Developer and publisher: Filip Majchrzak.
Updated 4 October 2026. Controller: Filip Majchrzak, operating as STUDIO MASAŻU FILIP MAJCHRZAK, ul. Czarnieckiego 9, 73-200 Choszczno, Poland, Polish tax identifier (NIP) 5941544462. Contact: fmajchrzak.ai@gmail.com. This notice covers research, account and subscription administration, support and optional website features.
Research requests and accounts
Research tools receive company search text, sectors, tickers, fiscal periods and pagination parameters, with request and protocol metadata. We process these inputs to return the public SEC facts in our hosted snapshot. The application does not save individual research queries, their contents or a research history in its database. Search text may contain personal information if you enter it; use company names and tickers.
The managed ChatGPT connection and website sign-in can supply a platform account identifier and email address. We use the identifier to authenticate you and, when subscriptions are enabled, check paid access and associate a subscription with your account. Public preview requests can operate without identity while billing is disabled. These connections do not grant access to your email inbox, files, brokerage account, portfolio or full chat history. Results are not personalized investment recommendations.
Subscriptions and payments
When you start checkout, we store your account identifier, associated Stripe customer identifier, checkout and subscription references, invoice reference, payment or subscription status, paid-access expiry and reconciliation timestamps. We also keep the subscription terms you accepted, their version, price, currency and time of acceptance. Withdrawal, refund, cancellation and complaint requests include your identifying information, request text, receipt time and processing status. Online withdrawal confirmations are retained with the request and are downloadable only by its authenticated owner.
Stripe collects payment details on its hosted checkout and portal, including information needed for billing, invoices, tax and fraud checks. We can access relevant customer, payment, subscription and invoice information in Stripe to administer purchases, verify payment, investigate problems and process refunds. Our research application does not store full card numbers or security codes. Payment verification can automatically enable or restrict access; contact support for a human review of an incorrect decision. There is no automated investment decision-making.
Billing safeguards process account-linked action counts and time windows to limit abuse, plus provider event identifiers, types and processing timestamps for reconciliation.
Purposes and legal bases
- Requested research, accounts, subscriptions and support: contract performance or steps you request before a contract (GDPR Article 6(1)(b)). Required account and payment information is necessary to administer paid access.
- Invoices, tax records and legally required consent evidence: applicable legal obligations (Article 6(1)(c)).
- Security, moderation, fraud prevention and legal claims: our legitimate interests in protecting the service and resolving disputes (Article 6(1)(f)), balanced against your rights.
- Optional website measurement: your withdrawable consent (Article 6(1)(a)). Registering, connecting or purchasing does not subscribe you to marketing.
Providers and disclosures
OpenAI provides ChatGPT, the managed connection, sign-in and hosting platform. Hosting uses Cloudflare infrastructure and a D1 database for application records. Stripe provides checkout, subscriptions, invoices, payment verification and refunds; it acts as a processor or an independent controller depending on the processing, including its own fraud prevention and legal obligations. Gmail receives support correspondence. The operator accesses records needed for support, billing and moderation; relevant records may be provided to accounting advisers or authorities where necessary for an obligation or claim.
Providers may keep network addresses, access times, device and authentication information in separate technical records. Their logs, ChatGPT conversations and Stripe-held payment records are separate from our database. Opening an SEC link visits the SEC directly; the application does not forward research questions to the SEC. We do not sell personal information or disclose research inputs to advertising services.
Providers may process data outside Poland or the European Economic Area, including in the United States. Their terms describe applicable transfer arrangements, which can include an adequacy decision, the EU–US Data Privacy Framework for a certified recipient or European Commission standard contractual clauses. See OpenAI privacy information, OpenAI’s business data-processing addendum, Cloudflare privacy information, Stripe privacy information and Stripe’s data-transfer addendum. A business addendum applies only to services governed by the relevant agreement. Contact us for information about safeguards applicable to your records and how to obtain a copy.
Retention
- Research query contents: processed during a request, not stored as a research history by the application.
- Account and subscription administration: kept while active, then for the consent, payment and legal-record periods below. Cancelling does not erase required transaction evidence.
- Consent evidence and associated contract or cancellation records: at least three years from acceptance or one year after the contract ends, whichever is later. Additional retention is limited to a legal obligation or unresolved claim.
- Tax, payment and invoice documentation: the statutory period, normally five years from the end of the calendar year in which the relevant Polish tax payment was due. A legal suspension or interruption can extend it. This does not govern unrelated research queries.
- Billing action counters: records older than 24 hours are removed on the next relevant billing action. Event reconciliation references follow the billing-record period.
- General support: up to 24 months after resolution. Subscription, refund, complaint or dispute correspondence follows the relevant contract or legal-record period. Deletion and periodic review are manual; there is no general automatic deletion schedule for billing records or the support mailbox.
Optional forum and measurement
The forum stores profile and post records for accounts, authorship and moderation. Members see your public display name and posts, not email or platform identifiers in member API responses. Records remain until removal or an account-deletion request; no automatic expiry is configured. Account deletion clears stored email, display name and topic/reply content and deletes reports you submitted from the live database. Structural placeholders, other members’ replies and reports about entries may remain. It does not erase subscription, consent or legally required payment records, nor separate provider backups.
Consented measurement stores aggregate UTC-day, event type, ticker, period, coarse acquisition category and counts, without visitor identifiers or email links. Records older than 90 days are removed when the next consented event is processed. Choose “No thanks” or change “Usage privacy settings” to stop future events. Aggregates cannot be matched to you for individual deletion. See community rules and privacy.
Your choices and rights
Contact fmajchrzak.ai@gmail.com for access, correction, deletion, restriction or portability, or to object to legitimate-interest processing. Withdraw measurement consent without affecting earlier lawful processing. We may need proportionate information to identify records; do not send identity documents in your first message. Rights and response periods depend on the basis and applicable law. You can complain to the President of UODO or your competent supervisory authority.
Disconnecting or uninstalling stops future app calls but does not cancel billing, delete a forum profile or erase required evidence. Use Manage billing to cancel. Requests about ChatGPT conversations or data held by a provider under its own authority should also follow its procedures. We will not deny available service rights because you submit a privacy request.