DISASTERGEN

Legal

Privacy Policy

What we collect, why we are allowed to, who else touches it, and how long we keep it. §2 is the short version: no advertising, no analytics, no tracking scripts, and nothing sold.

Effective
15 August 2026
Version
1.0
Contents
  1. 01Who controls your data
  2. 02What we do not do
  3. 03What we collect, why, and on what basis
  4. 04What we never ask for
  5. 05What becomes public
  6. 06Who else processes your data
  7. 07Transfers outside the EEA
  8. 08Cookies
  9. 09How long we keep it
  10. 10Your rights
  11. 11How we protect it
  12. 12Age
  13. 13Changes to this policy

Who controls your data

The controller of your personal data within the meaning of the GDPR (Regulation (EU) 2016/679) is GT Solutions, the trading name of GT SOLUTIONS KONRAD SIERZPUTOWSKI.

Controller
GT SOLUTIONS KONRAD SIERZPUTOWSKI
Address
Budowlanych 1A, 62-081 Baranowo, Poland
NIP
7792155376

We have not appointed a Data Protection Officer; we are not required to. Data protection questions go to the contact form above and reach us directly.

The summaries marked In short throughout this page are a reading aid. Where one differs from the numbered text, the numbered text is what applies.

What we do not do

In shortNo advertising, no analytics, no tracking scripts, no selling data, no profiling that decides anything about you.

Stated up front, because it removes most of what people come to this page for:

  • The Service contains no analytics, advertising or tracking scripts. There is no Google Analytics, no advertising pixel, no session recorder.
  • We do not sell, rent or trade personal data, and we never have.
  • We do not use your data for advertising or send marketing email.
  • We take no decision about you that is based solely on automated processing and produces legal effects for you. The Input screen described in the Terms §7 assesses the words you typed, not you.

What we collect, why, and on what basis

Account data

Username, display name, email address, a hash of your password (never the password itself), your role, your Credit balance, and the dates the account was created and last changed.

Why: to give you an account and provide the Service. Basis: performance of a contract, art. 6(1)(b) GDPR.

Session data

A session token, its expiry, and the IP address and browser user-agent string recorded when the session was created.

Why: to keep you signed in, and to detect and limit abuse of the Service. Basis: contract for the sign-in itself, art. 6(1)(b); our legitimate interest in the security of the Service for the network identifiers, art. 6(1)(f).

What you generate

The words you place into template fields, the prompt assembled from them, the resulting video and poster image, its title, status and timestamps, and the record of Credits deducted and refunded. Where the Input screen refuses your text, the refused text is retained as a record of the refusal.

Why: to render and host what you asked for, to keep your Credit balance reconcilable, and to enforce the Terms. Basis: contract, art. 6(1)(b), and our legitimate interest in enforcing our rules and preventing misuse, art. 6(1)(f).

Messages you send us

The name, email address, subject and message you submit through the contact form, together with the IP address and user-agent recorded with it, and your account id if you were signed in.

Why: to answer you, and to keep the form usable by blocking abuse. Basis: our legitimate interest in handling correspondence and keeping the form working, art. 6(1)(f); performance of a contract where your message concerns one, art. 6(1)(b).

Server logs

Our web server and our network provider record requests, including IP address, time, path and user-agent, in the ordinary course of serving the site.

Why: operating, securing and debugging the Service. Basis: legitimate interest, art. 6(1)(f).

What we never ask for

We do not ask for your real name, postal address, date of birth, phone number or any payment details, and the Service has no field in which to give them. Do not put such information into template fields or into a message to us: template Input is used to generate publicly visible videos, and anything you type there may end up on a public page.

What becomes public

In shortYour username and everything you publish are public and indexed by search engines. Your email address never is.

When you publish a video, the video, its poster image, its title and description, its category, its vote count and your username become publicly visible and are offered to search engines for indexing.

Your email address, your IP address, your user-agent and your Credit history are never published.

Choose a username accordingly — see Terms §5.3.

Who else processes your data

We keep the list short on purpose. Data reaches the following categories of recipient, and no others:

  • Our video rendering provider. It receives the assembled prompt and the technical render parameters. It does not receive your account id, username, email address, IP address or session. It cannot connect a prompt to you from what we send it.
  • Our network and infrastructure providers — the company whose servers run the Service, and the content delivery network that sits in front of it. Both necessarily process the IP addresses of visitors in order to route traffic, and the delivery network filters malicious traffic on our behalf.
  • Public authorities, where we are legally obliged to disclose.

We do not use processors for analytics, marketing, customer support or email, because the Service does none of those things.

Transfers outside the EEA

Some of the providers described in §6 operate infrastructure outside the European Economic Area, or are established outside it. Where personal data is transferred outside the EEA, the transfer takes place on the basis of an adequacy decision of the European Commission where one covers the recipient, or otherwise under the Commission's standard contractual clauses, together with the additional measures appropriate to the transfer. You may ask us for details of the safeguards applying to a specific transfer using the contact form.

Cookies

In shortOne cookie, and only once you sign in. It keeps you signed in. That is the entire list.

The Service sets a single cookie: the session cookie that keeps you signed in after you log in. It is set only when you sign in, it is removed when you sign out, and it expires on its own.

It is strictly necessary to provide a service you have explicitly requested, so under art. 173(3) of the Polish Telecommunications Law it does not require your consent — which is why this site shows you no cookie banner. We would need one if we added analytics or advertising, and we would ask before doing so.

Browsing the Service without signing in sets no cookie at all.

How long we keep it

  • Account data — while your account exists, and deleted when you close it, save for anything we must keep by law.
  • Sessions — until they expire or you sign out.
  • Published videos and their Input — until you delete them or the account is closed. Copies persist in backups until those backups age out, which is currently 14 days.
  • Records of refused Input and abuse evidence — for as long as needed to enforce the Terms and to defend a claim, and no longer.
  • Contact messages — for as long as needed to deal with the matter and to show how we dealt with it, then deleted.
  • Server logs — for the short period our infrastructure retains them for security and diagnostics.

Your rights

In shortAccess, correct, delete, restrict, port, object — and complain to the regulator if we get it wrong.

Under the GDPR you may ask us to:

  • confirm what personal data we hold about you, and give you a copy (art. 15);
  • correct data that is wrong or incomplete (art. 16);
  • delete your data (art. 17);
  • restrict how we use it while a dispute about it is resolved (art. 18);
  • send you, or another controller, the data you gave us in a portable format (art. 20);
  • object to processing we base on legitimate interest, on grounds relating to your situation (art. 21).

Use the contact form. We answer within one month and will tell you if we need longer. We may need to check that the request comes from you before acting on it.

You can delete your account and your published videos yourself at any time from the Service, without asking us.

If you think we have handled your data unlawfully you may complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, or to the supervisory authority of your EU country of residence. We would rather you told us first, but you do not have to.

How we protect it

Traffic is encrypted in transit. Passwords are stored only as hashes and cannot be read back by us. Database and administrative interfaces are not exposed to the public internet. Administrative access is restricted to accounts that need it and administrative actions are logged. Backups are taken daily and retained for 14 days.

No service is immune. If a breach occurs that is likely to result in a high risk to your rights, we will tell you as well as the supervisory authority, as art. 33 and 34 GDPR require.

Age

The Service is not for anyone under 16 — see Terms §4. We do not knowingly collect data from anyone younger. If you believe a child under 16 has given us personal data, tell us and we will delete it.

Changes to this policy

We may update this policy. The version and effective date at the top of the page identify the current text. Where a change materially affects how we handle your data, we will give notice in the interface, or by email where we hold your address, before it takes effect.