mail address Yes (hashed on server) No Account creation & login Yes – Delete Account
User-generated content › Chat messages Yes (device only) Yes (pseudonymised to AI providers) Generate responses Yes – Clear Data / uninstall
App info & performance › Crash/diagnostics No
Device or other IDs / Ads No
Data encrypted in transit: Yes  |  User can request deletion: Yes (self-service + Contact Us)

By continuing to use Enigma AI, you agree to this Privacy Policy. If you disagree, please uninstall the App or refrain from creating an account.