Privacy Policy of the Boski Application
Effective date: 12 August 2026
§1 General information
- The Boski application (hereinafter: "Application") is operated by Whitestone Labs, Inc., a company incorporated under the laws of the State of Delaware, United States, 1111B S Governors Ave Suite 90298, Dover, DE 19904, United States, e-mail: contact@whitestonelabs.org (hereinafter: "Controller"). The Controller's representative in the European Union within the meaning of Article 27 GDPR is Whitestone Labs sp. z o.o. with its registered office in Warsaw, Poland, address: Świeradowska 47, 02-662 Warsaw, Poland, e-mail: contact@boski.com.
- The Application may be used through various channels, in particular as a web application, as mobile applications and through third-party messaging platforms (such as WhatsApp or, once made available, iMessage). This Privacy Policy applies regardless of the channel through which the User uses the Application.
- In connection with the operation of the Application, data of Application users (hereinafter: "Users"), including personal data, may be collected, processed and used.
- Users' data may be collected as a result of Users voluntarily providing it (e.g. when creating an account, including when signing in through Google or Apple, where Users provide, among other things: name, e-mail address and authentication data, and when using the Application, where Users provide goals, tasks, notes, instructions and other content) or automatically in connection with the use of the Application.
- The following may also be collected: information about the User's IP address, approximate location derived from the IP address, device and browser type, the time of requests, error logs and performance diagnostics. This information is used for the purposes of administering the Application, ensuring its security and creating statistics and analyses.
- If the User chooses to connect a supported third-party service (such as Google Calendar), the Application may, after the User grants permission through the consent screen of that service, collect and process the data necessary to provide the features requested by the User (in the case of Google Calendar: calendar event data). The User may disconnect the service and revoke the permission at any time, in particular through the account settings of that service.
- Where the User uses the Application through a third-party messaging platform, messages exchanged with the Application are transmitted through the infrastructure of the provider of that platform (in the case of WhatsApp - Meta Platforms; in the case of iMessage - Apple), which processes them as an independent controller, in accordance with its own terms and privacy policy. Similarly, where the User signs in through Google or Apple or makes payments through a payment provider or an app store, those entities process the related data as independent controllers, to the extent described in their own privacy policies.
- The Controller's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, the Controller uses Google user data only to provide or improve user-facing features of the Application, does not sell it, does not use it for advertising purposes, does not use it to train generalised artificial intelligence or machine learning models, and does not allow humans to read it, except with the User's permission, for security or abuse prevention purposes, where required by law, or in aggregated or de-identified form.
§2 Personal data
- The controller of Users' personal data is Whitestone Labs, Inc., 1111B S Governors Ave Suite 90298, Dover, DE 19904, United States, e-mail: contact@whitestonelabs.org.
- Through the Application, the Controller may collect and then process personal data for purposes such as:
- creating and maintaining the User's account and providing the features of the Application, including features using artificial intelligence and connected third-party services, i.e. the conclusion and performance of the agreement for the use of the Application;
- handling and settling payments for paid features of the Application;
- responding to Users' enquiries or correspondence, including handling complaints;
- sending commercial communications, including newsletters, product updates and offers; creating an Account is equivalent to giving marketing consent, which remains effective until withdrawn by the User;
- meeting the legal obligations incumbent on the Controller, in particular tax and accounting obligations;
- establishing, pursuing or defending claims;
- ensuring the security of the Application and preventing fraud and abuse;
- statistics and analysis of Users' behaviour in the Application.
- The Controller processes personal data on the following bases:
- for data processed in order to create and maintain the account, provide the features of the Application and handle payments - processing necessary to perform the agreement (Article 6(1)(b) GDPR), and in the case of data processed in connection with a connected third-party service - the User's consent (Article 6(1)(a) GDPR), which may be withdrawn at any time, in particular by disconnecting the service, without affecting the lawfulness of processing carried out before its withdrawal;
- for data processed in order to send commercial communications (including newsletters, product updates and offers) - on the basis of the User's consent (Article 6(1)(a) GDPR); by signing up and creating an Account, the User consents to receive such communications until that consent is withdrawn, including through an unsubscribe link or by contacting the Controller;
- for data processed in order to meet legal obligations, in particular tax and accounting ones - on the basis of Article 6(1)(c) GDPR;
- for data processed in order to respond to enquiries or correspondence and to handle complaints - on the basis of the Controller's legitimate interest, namely communicating with the User and handling complaints (Article 6(1)(f) GDPR);
- for data processed in order to establish, pursue or defend claims - on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR);
- for data processed in order to ensure security and prevent fraud and abuse - on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR);
- for data processed in order to keep statistics and analyses - on the basis of the Controller's legitimate interest, namely verifying how Users use the Application (Article 6(1)(f) GDPR), and where consent is required by applicable law - only after obtaining that consent.
- The features of the Application may use artificial intelligence systems, including models supplied by third-party providers acting on behalf of the Controller, solely in order to provide the features requested by the User. The Controller informs that outputs presented within such features are generated by an artificial intelligence system.
- The Controller may disclose Users' data to its subcontractors (entities whose services it uses in processing), such as: hosting and infrastructure providers, database providers, providers of the AI models used in the Application, e-mail delivery providers, analytics providers, the operators of app stores and payment providers, an accounting office, as well as other providers of IT services and solutions.
- The Controller is operated from the United States and may use IT service providers based outside the European Economic Area. As a result, the User's data may be transferred outside the EEA. The Controller uses only services supplied by entities based in countries which the European Commission has found to provide an adequate level of protection, by entities processing personal data on the basis of Standard Contractual Clauses adopted by the European Commission, as referred to in Article 46 GDPR and concluded between the Controller and that entity, or by entities processing data under the EU-U.S. Data Privacy Framework.
- In relation to data covered by the UK GDPR, the preceding point applies accordingly, with transfers taking place on the basis of the transfer mechanisms provided for under the UK GDPR, in particular the UK Addendum to the Standard Contractual Clauses or the UK International Data Transfer Agreement.
- The retention periods for personal data are as follows, for data processed in order to:
- create and maintain the account and provide the features of the Application, including payment handling - the data is kept for the duration of the agreement (maintenance of the account) and for the period necessary to pursue the Controller's own claims or to defend against claims, and for the period required by applicable tax and accounting law;
- provide features based on a connected third-party service (including Google Calendar) - the data is kept only as long as the service is connected and needed to provide the features; after disconnection, it is deleted within 30 days, except where retention is required for backup integrity, security or legal compliance;
- respond to the User's enquiries or correspondence - the data is processed for a period of 3 years from the date the enquiry or correspondence was sent;
- send commercial communications (including newsletters, product updates and offers) - the data is processed until the consent is withdrawn;
- keep statistics and analyses of Users' behaviour in the Application - the data is processed for a maximum of one year from the date it was collected;
- meet the legal obligations incumbent on the Controller - the data is processed for the period required by the applicable provisions, in particular of tax and accounting law;
- ensure the security of the Application and prevent fraud and abuse - the data (including logs) is processed for a period not exceeding 12 months from the date it was collected, unless a longer period is necessary to investigate an incident or abuse;
- establish, pursue or defend claims - the data is processed until the expiry of the limitation periods for the relevant claims under applicable law.
- The User to whom the data relates has the following rights:
- the right to access personal data and to receive a copy of it - the User may ask the Controller whether their data is being processed and, if confirmed, request access to it and a copy of the processed personal data;
- the right to request rectification of personal data - the User may request the rectification of incorrect personal data or the completion of incomplete personal data, taking into account the purposes of processing;
- the right to request erasure of personal data;
- the right to request restriction of processing of personal data;
- the right to data portability;
- the right to object to the processing of personal data;
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
- the right to lodge a complaint with the competent supervisory authority, which in Poland is the President of the Personal Data Protection Office and in the United Kingdom - the Information Commissioner's Office (ICO).
- To exercise the above rights, the User should contact the Controller or the Controller's representative referred to in §1 point 1. The Controller responds without undue delay, at the latest within one month of receipt of the request.
- Providing personal data is voluntary; however, without it, it will not be possible to create the account, use the Application or contact the Controller.
- The Controller does not take decisions in relation to Users based solely on automated processing, including profiling, which produce legal effects concerning the User or similarly significantly affect the User; the User retains control over reviewing and approving actions performed with the use of the Application.
- The Application is intended for persons who are at least 16 years old. The Controller does not knowingly collect personal data from persons under 16 years of age. If the Controller becomes aware that it has collected personal data from a person under 16 years of age, it will take appropriate steps to delete the relevant personal data and the related account without undue delay.
- The Controller applies technical and organisational measures appropriate to the risk. In the event of a personal data breach, the Controller will notify the competent supervisory authority and, where required, the affected Users, in accordance with Articles 33 and 34 GDPR.
§3 California and other U.S. state privacy rights
- This section applies to California residents to the extent that the Controller qualifies as a "business" within the meaning of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (hereinafter: "CCPA"). The categories of personal information collected, the purposes of processing and the retention periods are described in §1 and §2.
- California residents have the right to: know and access the personal information collected, request its deletion, request the correction of inaccurate personal information, opt out of the sale or sharing of personal information, limit the use of sensitive personal information, and not be discriminated against for exercising these rights. A request may also be submitted by an authorised agent.
- The Controller does not sell personal information and does not share personal information for cross-context behavioural advertising within the meaning of the CCPA, and does not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
- Requests may be submitted by e-mail to contact@whitestonelabs.org. The Controller responds within 45 days; this period may be extended by a further 45 days, of which the requesting person will be informed.
- Residents of other U.S. states whose comprehensive privacy laws apply to the Controller have, to the extent provided for by those laws, analogous rights, in particular the rights to access, correct and delete personal data and to obtain a copy of it, the right to opt out of the sale of personal data, of its processing for targeted advertising and of profiling producing legal or similarly significant effects, and the right not to be discriminated against for exercising these rights. The Controller does not sell Users' personal data and does not process it for targeted advertising purposes. Requests may be submitted in the manner described in point 4; if a request is refused, the requesting person may appeal against the refusal by replying to the Controller's response.
§4 Final provisions
- The Controller may update this Privacy Policy, in particular in connection with the introduction of new features or channels of the Application. Users will be notified of material changes (by e-mail, within the Application or through the messaging channel used by the User) before they take effect. If the manner of use of data received from Google APIs changes materially, the Controller will additionally obtain any consent required by Google API policies or applicable law.
- Questions regarding this Privacy Policy may be directed to contact@whitestonelabs.org.