Last updated: 2026-09-10
This policy explains how Sourcebound collects and uses personal data when you read reports, ask questions, create an account, or buy credits.
catnimitz, a sole trader registered in Poland (CEIDG, NIP [OPERATOR_NIP], REGON [OPERATOR_REGON]), address [OPERATOR_ADDRESS], is the data controller for personal data processed through Sourcebound (https://sedesmaximus.com). Contact for privacy matters: hello@sedesmaximus.com. We have not appointed a Data Protection Officer; this is reviewed periodically as the Service grows. <!-- e.g. "We are not required to appoint a Data Protection Officer under Art. 37 GDPR given our scale, but we review this periodically." -->
For purchases, Polar acts as an independent controller of the data needed to process your payment (see Section 4).
| Data | Examples | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account data | Email, password hash (hashed by Supabase Auth), sign-up date | Create/manage your account, authenticate you | Contract (Art. 6(1)(b)) |
| Authentication logs | Login timestamps, IP address, device/browser info, 2FA status | Security, fraud/abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Visitor identifier | IP-derived hash, allowance cookies | Enforce the 2 free anonymous answers, prevent abuse | Legitimate interest (Art. 6(1)(f)) |
| Questions & selected fragments | The text you highlight and the question you ask | Generate your answer, improve the Corpus and research queue | Contract (Art. 6(1)(b)); legitimate interest for queue/quality analysis (Art. 6(1)(f)) |
| Generated answers & feedback | AI-generated answer text, your rating/feedback, refund requests | Deliver the answer, process refund requests, improve accuracy | Contract; legitimate interest |
| Credit ledger | Credits purchased, spent, refunded, balance | Operate the credit system | Contract |
| Purchase records | Order ID, product, amount, currency, date (no card numbers — these are handled solely by Polar) | Accounting, tax records, customer support | Contract; legal obligation (Art. 6(1)(c)) for tax/accounting retention |
| Cookies (strictly necessary only) | Session, CSRF, visitor-allowance cookies | Keep the Service secure and functional | Legitimate interest / not subject to consent under Art. 6(1)(f) and the Polish Telecommunications Law equivalent of the ePrivacy Directive, since these are strictly necessary |
We do not use advertising cookies or third-party tracking. Our on-site usage analytics (Vercel Web Analytics) is cookieless and does not identify you — see Section 7.
We only ask for consent (Art. 6(1)(a)) where a legal basis above doesn't apply — for example, an optional marketing newsletter, if we offer one in future; you can withdraw consent at any time.
When you ask a question, the question text and relevant excerpts retrieved from our Corpus are sent to Anthropic's Claude API to generate an answer. See our AI Disclosure page for what this does and does not involve. Anthropic processes this data as our processor under a data processing agreement; per Anthropic's commercial API terms, this data is not used to train Anthropic's models.
| Recipient | Role | What it processes | Location | Transfer safeguard |
|---|---|---|---|---|
| Vercel Inc. | Hosting, cookieless web analytics | Site delivery, traffic logs, anonymised analytics | EU region (Frankfurt/Ireland, configurable); Vercel Inc. is a US company | EU-U.S. Data Privacy Framework certification, plus Standard Contractual Clauses (Art. 46(2)(c) GDPR) — verify current DPF certification status and DPA terms at time of launch |
| Supabase Inc. | Database, authentication | Account data, auth logs, credit ledger, questions, answers | EU region — Frankfurt (eu-central-1); Supabase Inc. is a US company, infrastructure via AWS | Data Processing Agreement incorporating Standard Contractual Clauses; EU region selection reduces but does not eliminate cross-border exposure (support access, backups) — verify Supabase's current DPA/SCC coverage and any DPF status |
| Anthropic, PBC | AI answer generation | Question text, selected fragment, retrieved Corpus excerpts | United States | Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework — verify Anthropic's current DPF certification status and DPA terms for API/commercial customers at time of launch |
| Polar Software Inc. | Payments, Merchant of Record | Purchase amount, product, order ID, billing details, payment method (Polar is an independent controller for this data, not our processor) | EU/US as per Polar's own infrastructure | Governed by Polar's own privacy notice; see polar.sh/legal/privacy |
| Resend | Transactional email (magic links, receipts, notifications) | Email address, email content | Processing in the US | Standard Contractual Clauses; Resend holds EU-U.S. DPF certification — verify current certification scope |
We do not sell personal data, and we do not share it with data brokers or advertisers.
| Data | Retention |
|---|---|
| Account data | While your account is active, plus 12 months after closure (in case of disputes/fraud), then deleted or anonymised |
| Auth/security logs | 12 months, then deleted |
| Visitor identifier / allowance cookies | Up to 12 months from last use |
| Questions, fragments, answers, feedback tied to an account | While your account is active, plus 24 months, then anonymised for research-queue and quality purposes |
| Anonymous-visitor questions and answers | Anonymised or deleted after 12 months |
| Credit ledger and purchase records | 5 years from the end of the calendar year of the transaction, to meet Polish tax/accounting record-keeping obligations |
| Data related to an open legal claim or dispute | Until the matter is resolved, plus applicable limitation period |
These periods are our current proposal and should be reviewed against final Polish accounting/tax retention rules before launch.
Under the GDPR, if you are in the EU/EEA (and under equivalent UK GDPR rights if you are in the UK), you have the right to:
To exercise any of these rights, email hello@sedesmaximus.com. We will respond within one month as required by Art. 12(3) GDPR.
We use only strictly necessary cookies (session, CSRF protection, and the anonymous-visitor free-answer counter) and Vercel's cookieless Web Analytics, which does not use cookies or collect data that identifies you and cannot track you across days or sites. Because we use no non-essential cookies and no advertising/tracking cookies, we do not show a cookie-consent banner — see our Cookie Notice for details and for when this would change.
The Service is not directed at children. Creating an account and making purchases requires you to be at least 18 years old (or the age of legal majority in your jurisdiction, if higher). We do not knowingly collect personal data from children; if you believe a child has provided us data, contact hello@sedesmaximus.com and we will delete it.
Answers to your questions are generated automatically by an AI system, but this does not produce legal effects or otherwise significantly affect you within the meaning of Art. 22 GDPR — it is information output, not a decision about you (e.g. it does not determine eligibility, pricing personalised to you, or account status). We do not use automated profiling to make decisions with legal or similarly significant effects about you. If this changes, we will update this policy and provide the safeguards Art. 22 GDPR requires.
Where our processors are located outside the EEA/UK (notably Anthropic and, for backend infrastructure, Vercel and Supabase in the US), we rely on the EU Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework certification, as available, as our transfer mechanism, per Section 4. We will keep this list current and will update it before adding or changing any processor with cross-border impact.
We may update this policy from time to time; the "Last updated" date at the top reflects the latest version. For material changes we will make reasonable efforts to notify registered users.
catnimitz, [OPERATOR_ADDRESS] — hello@sedesmaximus.com.