Privacy Policy
and Cookies
At Rescrito and Aithor, services operated by Chatbot App Limited and available through rescrito.com, aithor.ai, aithor.io, their web applications, mobile applications for iOS and Android, and other associated services, we value your privacy and are committed to processing your personal data responsibly, transparently, and securely.
This Privacy Policy explains what information we collect, how and why we use it, with whom we may share it, where and for how long it is retained, and the measures we apply to protect it.
It also describes how we process data relating to your conversations, documents, files, preferences, subscriptions, use of the Platforms and, where available and enabled, conversational memory and personalisation features.
This Policy also explains the rights you may exercise in relation to your personal data and the channels available to manage your preferences or contact us.
- Identification of the Data Controller
In accordance with the applicable laws and regulations governing personal data protection and digital services, including, where applicable, Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), Law 34/2002 on Information Society Services and Electronic Commerce (“LSSI-CE”), and any other applicable legislation, you are hereby informed that the controller of your personal data is:
Data Controller: Chatbot App Limited
Business Registration Number (BRN): 79362831
Registered Office: Hong Kong
Privacy contact email: [email protected]
Platforms and services covered:
rescrito.com
aithor.ai
aithor.io
The Rescrito and Aithor web applications.
The mobile applications for iOS and Android.
Any extensions, integrations, interfaces, and associated services made available from time to time.
Chatbot App Limited is a company incorporated in Hong Kong and does not currently have an establishment in the European Union.
Chatbot App Limited determines the purposes and essential means of processing the personal data managed through Rescrito and Aithor and therefore acts as the data controller in relation to the processing activities described in this Privacy Policy.
This responsibility includes, among other things, processing related to:
The creation, authentication, and administration of accounts.
The provision of artificial intelligence-based features.
The processing of prompts, conversations, documents, files, and other content provided by Users.
The personalisation of the experience and, where available and enabled, conversational memory.
The synchronisation of data across devices.
The management of subscriptions, credits, payments, and billing.
The operation of the mobile applications.
User support.
The security, fraud prevention, diagnostics, and improvement of the Platforms.
Operational and marketing communications carried out on the basis of the applicable legal ground.
Users may direct any enquiry, request, or complaint relating to the processing of their personal data directly to Chatbot App Limited at [email protected], without prejudice to their right to contact the competent data protection authority.
- Data We Collect
The personal data we collect and process depends on how the User accesses Rescrito or Aithor, the features they use, their account settings, and whether they use the websites, web applications, or mobile applications for iOS and Android.
Not all categories described in this section are collected in relation to every User.
2.1. Data Provided Directly by the User
We may collect the following data when the User creates an account, purchases a service, uses the Platforms, or contacts us:
Name, username, alias, or pseudonym.
Email address.
A securely stored password or the credentials required to authenticate the account.
Information included in the profile and preferences configured by the User.
Tax and billing information where necessary to issue an invoice.
Information provided when contacting support, submitting a complaint, requesting a refund, or exercising data protection rights.
Responses voluntarily provided through surveys, feedback forms, or communications with Chatbot App Limited.
Any other information the User chooses to provide through forms or features of the Platforms.
When the User registers or signs in through Apple, Google, or another external authentication provider, we may receive certain data from that provider, such as:
Name or alias.
The User’s actual email address or a private email address generated by the provider.
An identifier associated with the external account.
Information required to verify authentication.
The specific data received will depend on the provider, the settings selected by the User, and the permissions granted.
Payment and Contracting Information
When the User purchases a subscription, starts a paid trial, or acquires credits, we may process information such as:
The plan or product purchased.
The price, currency, and applicable taxes.
The date and status of the transaction.
The billing period and renewal date.
The history of purchases, cancellations, and refunds.
The order, receipt, or transaction identifier.
The subscription status.
Limited information about the payment method, such as its type, brand, and last digits, where provided by the relevant provider.
Complete card, bank account, or other payment method details are entered and managed directly by external providers such as Stripe, Apple App Store, Google Play, or other enabled providers.
As a general rule, Chatbot App Limited does not receive or store full card numbers or security codes. The specific data to which it has access will depend on the channel through which the purchase was made.
2.2. Content and Data Generated During Use of the Service
When the User uses Rescrito or Aithor, we may process:
Prompts, instructions, queries, and questions.
Messages and conversations with artificial intelligence systems.
Texts entered, written, or edited within the Platforms.
Uploaded documents and files, such as PDF files, text documents, spreadsheets, presentations, images, photographs, audio files, videos, or other compatible formats.
Links, web addresses, and content selected for analysis.
Results, responses, and content generated by artificial intelligence systems.
Corrections, ratings, comments, and assessments provided by the User in relation to the Results.
Conversations, documents, folders, projects, templates, favourites, and other items created or stored in the account.
Information about the tools used and the operations carried out on content, such as saving, copying, editing, exporting, sharing, or deleting.
Activity history and use of the features.
Preferences and settings, such as language, format, tone, writing style, preferred models, and personalisation options.
Information required to synchronise conversations, projects, settings, and files across devices associated with the same account.
User Content may include personal data relating to the User or to third parties. The User should avoid entering personal information that is not necessary and must have a sufficient legal basis, authorisation, or right when providing data relating to other people.
2.3. Conversational Memory and Personalisation Data
When conversational memory features are available and enabled, we may identify, generate, and retain information intended to maintain continuity between conversations and personalise future responses.
This information may include:
Language and communication preferences.
Preferred tone, style, structure, or writing format.
Academic, personal, or professional objectives.
Subjects, projects, research, or areas of interest.
Recurring instructions and preferences.
Tools and features regularly used.
Relevant context shared in previous conversations.
Information that the User expressly asks to be remembered.
The date, source, or conversation from which the information was obtained.
Corrections or deletions made by the User.
Technical representations, semantic indexes, or identifiers used to store, locate, and retrieve relevant information.
Certain memory items may be:
Entered expressly by the User.
Automatically identified from a conversation.
Generated through automated processes that summarise or structure contextual information.
Memory may contain incorrect interpretations, incomplete data, or outdated information. The User may have access to mechanisms for reviewing, correcting, deleting, or disabling stored information, in accordance with the options available on the Platforms.
Conversations and memory items may be stored and managed separately. Therefore, deleting a conversation will not necessarily result in the automatic deletion of information previously added to memory.
When memory is disabled, it will not be used to personalise future conversations. The relevant settings will explain whether previously stored items are retained until the User deletes them or are deleted automatically.
2.4. Data Collected Through Mobile Applications
When the User uses the Rescrito or Aithor applications for iOS or Android, we may process, depending on the settings and features used:
The device model, manufacturer, and category.
The operating system and installed version.
The application version and configuration.
Language, country, and regional settings.
IP address and internet service provider.
Technical installation, session, account, or device identifiers.
Information about session and authentication status.
Compatibility and connectivity data.
Records relating to application launch, closure, and updates.
Data about the features used within the application.
The history and status of mobile purchases or subscriptions.
Receipts and identifiers provided by Apple App Store or Google Play.
Information required to restore purchases.
The technical token used to send push notifications.
Notification preferences.
Data relating to errors, crashes, performance, loading times, and synchronisation failures.
Information about permissions granted to or denied for the application.
Certain features may require access to:
Files and documents.
Photographs and videos.
The camera.
The microphone.
Device notifications.
Access will be requested when necessary to use the relevant feature. The User may grant, deny, or withdraw permissions through their device settings.
Chatbot App Limited will process only the files, images, audio, or other content that the User selects, records, or uploads through the enabled features. Granting a permission does not necessarily mean that all content available on the device will be collected.
The application may also store locally certain information required for its operation, such as:
Authentication tokens.
Preferences and settings.
Temporary data or cache.
Drafts awaiting synchronisation.
Information required to maintain the session.
Uninstalling the application may delete locally stored data, but it does not automatically delete data retained in the account or cancel subscriptions managed by Apple, Google, or other external providers.
2.5. Technical, Security, Usage, and Analytics Data
When the User accesses or uses the Platforms, we may automatically collect:
IP address.
Approximate geographical location derived from the IP address, such as approximate country, region, or city.
Browser type and version.
Operating system.
General device type and characteristics.
Language, time zone, and screen resolution.
The date, time, duration, and frequency of sessions.
Pages, screens, and sections visited.
Buttons, links, and features used.
Queries submitted and the general navigation sequence.
The source or campaign through which the User accessed the Platforms.
Loading and response times.
Errors, crashes, and technical incidents.
System and server logs.
Sign-in attempts and authentication events.
Usage of credits, queries, documents, tokens, or other limits.
Technical installation, session, or device identifiers.
Information related to fraud detection, automated activity, abusive use, or circumvention of restrictions.
Data collected through cookies, local storage, SDKs, and similar technologies.
This information may be used to provide the service, maintain security, prevent fraud, diagnose problems, understand how the Platforms operate, and improve their performance and user experience.
Non-essential analytics, measurement, or personalisation tools will be used in accordance with the User’s preferences and, where applicable, after obtaining their consent.
Information about cookies, SDKs, local storage, and similar technologies is available in the relevant section of this Policy and in the Cookies and Similar Technologies Policy.
2.6. Data Obtained from Third Parties
We may receive personal data from third parties when the User uses external services related to Rescrito or Aithor, including:
Authentication providers: name, email address, account identifier, and authentication confirmation.
Payment providers: transaction information, payment status, limited payment method information, incidents, and fraud-prevention signals.
Apple App Store and Google Play: the product purchased, receipt, subscription status, renewal date, cancellation, refund, and identifiers required to verify or restore purchases.
Communications providers: information about message delivery, opening, or rejection, where legally applicable.
Analytics and attribution providers: technical information about access to, installation of, or interaction with the Platforms, in accordance with the applicable privacy preferences.
Security and fraud-prevention providers: technical signals intended to detect unauthorised access, suspicious transactions, bots, or abusive use.
Services integrated by the User: information required to provide an integration or import requested content.
The data received will depend on the service used, the User’s settings, and the terms and policies of the relevant third party.
2.7. Special Categories of Data and Sensitive Information
Chatbot App Limited does not intentionally request special categories of personal data, such as information relating to:
Physical or mental health.
Racial or ethnic origin.
Religion or philosophical beliefs.
Political opinions.
Trade union membership.
Sex life or sexual orientation.
Genetic data.
Biometric data used to uniquely identify a person.
The User should avoid entering these categories of data in prompts, conversations, documents, files, memory items, or communications unless doing so is strictly necessary, the applicable law permits the processing, and the User has a sufficient legal basis or authorisation.
We also recommend that Users do not provide confidential or particularly sensitive information that is not necessary, such as passwords, private keys, access codes, full card numbers, complete medical records, or trade secrets.
Due to the open nature of certain tools, the User may voluntarily provide sensitive information without Chatbot App Limited having requested it in advance. In such cases, that information may be processed incidentally and only to the extent necessary to provide the requested feature, protect security, or comply with a legal obligation.
Chatbot App Limited may apply automated or manual measures intended to prevent, restrict, conceal, or delete certain sensitive content where its processing is not necessary, appropriate, or legally permitted.
We will not use special categories of data provided incidentally to infer sensitive profiles, carry out personalised advertising, or pursue purposes incompatible with the User’s request, unless there is a specific legal basis and the information required by applicable law has been provided in advance.
2.8. Anonymous and Aggregated Data
Chatbot App Limited may generate statistical, aggregated, or anonymised information from the use of the Platforms in order to:
Analyse the operation of Rescrito and Aithor.
Measure the performance of the features.
Identify general usage trends.
Improve security and stability.
Develop and evaluate new tools.
Prepare internal or commercial reports.
Once information has been irreversibly anonymised and no longer reasonably allows a person to be identified, it will cease to be considered personal data and may be retained and used for the stated purposes.
- Purposes of Processing
Chatbot App Limited will process the User’s personal data for the purposes described below. Not all purposes will apply to every User, as they will depend on the Platforms, features, devices, settings, and purchasing arrangements used.
3.1. Registration, Authentication, and Account Administration
Data may be processed to:
Manage the User’s registration, identification, and authentication on Rescrito and Aithor.
Enable sign-in using email, Apple, Google, or other enabled authentication providers.
Create, administer, verify, and protect the account.
Maintain the preferences, settings, language, and options selected by the User.
Manage active sessions and synchronise the account across different devices.
Restore access to the account and manage credential changes.
Verify the email address and prevent fraudulent or abusive registrations.
3.2. Provision of the Requested Features
Data will be processed to enable access to and use of the tools available on Rescrito and Aithor, including, among others:
Writing, editing, correcting, rewriting, translating, paraphrasing, and humanising texts.
Interaction through chat and virtual assistants.
Researching, searching, analysing, and organising information.
Generating and managing citations and references.
Processing documents, PDF files, images, audio, videos, links, and web pages.
Creating study materials, presentations, multimedia content, and other resources.
Managing conversations, projects, documents, folders, favourites, and templates.
Exporting, copying, storing, and sharing content where these options are available.
Any other feature compatible with the general nature of the Platforms that may be introduced in the future.
For these purposes, we may process the prompts, instructions, messages, conversations, documents, files, links, and other content provided by the User in order to generate, store, and deliver the requested Results.
3.3. Conversational Memory and Personalisation
When the memory feature is available and enabled, data may be processed to:
Maintain continuity between conversations.
Remember language, tone, style, format, or structure preferences.
Retain objectives, projects, recurring instructions, and other relevant contextual data.
Personalise future responses and recommendations.
Retrieve relevant information from previous conversations.
Synchronise certain memory items across devices linked to the same account.
Allow the User to review, correct, delete, or manage stored information.
Memory may be generated from information provided directly by the User or through automated processes that identify and summarise relevant contextual data.
Identifiable information stored through memory will not be used to train artificial intelligence models for a purpose other than providing, securing, evaluating, or personalising the service without first informing the User and having a valid legal basis.
3.4. Operation of the Mobile Applications
When the User uses the applications for iOS or Android, their data may be processed to:
Install, launch, and maintain the operation of the application.
Keep the User signed in.
Verify device and operating system compatibility.
Manage permissions requested by certain features.
Enable the selection or uploading of files, photographs, videos, and audio.
Enable the use of the camera or microphone when the User requests a feature that requires them.
Synchronise conversations, projects, settings, and purchases.
Restore subscriptions or purchases made through the Apple App Store or Google Play.
Detect errors, crashes, synchronisation failures, and performance issues.
Distribute updates, fixes, and improvements.
Adapt certain features to the device or application version.
3.5. Subscription, Payment, and Billing Management
Data may be processed to:
Process the purchase of subscriptions and trial periods.
Manage purchases of credits or other digital products.
Process charges and automatic renewals.
Verify the status of a purchase or subscription.
Restore purchases made through the mobile applications.
Manage cancellations, failed payments, returns, and refunds.
Issue receipts, supporting documents, and invoices.
Manage taxes and accounting obligations.
Detect suspicious or fraudulent transactions.
Respond to enquiries relating to transactions.
Payments may be processed through Stripe, the Apple App Store, Google Play, or other enabled providers. As a general rule, Chatbot App Limited does not store complete card or payment method details.
3.6. User Support and Request Management
Data may be processed to:
Respond to enquiries and requests for information.
Resolve technical incidents.
Manage complaints and refund requests.
Assist with restoring accounts or purchases.
Handle requests relating to conversations, files, memory, or subscriptions.
Manage the exercise of data protection rights.
Maintain a reasonable record of the communications required to resolve each case.
Assess and improve the quality of the support provided.
3.7. Operational Communications and Notifications
Data may be used to send communications that are necessary for or related to the operation of the service, such as:
Confirmations of registration, authentication, or password changes.
Confirmations of purchases, payments, renewals, cancellations, or refunds.
Notices concerning subscription status or credit usage.
Security alerts or notifications of suspicious access.
Information about technical incidents, maintenance, or availability.
Notices concerning material changes to features.
Changes to the Terms, Privacy Policy, or other conditions.
Responses to enquiries and requests.
Notifications requested by the User within a feature.
These communications may be sent by email, through notices within the Platforms, or by push notification.
The User may manage push notifications through the application or their device settings. Certain communications that are strictly necessary for the account or contractual relationship cannot be disabled while the relevant service remains active.
3.8. Marketing Communications
Where there is a valid legal basis, data may be processed to:
Send newsletters.
Communicate updates about Rescrito and Aithor.
Provide information about new tools, plans, or features.
Send offers, promotions, discounts, and marketing campaigns.
Personalise certain communications according to the User’s preferences.
Measure campaign delivery and effectiveness where legally permitted.
Where marketing communications are based on consent, the User may withdraw it at any time through the unsubscribe link included in the messages, through their account settings, or by writing to [email protected].
The withdrawal of consent will not affect the lawfulness of processing carried out before its withdrawal.
3.9. Analysis, Diagnostics, and Improvement of the Platforms
Data may be processed to:
Analyse the operation and use of Rescrito and Aithor.
Understand which tools and features are used.
Measure performance, stability, and response times.
Detect errors, crashes, and technical incidents.
Improve usability and the User experience.
Assess the overall quality of the Results.
Develop, test, and improve new features.
Conduct technical tests and tests involving interfaces, models, prices, or offers.
Improve compatibility between the web, iOS, Android, and other channels.
Optimise the security, capacity, and scalability of the services.
Prepare internal statistics and aggregated analyses.
Where reasonably possible, data used for these purposes will be aggregated, pseudonymised, or anonymised.
Non-essential analytics or tracking tools will be used in accordance with the User’s preferences and, where applicable, after obtaining their consent.
3.10. Security, Moderation, and Fraud Prevention
Data may be processed to:
Detect unauthorised access and suspicious activity.
Prevent identity theft and impersonation.
Detect abusive account creation.
Prevent the circumvention of limits, restrictions, payments, or promotions.
Protect accounts, content, systems, and infrastructure.
Detect bots, scraping, attacks, and other unauthorised automated uses.
Investigate failed payments, abusive chargebacks, and fraudulent transactions.
Identify content or activity that may breach the Terms or applicable law.
Apply restriction, blocking, or suspension measures where necessary.
Maintain technical records and evidence relating to incidents.
Cooperate with security, payment, and fraud-prevention providers.
These operations may be carried out using automated systems and, where necessary, through review by authorised personnel.
3.11. Legal Compliance and Protection of Rights
Data may be processed to:
Comply with tax, accounting, administrative, and regulatory obligations.
Respond to valid requests from authorities, courts, or competent bodies.
Comply with obligations relating to data protection and consumer rights.
Establish, exercise, or defend legal claims.
Retain evidence of purchases, payments, consents, and communications.
Protect the rights, property, security, and legitimate interests of Chatbot App Limited, its Users, providers, and third parties.
Investigate and respond to communications relating to intellectual property, fraud, security, or unlawful activities.
3.12. Anonymisation and Preparation of Statistics
Chatbot App Limited may anonymise personal data to generate statistical information that no longer reasonably allows the User to be identified.
This information may be used to:
Analyse general trends.
Assess the performance of the Platforms.
Improve tools and models.
Plan new features.
Prepare internal or commercial reports.
Investigate security and usage patterns.
Once irreversibly anonymised, the information will cease to be considered personal data.
3.13. Purpose Limitation
Chatbot App Limited will not use personal data for purposes incompatible with those for which it was collected.
Where substantially different processing is intended, the User will be informed in advance and the appropriate legal basis will be determined. Where necessary, separate, specific, and informed consent will be requested.
- Legal Bases for Processing
Where European data protection law applies, Chatbot App Limited will process the User’s personal data on the legal basis applicable to each specific purpose.
The use of Rescrito or Aithor and the acceptance of their Terms and Conditions do not constitute general consent to all processing of personal data.
The same data may be processed on different legal bases where necessary for different purposes. For example, certain transaction data may be used to provide the service, comply with tax obligations, and prevent fraud.
4.1. Performance of a Contract and Pre-contractual Measures
Processing will be necessary for the performance of the contract with the User or in order to take pre-contractual steps at the User’s request, pursuant to Article 6(1)(b) of the GDPR, where it is carried out to:
Create, authenticate, verify, and administer the account.
Enable sign-in and maintain active sessions.
Provide the features requested on Rescrito and Aithor.
Process prompts, instructions, conversations, documents, files, images, audio, videos, and other content provided by the User.
Generate, store, and deliver the requested Results.
Manage conversations, projects, documents, folders, favourites, and settings.
Synchronise account information across different devices.
Provide personalisation features expressly requested by the User.
Manage subscriptions, trial periods, credits, purchases, renewals, cancellations, and refunds.
Verify and restore purchases made through the Apple App Store, Google Play, or other channels.
Issue confirmations, receipts, and communications necessary for the provision of the service.
Provide technical support and address issues relating to the account or the purchase.
Manage account deletion and the export of information where these operations form part of the service.
Where the User does not provide the data necessary for these purposes, Chatbot App Limited may be unable to create the account, enter into the contract, or provide the requested feature.
4.2. User Consent
Processing will be based on the User’s consent, pursuant to Article 6(1)(a) of the GDPR, where such consent is necessary to:
Enable optional conversational memory features that allow information to be retained between conversations.
Store certain optional preferences or contextual data in order to personalise future responses.
Send newsletters, promotions, and other marketing communications where there is no other valid legal basis.
Send promotional push notifications.
Use non-essential cookies, SDKs, identifiers, or similar technologies.
Carry out analytics, attribution, or personalisation measurements that require consent.
Access certain device permissions where such access requires the User’s specific authorisation.
Carry out any other operation that, by its nature or under applicable law, requires prior authorisation.
Consent must be freely given, specific, informed, and unambiguous, and will be requested through a clear affirmative action.
The User may withdraw consent at any time through:
Their account settings.
The memory or personalisation options.
The cookies or privacy panel.
Their device notification settings.
The unsubscribe link included in marketing communications.
A request sent to [email protected].
The withdrawal of consent will not affect the lawfulness of processing carried out before its withdrawal.
Where the User withdraws consent for an optional feature, that feature may be disabled or cease to be available, without necessarily affecting the rest of the Platforms.
Where conversational memory is based on consent, withdrawal will prevent its use in new conversations. The relevant settings will indicate whether previously stored data is deleted automatically or must be deleted separately.
4.3. Legitimate Interests
Chatbot App Limited may process certain data on the basis of its legitimate interests or those of third parties, pursuant to Article 6(1)(f) of the GDPR, where those interests are not overridden by the User’s interests, fundamental rights, or freedoms.
These interests may include:
Protecting the security, integrity, and availability of the Platforms.
Detecting and preventing unauthorised access, fraud, abuse, bots, and unlawful activities.
Preventing abusive account creation and the circumvention of payments, limits, or promotions.
Investigating errors, crashes, and technical incidents.
Maintaining reasonable security and activity records.
Protecting the rights, systems, property, and Users of Chatbot App Limited.
Establishing, exercising, or defending legal claims.
Improving the stability, performance, compatibility, and overall experience of the Platforms.
Preparing internal statistics and aggregated analyses.
Assessing the overall quality of the service and User support.
Conducting technical tests that do not require consent.
Preventing fraudulent returns, claims, or transactions.
Managing operational communications that are not strictly contractual but are reasonably expected.
Ensuring business continuity and infrastructure security.
Before relying on legitimate interests for relevant processing, Chatbot App Limited will assess:
The existence of a genuine legitimate interest.
The necessity and proportionality of the processing.
The User’s reasonable expectations.
The nature of the data processed.
The potential impact on the User’s rights and freedoms.
The measures available to reduce that impact.
These measures may include data minimisation, pseudonymisation, aggregation, access restrictions, shorter retention periods, and objection mechanisms.
The User may object to processing based on legitimate interests on grounds relating to their particular situation.
Chatbot App Limited will cease processing the data unless it demonstrates compelling legitimate grounds that override the User’s interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
Where the objection relates to direct marketing, processing for that purpose will cease.
4.4. Compliance with Legal Obligations
Processing may be necessary in order to comply with legal obligations applicable to Chatbot App Limited, pursuant to Article 6(1)(c) of the GDPR.
These obligations may include:
Tax, accounting, and billing obligations.
Retention of transaction records.
Responding to valid requests from judicial, administrative, tax, regulatory, or law-enforcement authorities.
Compliance with obligations relating to consumers, electronic commerce, and digital services.
Managing and notifying security incidents where required.
Handling data protection requests and complaints.
Compliance with fraud prevention, anti-money laundering, sanctions, or trade restriction measures where applicable.
Retention of information necessary to demonstrate legal compliance.
Removal or restriction of content where there is a legal obligation or valid order.
Where Chatbot App Limited is required to retain data under a legal obligation, such data may remain blocked or restricted even after account deletion or withdrawal of consent.
4.5. Vital Interests
In exceptional circumstances, processing may be necessary to protect the vital interests of the User or another natural person, pursuant to Article 6(1)(d) of the GDPR.
This legal basis will only be used where there is a real and significant risk to a person’s life or physical integrity and it is not reasonably possible to rely on another, more appropriate legal basis.
Rescrito and Aithor are not emergency services and do not guarantee the detection or management of risk situations.
4.6. Special Categories of Personal Data
Chatbot App Limited does not intentionally request special categories of personal data.
Where the User provides information relating to health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, sexual orientation, genetic data, or biometric data, having a legal basis under Article 6 of the GDPR alone will not be sufficient.
A valid condition permitting the processing under Article 9(2) of the GDPR must also apply, such as, where relevant:
The data subject’s explicit consent.
The fact that the data has manifestly been made public by the data subject.
The necessity of establishing, exercising, or defending legal claims.
Any other legally recognised exception.
The User should avoid entering special categories of data unless they are strictly necessary and the User has a sufficient legal basis.
Where there is no valid condition for processing such data, Chatbot App Limited may refuse to process it, block it, restrict it, or delete it.
The mere voluntary submission of sensitive information will not automatically be regarded as explicit consent to any processing or purpose.
4.7. Conversational Memory
The legal basis applicable to memory will depend on how it operates and is configured.
Where memory is an optional feature that retains information for future conversations, its activation and use may be based on the User’s consent.
Where certain contextual operations are strictly necessary to provide a feature expressly requested within a conversation or project, they may be based on the performance of the contract.
Processing required to protect memory, prevent improper access, detect errors, or ensure its security may be based on Chatbot App Limited’s legitimate interests.
Information stored in memory will not be reused for incompatible purposes or to train models for a purpose other than providing, securing, evaluating, or personalising the service without a valid legal basis and the provision of the relevant information.
4.8. Mobile Applications and Device Permissions
The processing of data necessary to install, authenticate, maintain, synchronise, and provide the features of the mobile applications may be based on the performance of the contract.
The processing of technical logs necessary to ensure security, diagnose failures, and maintain stability may be based on legitimate interests.
Access to the camera, microphone, photographs, videos, files, or notifications will depend on the authorisation granted through the device’s operating system.
Technical authorisation through the operating system will not replace any consent required under data protection law where such consent is necessary for a specific purpose.
Strictly operational notifications may be sent in order to perform the contract or maintain account security. Marketing notifications will be based on consent or another valid legal basis.
4.9. External Providers
The involvement of an external provider does not in itself alter the legal basis for the processing.
Chatbot App Limited will determine the applicable legal basis according to the purpose for which each provider is used.
For example:
Artificial intelligence providers may process content in order to fulfil the User’s request.
Payment providers may be involved in order to perform the contract, prevent fraud, and comply with legal obligations.
Security services may be used on the basis of legitimate interests.
Non-essential analytics tools may require consent.
Apple, Google, or other providers may carry out their own processing on the basis of their own terms and responsibilities.
Where a provider acts as an independent controller, it must determine and communicate its own legal bases in relation to processing carried out for its own purposes.
4.10. Automated Processing
The use of automated systems to generate content, detect fraud, apply limits, personalise features, or select experiences will rely on the legal basis applicable to the specific purpose.
As a general rule, Chatbot App Limited does not make decisions based solely on automated processing that produce legal effects concerning the User or similarly significantly affect them.
If such processing were introduced, Chatbot App Limited would:
Inform the User in advance.
Identify a valid legal basis.
Explain the general logic, significance, and anticipated consequences.
Apply the safeguards required by law.
Allow the User, where applicable, to request human intervention, express their point of view, and contest the decision.
4.11. Change of Legal Basis or Purpose
Chatbot App Limited will not arbitrarily change the legal basis for processing in order to avoid the obligations associated with the basis originally relied upon.
Where data is intended to be processed for a new or substantially different purpose, the following will be assessed:
Whether the new purpose is compatible with the original purpose.
The relationship between the two purposes.
The context in which the data was collected.
The nature of the information.
The possible consequences for the User.
The applicable safeguards.
Where the new purpose is incompatible or requires consent, the User will be informed in advance and separate authorisation will be requested where appropriate.
- Data Retention
Chatbot App Limited will retain personal data only for as long as necessary to fulfil the purposes for which it was collected and, thereafter, for the periods required to comply with legal obligations, address potential liabilities, and establish, exercise, or defend legal claims.
Specific retention periods may vary depending on the category of data, the purpose of the processing, the relationship maintained with the User, the features used, and the applicable legal obligations.
5.1. Account and Profile Data
Registration, identification, authentication, profile, preference, and configuration data will be retained for as long as the account remains active.
When the User requests the deletion of their account, this data will be deleted or anonymised within a reasonable period, unless it must be temporarily retained in order to:
Comply with legal obligations.
Manage pending payments, billing, refunds, or claims.
Investigate fraud, security incidents, or breaches.
Establish, exercise, or defend legal claims.
Maintain minimum records intended to prevent abusive use or the fraudulent reopening of accounts, where there is a valid legal basis.
Cancelling a subscription does not result in the deletion of the account. Likewise, signing out or uninstalling a mobile application does not delete data stored on the Platforms’ servers.
5.2. Conversations, Prompts, Documents, and Content
Prompts, messages, conversations, documents, files, projects, and generated Results may be retained for as long as:
The account remains active.
The User has not deleted them using the available features.
They are necessary to provide the requested features.
They must be retained for security, legal compliance, or the defence of legal claims.
When the User deletes a conversation, document, file, or project, it will cease to be available in their account once the request has been processed.
However, certain copies may remain temporarily in backup systems, technical logs, or recovery environments until they are overwritten or deleted in accordance with the relevant security cycles.
Deleting a conversation does not necessarily result in the deletion of information that may previously have been added to conversational memory where the two items are stored and managed separately.
5.3. Conversational Memory and Personalisation
Items stored through conversational memory features may be retained for as long as:
The feature remains enabled.
The User maintains their account.
The User has not deleted the specific item or all memory.
They remain necessary to provide the requested personalisation.
The User may manage memory through the enabled options, including, where available:
Reviewing the stored information.
Correcting inaccurate or outdated data.
Deleting specific items.
Deleting all memory.
Disabling the addition or use of new items.
When the User disables memory, the information will no longer be used to personalise future conversations.
The interface will clearly indicate whether existing items are deleted automatically when memory is disabled or remain stored until the User expressly deletes them.
Where memory processing is based on consent and the User withdraws it, the data will no longer be used for that purpose and will be deleted, unless another legal basis temporarily justifies its retention.
Deleting memory does not necessarily result in the deletion of the original conversations from which the information may have originated. The User must also delete those conversations where they wish to remove both items.
5.4. Subscription, Payment, and Billing Data
Data relating to subscriptions, credit purchases, payments, renewals, cancellations, invoices, receipts, and refunds will be retained for the period necessary to manage the contractual relationship and for the applicable tax, accounting, commercial, and legal retention periods.
Chatbot App Limited may retain limited transaction information, such as:
Date and amount.
Currency.
Product or plan purchased.
Transaction identifier.
Payment status.
Information necessary to address claims or prevent fraud.
Payment providers, the Apple App Store, Google Play, and other external platforms may retain transaction data in accordance with their own obligations, policies, and retention periods, acting in certain cases as independent data controllers.
5.5. Mobile Application Data
Technical data required to maintain a session, synchronise the account, and provide mobile features will be retained for as long as necessary for the operation of the application or account.
In particular:
Push notification tokens will be retained for as long as they remain valid and the User keeps the relevant notifications enabled.
Purchase restoration data may be retained for as long as necessary to verify subscriptions or purchased products.
Error, crash, and performance logs will be retained for as long as reasonably necessary to diagnose incidents and improve stability.
Data stored locally on the device may remain until the User signs out, deletes the application data, or uninstalls the application.
Uninstalling the application may delete locally stored data, but it does not automatically delete the account, conversations, memory items, or subscriptions managed through Apple, Google, or other providers.
5.6. Support and Communications Data
Enquiries, incidents, complaints, refund requests, and communications with support will be retained for the period necessary to address the request and, thereafter, for the period reasonably necessary to:
Maintain a record of the assistance provided.
Manage related claims.
Protect the rights of the parties.
Comply with legal obligations.
Improve the quality of support.
Where a communication relates to a transaction, legal claim, or security incident, it may be retained for a longer period in accordance with the applicable time limits.
5.7. Security and Fraud-Prevention Data
Technical logs, access records, authentication events, IP addresses, suspicious activity, and other information used to protect the Platforms may be retained for as long as necessary to:
Detect and investigate unauthorised access.
Prevent fraud, abuse, and circumvention of limits.
Investigate security incidents.
Protect accounts and systems.
Establish, exercise, or defend legal claims.
Comply with valid requests from authorities.
Retention periods will be determined by taking into account the nature of the record, the severity of the risk, the need for investigation, and the applicable legal obligations.
5.8. Analytics and Diagnostic Data
Navigation, usage, performance, diagnostic, and analytics data will be retained for the period necessary to assess the operation of Rescrito and Aithor, detect errors, prepare statistics, and improve the Platforms.
Where this processing is based on consent, it will cease for the future when the User withdraws that consent.
Pseudonymised data will continue to be considered personal data for as long as it can reasonably be linked to a person.
Aggregated or irreversibly anonymised data may be retained indefinitely, provided that it no longer allows the User to be identified or their personal information to be reasonably reconstructed.
5.9. Marketing Communications
Data used to send marketing communications will be retained for as long as there is a valid legal basis and the User has not withdrawn their consent or exercised their right to object.
Following an unsubscribe request, minimum information may be retained on a suppression list to record the request and prevent further unauthorised marketing communications from being sent.
The withdrawal of consent will not affect the retention of operational communications necessary to administer an account, subscription, purchase, or security incident.
5.10. Account Deletion
The User may request the deletion of their account through the options available on the Platforms or by writing to [email protected].
Before deleting the account, Chatbot App Limited may request reasonable identity verification in order to prevent unauthorised deletions.
Account deletion may result in the permanent loss of access to:
Conversations and history.
Documents and files.
Projects and folders.
Generated Results.
Preferences and settings.
Memory items.
Credits or benefits linked to the account.
Other features or content not previously exported.
Deleting an account does not necessarily cancel a subscription processed by the Apple App Store, Google Play, or another external provider. The User must first cancel the renewal through the channel that manages the charge.
Where the immediate deletion of certain data is not possible due to a legal obligation, a pending claim, or a legitimate security need, the data will be blocked, isolated, or subject to restricted access and will not be used for other incompatible purposes.
5.11. Backups
Backups may temporarily retain personal data after it has been deleted from active systems.
During this period:
The data will not be available for the ordinary use of the Platforms.
Access will be limited to security, recovery, or legal compliance needs.
The copies will be overwritten or deleted in accordance with the established technical cycles.
If a backup must be restored, the relevant deletion requests will be reapplied.
The existence of technical backups does not mean that Chatbot App Limited can restore specific conversations, documents, or items at the User’s request.
5.12. Retention for Legal Obligations or Claims
Chatbot App Limited may retain certain data for a longer period where necessary to:
Comply with a legal obligation.
Respond to a request from a competent authority.
Investigate a possible infringement.
Protect the security of the Platforms or third parties.
Establish, exercise, or defend legal claims.
Provide evidence of purchases, payments, consents, or communications.
In such cases, processing will be limited to those purposes and access to the data will be restricted.
Once the reasons justifying the additional retention no longer apply, the data will be securely deleted or anonymised.
5.13. User Rights
The User may request information about the retention criteria applicable to their data and exercise their rights of access, rectification, erasure, objection, restriction, and portability in accordance with Section 7 of this Policy.
A request for erasure will not always result in the immediate deletion of all data where there is an obligation or valid legal basis requiring its temporary retention.
In such cases, Chatbot App Limited will inform the User of the reasons for the retention, unless applicable law prevents that information from being provided.
- Disclosure of Data to Third Parties
Chatbot App Limited does not sell or rent Users’ personal data to third parties for their own commercial purposes.
Personal data will only be disclosed or made available to third parties where:
It is necessary to provide, maintain, protect, or improve Rescrito and Aithor.
The User has requested a feature that requires the involvement of an external provider.
There is a legal obligation or valid request.
It is necessary to establish, exercise, or defend legal claims.
The User has given their consent.
There is any other valid legal basis under applicable law.
The use of a provider does not mean that it receives all of the User’s data. Each provider will access only the categories of information reasonably necessary to perform the relevant function.
6.1. Infrastructure and Technical Service Providers
Chatbot App Limited may use providers of infrastructure, hosting, storage, databases, authentication, synchronisation, and technical services.
These may include:
Google Cloud and Firebase: hosting, infrastructure, databases, storage, authentication, synchronisation, messaging, and other technical functions.
Contextual storage, semantic search, or vector database providers: indexing, storage, and retrieval of information necessary to provide search, conversational memory, and personalisation features.
Monitoring and security providers: system monitoring, incident detection, account protection, and prevention of unauthorised access.
Backup and recovery providers: temporary retention and technical restoration of information where necessary.
Depending on the service used, the data processed may include account information, technical identifiers, conversations, documents, files, settings, memory items, and activity logs.
6.2. Artificial Intelligence Providers
In order to provide the requested features, certain data may be processed by providers of artificial intelligence models and services, including, among others:
OpenAI.
Google.
Anthropic.
Mistral AI.
DeepSeek.
Other providers that may be added, replaced, or discontinued.
Depending on the feature, the data sent may include:
Prompts and instructions.
Messages and excerpts from conversations.
Documents, texts, and files.
Images, audio, videos, or links.
Contextual information necessary to generate the response.
Relevant conversational memory items where memory is enabled.
Technical parameters and preferences relating to the request.
Not all providers are involved in every request. The provider or combination of technologies used may vary depending on the tool, selected model, content format, language, region, subscribed plan, and technical availability.
Providers will receive only the information necessary to process the relevant request.
The use of identifiable User Content to train models for a purpose other than providing, securing, evaluating, or personalising the service must be expressly disclosed and supported by a valid legal basis.
6.3. Payment Providers and App Stores
Payments, subscriptions, renewals, credit purchases, refunds, and related transactions may be managed through:
Stripe.
Apple App Store.
Google Play.
Other payment providers or distribution channels enabled from time to time.
These providers may process:
Account and transaction identifiers.
The product or plan purchased.
The amount, currency, and taxes.
Payment or subscription status.
Renewal, cancellation, or refund date.
Limited information about the payment method.
Billing information.
Fraud-prevention signals.
Receipts and information required to verify or restore purchases.
As a general rule, Chatbot App Limited does not receive or store full card numbers or security codes.
Payment providers and app stores may act as independent controllers in relation to processing activities for which they determine the purposes and means themselves, particularly regarding payment processing, fraud prevention, legal compliance, billing, and claims management.
In such cases, their own privacy policies and terms will also apply.
6.4. Authentication Providers
When the User registers or signs in through an external service, we may receive data from providers such as:
Apple.
Google.
Other enabled identity providers.
The information received may include the User’s name or alias, email address, a technical identifier, and the confirmation required to authenticate the account.
Where the User uses features such as Apple’s “Hide My Email”, we may receive a private relay address instead of their actual email address.
These providers may also carry out their own processing in accordance with their policies and the settings selected by the User.
6.5. Communications and Notification Providers
Chatbot App Limited may use external providers to send communications relating to the Platforms.
These may include:
Mailgun and other email services: sending transactional, operational, support, and authorised marketing messages.
Apple Push Notification Service: sending notifications to iOS devices.
Firebase Cloud Messaging: sending notifications to Android devices and other compatible environments.
Other messaging or communications providers enabled in the future.
These providers may process data such as:
Email address.
Name or alias.
Account identifier.
Content and category of the communication.
Technical notification token.
Information about delivery, rejection, or interaction with the message, where applicable.
Marketing communications and associated measurement technologies will be used in accordance with the relevant legal basis and the User’s preferences.
6.6. Analytics, Diagnostics, and Improvement Providers
In order to understand how the Platforms operate, detect errors, and improve the User experience, Chatbot App Limited may use services such as:
Google Analytics.
Hotjar.
Yandex Metrica.
Error and crash diagnostic tools.
Performance monitoring services.
Other analytics or experimentation providers.
Depending on the tool, the data processed may include:
IP address or approximate location.
Technical identifiers.
Browser, device, or operating system information.
Pages or screens visited.
Features used.
Clicks and interactions.
Session duration.
Errors, crashes, and loading times.
Application version.
Information about campaigns or access sources.
Analytics, session recording, attribution, or personalisation tools that are not strictly necessary will remain disabled until the User has given their consent, where such consent is required.
Where reasonably possible, data minimisation, pseudonymisation, masking, or anonymisation measures will be applied.
6.7. Support, Security, and Fraud-Prevention Providers
Certain data may be made available to providers that assist with:
User support.
Incident management.
Fraud detection.
Protection against bots and attacks.
Transaction verification.
Content moderation.
Infrastructure monitoring.
Technical maintenance.
Legal protection and regulatory compliance.
These providers may process account data, support communications, technical logs, transaction information, and content relating to a specific incident.
Access will be limited to the information necessary to investigate, handle, or resolve the relevant case.
6.8. Processors and Independent Controllers
Where a provider processes personal data on behalf of Chatbot App Limited and in accordance with its instructions, it will act as a processor or sub-processor.
In such cases, it will be subject to contractual obligations relating to:
Confidentiality.
Security.
Processing in accordance with documented instructions.
Purpose limitation.
Assistance with the exercise of rights.
Incident notification.
Deletion or return of data.
Control of the sub-processors used.
Where the GDPR applies, these relationships will be governed in accordance with Article 28.
Certain providers may act as independent controllers where they determine the purposes and means of processing themselves. This may occur particularly in relation to:
Payment processing and security.
Prevention of financial fraud.
App stores.
Billing and taxes.
Compliance with legal obligations.
Claims management.
External services used directly by the User.
In such cases, the processing will also be subject to the relevant provider’s privacy policies.
6.9. Disclosures Required by Law and Protection of Rights
Chatbot App Limited may disclose personal data:
To administrative, judicial, tax, regulatory, or law-enforcement authorities where there is a legal obligation or valid request.
To comply with court orders or legally binding measures.
To investigate or prevent fraud, unlawful activity, or security threats.
To protect the rights, property, or safety of Chatbot App Limited, its Users, employees, providers, or third parties.
To legal, tax, and accounting advisers, auditors, insurers, and other professionals where necessary to comply with obligations or establish, exercise, or defend legal claims.
Before disclosing information to an authority or third party, Chatbot App Limited will seek to verify the legitimacy, scope, and proportionality of the request, unless applicable law prevents such verification or the User from being informed.
6.10. Corporate Transactions
Personal data may be disclosed to prospective purchasers, investors, financial institutions, advisers, or participants in a transaction involving:
A merger.
An acquisition.
An investment.
Financing.
Restructuring.
A sale of assets.
A total or partial transfer of the business.
Such disclosures will be limited to the information necessary to evaluate or carry out the transaction and will be subject, where appropriate, to confidentiality obligations and protective measures.
If the transaction results in a change of data controller or materially affects how the data is used, Users will be informed in accordance with applicable law.
6.11. International Transfers
Chatbot App Limited is incorporated in Hong Kong and uses providers that may process data from Hong Kong, the United States, countries within the European Economic Area, and other jurisdictions.
Personal data may therefore be processed in or accessible from countries other than the User’s country of residence.
Where the GDPR applies and data is transferred to a country for which no adequacy decision exists, Chatbot App Limited will use legally recognised mechanisms, such as:
Standard contractual clauses approved by the European Commission.
Binding corporate rules, where applicable.
Legally recognised derogations for specific situations.
Other safeguards recognised under applicable law.
Where necessary, the circumstances of the transfer will be assessed and supplementary technical, contractual, or organisational measures will be adopted.
The User may request further information about the applicable safeguards by writing to [email protected].
6.12. Updates to Providers
The list of providers may change as Chatbot App Limited:
Introduces new features.
Launches or updates the mobile applications.
Adds memory and personalisation features.
Replaces technologies or models.
Improves security or performance.
Changes providers for technical, legal, operational, or commercial reasons.
Minor changes that do not materially alter the processing may be reflected by updating this Policy or a list of providers and sub-processors.
Where a change involves a new purpose, a relevant category of data, a substantially different international transfer, or a significant impact on the User’s rights, the relevant information will be provided before the new processing begins where required by applicable law.
- User Rights
The User may exercise the rights recognised under the data protection laws applicable to their circumstances, place of residence, and relationship with Rescrito or Aithor.
The availability and scope of each right may vary depending on the applicable law, the nature of the processing, and the legal basis relied upon.
7.1. Rights Applicable under the GDPR
Where the General Data Protection Regulation applies, the User may exercise the following rights:
Access: to find out whether Chatbot App Limited processes their personal data and obtain information about the purposes, categories of data, recipients, international transfers, retention periods, and other circumstances of the processing, as well as receive a copy of the personal data being processed.
Rectification: to request the correction of inaccurate data and the completion of incomplete information.
Erasure: to request the deletion of data where it is no longer necessary, consent has been withdrawn, a valid objection has been made, the processing is unlawful, or another legally recognised ground applies.
Restriction of processing: to request that processing be temporarily restricted in the circumstances provided for by applicable law.
Objection: to object, on grounds relating to their particular situation, to processing based on legitimate interests or the performance of a task carried out in the public interest.
Objection to direct marketing: to object at any time to the processing of their data for direct marketing purposes, including profiling related to such purposes.
Data portability: to receive certain data provided to Chatbot App Limited in a structured, commonly used, and machine-readable format and, where technically feasible, request its direct transmission to another controller. As a general rule, this right applies to automated processing based on consent or the performance of a contract.
Withdrawal of consent: to withdraw consent previously given at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Automated decision-making: to request not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them, where this right applies, as well as to request human intervention, express their point of view, and contest the decision.
These rights may be subject to the limitations, exceptions, and conditions established by applicable law.
7.2. Rights under Hong Kong Law
In accordance with Hong Kong’s Personal Data (Privacy) Ordinance (“PDPO”), the User may, where applicable:
Request confirmation as to whether Chatbot App Limited holds personal data relating to them.
Request access to that data and obtain a copy.
Request the correction of inaccurate personal data.
Request information about personal data processing policies and practices.
Submit a complaint to the competent Hong Kong authority where they believe their data has been processed in breach of the PDPO.
Chatbot App Limited will also address requests for deletion, objection, restriction, withdrawal of consent, or preference management where such rights apply under other legislation, the commitments made in this Policy, or the features offered on the Platforms.
7.3. Management of Conversations and Memory
In addition to the legal rights set out above, the User may have access to tools within Rescrito and Aithor that allow them to manage certain data directly.
Where these options are available, the User may:
Review and delete conversations.
Delete documents, files, projects, and other content.
Review information stored through conversational memory.
Correct inaccurate or outdated memory items.
Delete specific items or erase all memory.
Disable the use of memory for future conversations.
Download or export certain content from their account.
Request the deletion of their account.
Deleting a conversation and deleting information stored in memory may be separate processes. Where the data is managed separately, the User must delete both items using the relevant options.
The tools available within the Platforms do not replace or limit the User’s right to submit a formal request to Chatbot App Limited.
7.4. Procedure for Exercising Rights
The User may exercise their rights by writing to:
Where possible, the request should specify:
The right the User wishes to exercise.
The email address associated with the account.
The Platform concerned: Rescrito or Aithor.
A sufficiently clear description of the data or processing activities concerned.
Any information reasonably necessary to locate the data and process the request.
It is recommended that the request be sent from the email address associated with the account.
The User may also use the options available within the web or mobile applications to manage their account, conversations, memory, preferences, consents, and content.
Where a formal access request is submitted specifically under Hong Kong law, Chatbot App Limited may require the use of the form or procedure prescribed by the PDPO.
The User may exercise their rights personally or through a duly authorised representative.
7.5. Identity Verification
Chatbot App Limited may request additional information where there are reasonable doubts about the identity of the applicant or where necessary to prevent:
Unauthorised access to personal data.
Fraudulent account deletions.
Changes made by third parties.
Identity theft or impersonation.
Improper disclosure of conversations, files, or memory information.
The information requested will be limited to what is strictly necessary and proportionate to verify identity.
A copy of an identity document will not be requested unless it is reasonably necessary and no less intrusive method is available to complete the verification.
Where identity documentation is provided, measures such as redacting information that is not necessary for verification may be requested.
7.6. Response Times
Chatbot App Limited will respond to requests within the period established by applicable law.
Where the GDPR applies:
As a general rule, the request will be handled within one month of receipt.
The period may be extended by up to two additional months where necessary due to the complexity or number of requests.
The User will be informed of the extension and the reasons for it within the first month.
If no action is taken on the request, the User will be informed of the reasons and of the possibility of lodging a complaint with a supervisory authority.
Where an access request is made under Hong Kong’s PDPO, it will be handled within the applicable statutory period, generally within 40 days of receipt.
If it is not possible to complete the access request within that period for a legally permitted reason, the applicant will be informed in writing and the request will be handled as soon as reasonably possible.
7.7. Cost of Requests
Where the GDPR applies, the exercise of rights will be free of charge.
However, where a request is manifestly unfounded or excessive, particularly because of its repetitive nature, Chatbot App Limited may:
Charge a reasonable fee based on administrative costs.
Refuse to act on the request, providing reasons for the refusal.
Where an access request is made under Hong Kong’s PDPO, Chatbot App Limited may charge a fee that is not excessive and is limited to the costs directly and necessarily incurred in processing the request.
Before any fee is charged, the User will be informed of its amount and basis.
7.8. Limitations and Legal Retention
Certain rights are not absolute.
Chatbot App Limited may retain or continue to process certain data where necessary to:
Comply with a legal obligation.
Respond to valid requests from authorities.
Establish, exercise, or defend legal claims.
Prevent or investigate fraud and security incidents.
Protect the rights and safety of third parties.
Maintain tax, accounting, or contractual records.
Comply with any other exception recognised under applicable law.
Where a request cannot be fulfilled in whole or in part, the User will be informed of the reasons, unless a legal restriction prevents that information from being provided.
Data that must be retained will no longer be used for incompatible purposes and will remain blocked, isolated, or subject to restricted access, where appropriate.
7.9. Complaints to Data Protection Authorities
Before submitting a complaint, the User is encouraged to contact Chatbot App Limited at [email protected] so that we can review and resolve the matter.
This recommendation does not limit the right to contact an authority directly where permitted by law.
Where the GDPR applies, the User may lodge a complaint with the data protection authority corresponding to their habitual residence, place of work, or the place of the alleged infringement.
Users residing in Spain may lodge a complaint with the Spanish Data Protection Agency.
Users in other countries within the European Economic Area may contact the competent supervisory authority in their territory.
Where Hong Kong law applies, the User may submit a complaint to:
The Office of the Privacy Commissioner for Personal Data of Hong Kong (“PCPD”).
The complaint must identify the processing activity or conduct complained of and the entity responsible, and may require documentation enabling verification of the complainant’s identity and the circumstances of the case.
- Cookies, SDKs, and Similar Technologies
8.1. Scope
Rescrito and Aithor use cookies and other storage, identification, and measurement technologies on:
rescrito.com.
aithor.ai.
aithor.io.
Their web applications.
Their mobile applications for iOS and Android.
Associated extensions, interfaces, and integrations, where applicable.
These technologies may be used to enable the operation of the Platforms, maintain security, authenticate the User, remember their preferences, synchronise the account, analyse performance and, where enabled, measure campaigns or personalise content and communications.
The websites may use cookies, local storage, session storage, pixels, tags, and similar technologies.
The mobile applications may use SDKs, technical identifiers, notification tokens, local storage, and other equivalent technologies that do not necessarily operate through browser cookies.
The use of these technologies will be governed by this Policy, the detailed Cookies Policy, and the preferences selected by the User.
8.2. Strictly Necessary Technologies
Strictly necessary cookies and technologies make it possible to provide a service expressly requested by the User or to ensure the technical operation and security of the Platforms.
They may be used, among other purposes, to:
Enable navigation and the basic operation of the Platforms.
Create, maintain, and protect the User’s session.
Authenticate the account.
Temporarily remember information entered during a process.
Maintain security and detect attempts at unauthorised access.
Prevent fraud, abuse, and malicious automated activity.
Balance loads and maintain service stability.
Manage privacy preferences and retain the User’s cookie choices.
Process purchases, subscriptions, and other features expressly requested.
Maintain technical continuity between pages involved in the same operation.
These technologies may be used without requesting consent where they are strictly necessary to provide the requested service or enable communication between the User’s device and the Platforms.
They will not be used under this category for additional purposes such as non-essential analytics, personalised advertising, or profiling.
The User will not be able to disable them through the consent panel where they are essential to provide the service, although they may block them through their browser or device. Doing so may prevent sign-in or the proper operation of certain features.
8.3. Preference and Personalisation Technologies
These technologies make it possible to remember choices made by the User, such as:
Language.
Region or time zone.
Appearance and visual settings.
Accessibility preferences.
Selected tools or formats.
The status of certain features.
Personalisation settings.
Preferences relating to conversational memory.
Certain personalisation technologies may be considered necessary where they are used exclusively to remember an option expressly requested by the User.
Where they are used for profiling, combining information across services, or carrying out personalisation that is not necessary for the requested feature, they will remain disabled until the relevant consent has been obtained.
Conversational memory is specifically governed by the relevant sections of this Policy. Cookie settings do not replace the specific controls intended to enable, disable, review, or delete memory.
8.4. Analytics and Diagnostic Technologies
Analytics and diagnostic technologies help us understand how Rescrito and Aithor operate and are used.
They may be used to:
Measure visits, sessions, and use of features.
Identify the pages and screens used.
Analyse general navigation journeys.
Detect errors, crashes, and performance issues.
Measure loading and response times.
Assess the stability of the web and mobile applications.
Identify the general type of device, browser, or operating system.
Improve usability and design.
Evaluate new features and experiences.
Prepare aggregated statistics.
These functions may be provided through our own tools or external services such as Google Analytics, Hotjar, Yandex Metrica, or other providers that may be enabled from time to time.
Analytics technologies that are not strictly necessary will remain disabled until the User has given their consent where such consent is required.
Where possible, Chatbot App Limited will apply measures such as data minimisation, reduced location precision, field masking, pseudonymisation, or restrictive provider settings.
Session recording or replay tools, where used, must be configured to avoid the deliberate capture of passwords, payment information, private content, and other sensitive fields.
8.5. Advertising, Attribution, and Campaign Measurement Technologies
Rescrito and Aithor may use advertising or attribution technologies only where these are enabled.
These technologies may make it possible to:
Determine whether a User arrived through a specific campaign.
Measure registrations, purchases, or other conversions.
Limit how frequently a communication is shown.
Create advertising audiences.
Display content or advertisements tailored to certain interests.
Measure campaign performance.
Link interactions carried out across different pages, devices, or services where valid authorisation exists.
Technologies intended for personalised advertising, profiling, remarketing, or cross-service tracking will remain disabled until the User has given their consent where such consent is required.
Where the operating system, app store, or applicable law requires additional authorisation to use advertising identifiers or track activity across applications and websites, that authorisation will be requested through the relevant mechanism.
If Rescrito and Aithor do not use personalised advertising at a given time, this category may remain disabled or may not appear in the panel until that purpose is actually introduced.
8.6. SDKs and Technologies Used in Mobile Applications
The iOS and Android applications may incorporate SDKs and third-party components required to provide their features.
Depending on the settings and enabled services, these technologies may be used for:
Authentication.
Application operation.
Synchronisation across devices.
Purchase processing and subscription restoration.
Sending push notifications.
Error and crash diagnostics.
Security and fraud prevention.
Performance measurement.
Usage analytics.
Installation or campaign attribution.
Provision of artificial intelligence features.
These technologies may include services provided by Google Firebase, Apple, Google Play, payment providers, diagnostic tools, and other providers identified in this Policy.
Strictly necessary SDKs may be enabled to provide the requested feature.
SDKs used for non-essential analytics, advertising, advanced attribution, or tracking will remain disabled until the relevant authorisation has been obtained where required.
The User may manage certain permissions and options through:
The Rescrito or Aithor settings.
The privacy panel available within the application.
iOS or Android settings.
Apple or Google privacy options.
Uninstalling the application may remove certain identifiers or locally stored data, but does not necessarily delete the account, data retained on servers, or active subscriptions.
8.7. First-Party and Third-Party Technologies
In addition to their purpose, technologies may be classified according to the entity that manages them:
First-party: installed or managed directly by Chatbot App Limited in order to provide Rescrito or Aithor.
Third-party: installed, managed, or received by external providers involved in a specific feature.
A third-party technology does not in itself constitute a purpose category. A third party may be involved in necessary, analytics, personalisation, diagnostic, or advertising functions.
Where a third party acts on behalf of Chatbot App Limited, it will be subject to the relevant contractual obligations.
Where it determines the purposes and means of certain processing activities itself, it may act as an independent controller, and its own privacy policies will also apply.
The use of external providers and the corresponding international transfers are explained in Section 6 of this Policy.
8.8. Management and Obtaining of Consent
Cookies, SDKs, and similar technologies that are not strictly necessary will remain disabled until the User has given their consent, where such consent is required.
When first accessing the Platforms, the User may be presented with clearly visible options to:
Accept all optional technologies.
Reject all non-essential technologies.
Configure preferences by purpose.
The options to accept and reject will be presented in a clear manner without unjustifiably favouring one decision over the other.
The panel will allow the User to accept or reject separately at least the main available purposes.
The following will not constitute valid consent:
Silence or inactivity.
Mere browsing.
Pre-ticked boxes.
General acceptance of the Terms and Conditions.
The inability to reject optional technologies easily.
Acceptance of the Terms or the Privacy Policy does not imply acceptance of non-essential cookies or technologies.
Chatbot App Limited may retain a technical record of the choice made in order to:
Apply the selected preferences.
Avoid requesting the same decision on every visit.
Demonstrate consent where necessary.
Allow its subsequent modification or withdrawal.
8.9. Modification and Withdrawal of Consent
The User may modify or withdraw consent at any time through the “Cookie Settings”, “Privacy Preferences”, or equivalent mechanism made easily accessible on the Platforms.
Withdrawal must be as easy as giving consent.
When consent is withdrawn:
The relevant optional technologies will cease to be enabled for future use.
Stored cookies or identifiers may be deleted where technically possible.
It may be necessary to follow the external provider’s instructions where it directly manages a technology.
Processing validly carried out before withdrawal will not become unlawful.
The User may also block or delete cookies through their browser settings and manage permissions, identifiers, and storage through their mobile device.
General blocking through the browser or device may also affect necessary technologies and cause certain features not to operate correctly.
8.10. Consent Across Different Domains and Devices
Chatbot App Limited provides services through rescrito.com, aithor.ai, and aithor.io.
Where technically possible and legally appropriate, consent preferences may be synchronised across domains or devices associated with the same account.
Where preferences cannot be synchronised, the User may need to configure their choice separately on each domain, browser, device, or application.
Where a single choice applicable to several domains is requested, the panel will clearly identify:
The domains covered.
The relevant purposes.
The categories of technologies used.
The third parties involved.
Deleting cookies, changing browser, using private mode, reinstalling the application, or using another device may prevent the choice from being recognised and require it to be requested again.
8.11. Duration and Renewal of Preferences
The duration of each cookie, SDK, or identifier will depend on its purpose and configuration.
The following may be used:
Session technologies: deleted or cease to operate when the session, browser, or application is closed.
Persistent technologies: remain for a specified period or until the User deletes them.
Technical identifiers: remain for as long as necessary for the relevant function or until they are renewed, invalidated, or deleted.
Consent preferences may be requested again:
Where a reasonable period has elapsed since the previous choice.
Where the purposes change significantly.
Where relevant new third parties are introduced.
Where applicable law or guidance requires it.
Where the previous choice cannot be retrieved.
8.12. Detailed Information About the Technologies Used
The detailed Cookies Policy or settings panel will identify, where applicable:
The name of the cookie, SDK, or technology.
The responsible entity or provider.
The domain or application in which it is used.
Its purpose.
Its category.
The data processed.
Its duration.
Whether it is first-party or third-party.
Relevant international transfers.
A link to the provider’s information, where appropriate.
The table or inventory must reflect the technologies actually implemented and not merely examples of potential providers.
Chatbot App Limited will update this information whenever it introduces, replaces, or removes tools that materially change the processing.
Where a new technology involves a different purpose or the involvement of a relevant new third party, the User will be asked to make a new choice where necessary.
- Security Measures
Chatbot App Limited implements appropriate technical and organisational measures designed to protect personal data processed through Rescrito and Aithor against destruction, loss, alteration, disclosure, unauthorised access, or any other form of unlawful or accidental processing.
The measures applied are determined by taking into account:
The nature, volume, and sensitivity of the data processed.
The purposes and context of the processing.
The risks to the rights and freedoms of Users.
The state of the art.
Reasonable implementation costs.
The characteristics of the Platforms and the providers used.
Security measures are reviewed and updated periodically where necessary to adapt them to technological changes, new features, identified risks, or legal requirements.
9.1. Security of Communications and Storage
Measures intended to protect the transmission and storage of information may include:
Encryption of data in transit using secure protocols such as HTTPS and TLS.
Encryption of stored data where available and configured within the relevant infrastructure or provider.
Secure management of keys, credentials, technical secrets, and access tokens.
Logical separation between the accounts, projects, and content of different Users.
Controls intended to prevent conversations, documents, files, or memory items from being accessible through unauthorised accounts.
Reduction of the local storage of sensitive information where it is not necessary for the operation of the service.
Secure deletion or overwriting of data in accordance with the applicable procedures and retention periods.
The use of encryption provided by an external service does not mean that all data is protected by the same system or level of encryption at every stage of processing.
9.2. Identification, Authentication, and Access Control
Chatbot App Limited uses identification, authentication, and session-management systems intended to protect accounts and internal systems.
These measures may include:
Authentication systems provided by specialised providers, such as Firebase Authentication or equivalent services.
Verification of email addresses.
Management and expiration of sessions and tokens.
Controls against repeated access attempts.
Termination or revocation of sessions where suspicious activity is detected.
Enhanced authentication for certain internal or administrative access.
Restriction of access according to roles, responsibilities, and operational needs.
Application of the principle of least privilege.
Review and withdrawal of permissions when a person no longer requires them.
Logging of access to administrative systems or particularly protected information.
Authorised personnel and collaborators may access personal data only where necessary to perform their duties, provide support, investigate an incident, protect the Platforms, or comply with a legal obligation.
9.3. Mobile Application Security
Specific measures may be applied within the iOS and Android applications, such as:
Protected storage of authentication tokens using the security mechanisms available in the operating system.
Use of encrypted connections with servers.
Validation of sessions and permissions before allowing access to content.
Restriction of access to the camera, microphone, photographs, videos, or files to the features for which the User has granted permission.
Avoidance of unnecessary local storage of conversations, documents, or sensitive information.
Deletion or invalidation of certain local data when the User signs out, deletes application data, or uninstalls the application.
Detection and analysis of errors, crashes, and anomalous behaviour.
Distribution of updates and security fixes.
Adaptation to security requirements introduced by Apple, Google, or the relevant operating systems.
Application security also depends on the device used by the User, its configuration, installed updates, and the protective measures enabled within the operating system.
9.4. Protection of Conversations and Memory
Conversations, documents, projects, and conversational memory items will be subject to access controls linked to the User’s account.
Where the memory feature is available, measures may be applied to:
Associate memory items only with the relevant account.
Limit their use to authorised features.
Prevent them from being displayed to other Users.
Record relevant changes or deletions.
Allow the User to review, correct, or delete stored information.
Cease using memory items when the feature has been disabled.
Delete or restrict information where requested by the User or where its processing is no longer necessary.
Memory may be managed separately from conversation history. Specific controls will therefore be applied to its review, modification, and deletion.
9.5. Monitoring, Fraud Prevention, and Protection Against Abuse
Chatbot App Limited may use measures intended to detect and prevent:
Unauthorised access.
Identity theft or impersonation attempts.
Abusive account creation.
Automated attacks.
Scraping or unauthorised bulk extraction.
Circumvention of limits, access controls, or payment systems.
Fraudulent transactions.
Malicious use of features.
Introduction of potentially harmful code, files, or content.
Activities that may affect the stability or availability of the Platforms.
These measures may include:
Technical and security logs.
Monitoring of anomalous activity.
Rate and capacity limits.
Automated detection systems.
Temporary blocking of access or requests.
Additional identity or authentication checks.
Restriction of content or accounts.
Cooperation with payment, security, and fraud-prevention providers.
Automated measures may be supplemented by reviews carried out by authorised personnel where necessary and proportionate.
9.6. Development, Maintenance, and Vulnerability Management
Chatbot App Limited applies reasonable procedures intended to maintain the security of its software and infrastructure, which may include:
Reviewing and updating systems, applications, and dependencies.
Remediating known vulnerabilities.
Separating development, testing, and production environments where appropriate.
Limiting the use of real personal data in testing environments.
Reviewing relevant code and configurations.
Protected management of credentials and technical secrets.
Operational and security testing.
Monitoring errors and unexpected behaviour.
Assessing risks before introducing relevant features or providers.
Ending support for obsolete versions that present security risks.
Where a vulnerability is identified, Chatbot App Limited will seek to assess its severity and apply the relevant corrective measures within an appropriate period.
9.7. Backups and Service Continuity
Where necessary, Chatbot App Limited may use backup and recovery systems intended to protect the availability and continuity of the Platforms.
These measures may include:
Periodic backups.
Replication or redundancy of certain resources.
Restoration procedures.
Access controls over backups.
Infrastructure monitoring.
Response plans for interruptions or loss of information.
Backups will be retained according to defined technical cycles and will not be available for the ordinary use of the Platforms.
The existence of a backup does not guarantee that Chatbot App Limited can recover an individual conversation, file, project, or memory item at the User’s request.
9.8. Personnel, Collaborators, and Providers
Persons who may have access to personal data will be subject, as appropriate, to:
Confidentiality commitments.
Internal security instructions.
Access limitations.
Authentication measures.
Contractual obligations.
Appropriate privacy and security training or information.
Procedures for granting, modifying, and withdrawing permissions.
Providers that process data on behalf of Chatbot App Limited will be subject to contractual obligations relating to confidentiality, security, incident notification, and processing in accordance with the applicable instructions.
Before using relevant providers, Chatbot App Limited may assess their security measures, contractual terms, location, certifications, and available safeguards.
A provider’s security certifications or assessments relate to that provider and do not imply that Chatbot App Limited automatically holds the same certification.
9.9. Incident and Personal Data Breach Management
Chatbot App Limited maintains procedures intended to detect, analyse, and respond to incidents that may affect personal data or the operation of the Platforms.
In the event of an incident, it may take measures to:
Identify its origin and scope.
Contain unauthorised access or activity.
Protect affected accounts or systems.
Revoke credentials, sessions, or tokens.
Remediate vulnerabilities.
Recover information or services.
Assess the possible effects on Users.
Document the incident and the measures taken.
Cooperate with providers, experts, or authorities.
Reduce the risk of recurrence.
Where a personal data breach must be notified under applicable law, Chatbot App Limited will notify the competent authority within the relevant statutory period.
Where the breach may result in a high risk to the rights and freedoms of affected individuals, those Users will also be informed where legally required.
Communications may include information about the nature of the incident, its possible consequences, the measures taken, and recommendations intended to reduce further risks.
9.10. User Responsibility for Security
The User must also take reasonable measures to protect their account and data, including:
Using a strong and unique password.
Not sharing passwords, verification codes, or access links.
Protecting the device with a password, passcode, fingerprint, or facial recognition where possible.
Signing out on shared devices.
Keeping the operating system, browser, and application up to date.
Downloading applications only through official channels.
Reviewing sessions and suspicious activity.
Not providing particularly sensitive information where it is not necessary.
Reporting any possible unauthorised access or incident to [email protected].
Chatbot App Limited will never ask the User to provide their complete password, verification codes, or full payment card details by email.
9.11. No Absolute Security
Despite the measures adopted, no computer system, mobile application, cloud service, storage method, or method of transmitting information can guarantee absolute security.
Chatbot App Limited cannot ensure that attacks, human error, unknown vulnerabilities, interruptions, or unlawful access will never occur.
Nevertheless, it is committed to maintaining measures that are reasonable and proportionate to the risk, reviewing their effectiveness, and responding to security incidents in accordance with applicable law.
- Changes to This Policy
Chatbot App Limited may amend this Privacy and Cookies Policy in order to adapt it to changes that are:
Legal, regulatory, or arising from case law.
Corporate or organisational.
Technical, operational, or security-related.
Related to Rescrito, Aithor, or their applications for iOS and Android.
Resulting from the introduction, modification, or withdrawal of features, tools, artificial intelligence models, memory systems, integrations, SDKs, or external providers.
Related to the categories of data processed, the purposes, legal bases, retention periods, or international transfers.
Introduced in purchasing channels, payment systems, or app stores.
The current version will be available on the Platforms and will indicate the date on which it was last updated and, where appropriate, its effective date.
Chatbot App Limited may retain previous versions of the Policy for compliance, transparency, and evidentiary purposes regarding the terms applicable at any given time.
Minor changes, drafting clarifications, and updates that do not materially alter the processing of data may be communicated by publishing the new version on the Platforms.
The list of providers may also be updated where a service is added, replaced, or discontinued, provided that the change does not introduce a substantially different purpose or significantly affect the User’s rights.
Where material changes are introduced that may affect Users’ rights or the way in which their personal data is processed, Chatbot App Limited will provide reasonable advance notice through one or more of the following means:
An email sent to the address associated with the account.
A notification within Rescrito or Aithor.
A prominent notice on the websites.
A notification within the mobile applications.
A message displayed when accessing the affected feature.
Any other appropriate durable medium.
Material changes will include, among others:
The introduction of a new incompatible or significantly different purpose.
The processing of new relevant categories of personal data.
The activation of a new memory or personalisation feature involving different processing.
The use of identifiable data to train models for a purpose other than providing the service.
The introduction of advertising or tracking technologies not previously used.
A relevant change in the way data is shared with third parties.
An international transfer requiring additional information or safeguards.
A significant change to retention periods.
A change that materially affects the exercise of the User’s rights.
Where new processing legally requires the User’s consent, Chatbot App Limited will request separate, specific, and informed authorisation before commencing that processing.
Continued use of the Platforms, acceptance of the Terms and Conditions, or failure to respond to a communication will not replace express consent where such consent is required by applicable law.
Where new cookies, SDKs, or non-essential technologies involving new purposes or relevant providers are introduced, the preferences panel will be updated and a new choice will be requested where appropriate.
If the User does not accept optional processing based on consent, they may reject or disable it without necessarily losing access to the rest of the Platforms, unless that processing is essential to provide the specific feature requested.
Where a change affects an optional feature, such as memory, marketing communications, non-essential analytics, or personalised advertising, the User may manage their preferences through the available controls.
Where a change materially affects a purchased service, the User may stop using the affected feature, cancel their subscription, or request deletion of their account, without prejudice to any rights available to them under applicable law.
Changes to this Policy will not apply retroactively in order to legitimise processing activities that did not have a valid legal basis when they were carried out.
The User is encouraged to review this Policy periodically. However, this recommendation does not replace Chatbot App Limited’s obligation to actively inform Users of material changes where necessary.
- Contact
For any question, enquiry, complaint, or request relating to this Privacy Policy, the processing of your personal data, or the exercise of your rights, you may contact us using the following details:
Email: [email protected]
Data Controller: Chatbot App Limited
Business Registration Number (BRN): 79362831
Registered Office: Hong Kong
Platforms:
rescrito.com
aithor.ai
aithor.io
The Rescrito and Aithor web applications.
The mobile applications for iOS and Android.
Associated extensions, integrations, and services.
You may use this contact channel to request, among other matters:
Information about the processing of your personal data.
The exercise of your data protection rights.
The deletion of your account.
The deletion or export of conversations, documents, and files.
The review, correction, or deletion of information stored in conversational memory.
The withdrawal of consent or modification of your preferences.
The reporting of a possible privacy or security incident.
The submission of a complaint relating to Rescrito or Aithor.
Where the request concerns a specific account, we recommend sending it from the email address associated with that account.
Chatbot App Limited may request additional information that is strictly necessary to verify the applicant’s identity and prevent unauthorised access to, modification of, or deletion of personal data.
Requests will be handled within the time limits established by applicable law.