Terapeuta - Privacy Policy
Last updated: 2026-06-29
Wersja polska · home · Terms of Service · Account deletion
Privacy Policy
This Privacy Policy explains how Terapeuta ("we", "us") collects, uses, stores, and shares data when you use the Terapeuta app (domain logopeda.app).
Terapeuta is a notebook / CRM and a library of professional educational materials for adult users — speech-language pathologists running their professional practice and parents/guardians. App functions: a library of work areas with material templates (for manual adaptation by the specialist), user-created plans (selecting stages and substages, configuring elements), manual status marking for elements (not started / in progress / completed), exercise sets, sharing status updates with the recipient. Material templates are selected and configured manually by the adult user. The app does not recommend, rank, or select materials automatically. The app is not directed to children as end users — accounts are operated exclusively by adults. In the production pilot, Terapeuta uses Supabase (Auth, Postgres, Edge Functions), Firebase Cloud Messaging (push), Firebase Crashlytics (crash reporting), and Amplitude (product analytics, EU data center; only for signed-in adult users — see section 4). The iOS/Android apps are free companion apps and do not include in-app purchases, pricing, or payment links.
1) Data we collect
The app does not require users to enter child names, contact details, medical history, or other information directly identifying a child. Users may create exercise sets, session templates, and progress notes. Users are instructed not to enter personal data or health history identifying a child; if internal identification is needed, pseudonyms or anonymous identifiers chosen by the user are recommended.
- User account (therapist or parent/guardian): name, email,
authentication data (including, if the user enables the "Stay signed in after
reinstall" option — a session token stored in the iOS device keychain),
pilot access-entitlement data.
- Content entered by the user: exercise sets, session templates, user-created plans (selected stages and substages, configured elements), progress markers, the user's own working notes.
- Device and usage data: app version, crash logs (Firebase Crashlytics), region settings, pseudonymised product events in Amplitude (e.g., screen opened, section used).
- Support and feedback messages you send us.
2) How we use data
- To authenticate and secure accounts.
- To provide documentation, exercise-library, reminders and workflow features for therapists/parents.
- To render correct UI, language, and notifications.
- To improve reliability, fix bugs, and improve product quality.
- To verify access rights to product features.
- For transactional communication: reminders, confirmations, and account notices.
3) Legal basis
- Processing of account data and user content is based on performance of the service contract (Art. 6(1)(b) GDPR) and our legitimate interests (Art. 6(1)(f) GDPR) - security, fraud prevention, product diagnostics.
- Any marketing communication is based solely on consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time.
- The app does not require or encourage entering special-category data (Art. 9 GDPR, including health data identifying an individual) - see section 7. If the user, contrary to the instruction, enters such data, the user (as the data controller of that data) is responsible for having a valid legal basis under GDPR.
4) Sharing and processors
We share personal data only with service providers needed to run the service:
- Supabase (PostgreSQL, Auth, Edge Functions, EU region - Frankfurt) - primary application data host (user accounts and user-entered content).
- Amplitude (EU data center) - product analytics only for signed-in adult users (pseudonymised identifiers; no user-entered content). This follows from the contractual restriction in the Amplitude DPA Annex I regarding the transfer of special categories of personal data (Art. 9 GDPR).
- Firebase Cloud Messaging + Crashlytics (Google LLC) - push notifications and crash reports. Crashlytics collects technical data (stack trace, device model, OS version) and does not receive user-entered content.
- Apple App Store / Google Play - distribution of free companion apps and application of the download platform's terms; they do not process Terapeuta subscriptions in MVP.
We do not sell personal data for advertising. User content is not transferred to any processor other than Supabase EU.
5) Retention and security
- Account data and user content are retained as long as needed to provide the service and in line with applicable retention rules.
- User content (exercise sets, templates, notes, progress markers) is retained while the user uses the service. On request, it is deleted. If the therapist keeps separate external records (outside Terapeuta), those records remain outside our control.
- We use role-based access (RLS in Postgres), encryption in transit (TLS), and encryption at rest in line with Supabase standards.
- "Stay signed in after reinstall" option (iOS only, off by default).
The mobile app offers an optional feature that stores authentication data
(a session token) in the device keychain in a way that may allow automatic
sign-in after the app is reinstalled. The feature is off by default
and must be explicitly enabled by the user in account settings.
- Platform: this feature applies to iOS devices (iPhone, iPad)
only. On Android, the session is always cleared when the app is uninstalled —
regardless of settings — and the user must sign in again after reinstall.
- Nature of storage: the session token remains in the iOS
keychain after the app is uninstalled. This is a deliberate departure from the
default behaviour, in which uninstalling the app clears authentication data.
Token survival after uninstall on iOS relies on undocumented system behaviour
and is not guaranteed by Apple — Apple may change this behaviour in future OS
versions.
- Disabling the feature and signing out: signing out of the
app (the "Sign out" button in account settings) deletes the stored session token
from the keychain and disables the feature. This is the recommended way to
secure your account before handing over or selling a device. You may also object
to this processing at any time by contacting us at
jetware.software@gmail.com.
- Lost or stolen device risk: if an iOS device is lost or
taken by another person while this feature is enabled, an unauthorised person
may be able to access your account without a password until you remotely
invalidate the session. If your device is lost, we recommend signing out from
another device or contacting us immediately at
jetware.software@gmail.com
so we can invalidate active sessions.
6) Your rights
You can request access, correction, deletion, restriction, or portability of your data; you can object to processing based on legitimate interests. Where consent is the legal basis, you can withdraw consent at any time (withdrawal does not affect processing performed before withdrawal).
Send requests to jetware.software@gmail.com. You can also lodge a complaint with the Polish Data Protection Authority (UODO) or your local supervisory authority. For account deletion - see section 14 or the Account deletion page.
7) App audience and sensitive data
The Terapeuta app is a professional tool for adult users (speech-language pathologists and parents/guardians). It is not directed to children as end users and does not require entering data identifying a child.
- The app does not require users to enter child names, contact details, medical history, or other information directly identifying a child. Users may create exercise sets, session templates, and progress notes. Users are instructed not to enter personal data or health history identifying a child.
- Accounts are operated exclusively by adults (therapist or parent/guardian).
- The app does not display advertising and does not share content for marketing or advertising purposes.
- Product diagnostics and analytics (Amplitude, Crashlytics) are limited to pseudonymised feature-usage metrics and do not cover the content entered by the user.
- The app is not classified in the App Store "Kids" category or in Google Play "Designed for Families".
Additional Legal Notice
8) Data processing terms (under Art. 28 GDPR)
The app stores content entered by the user (exercise sets, session templates, user-created plans, notes, progress markers). The Provider acts as a data processor of this content solely on the user's documented instructions; acceptance of this Policy and the user's choice of in-app features and settings constitute documented instructions.
The app does not require entering personal data of children or special-category data (see section 7). If the user, contrary to the instruction, enters into their content the personal data of third parties (e.g., patients, children), the user is the data controller of that data within the meaning of GDPR and is responsible for: having a valid legal basis, obtaining required consents, handling data-subject rights requests, performing a Data Protection Impact Assessment (DPIA, where required), and maintaining their own record of processing activities.
- The Provider implements the technical and organisational measures required by Art. 32 GDPR (RLS, encryption in transit and at rest, access control, account segregation).
- The Provider's assistance with data-subject rights is provided upon a written user request sent to the contact email, within 30 days.
- The Provider's subprocessors are: Supabase Inc. (data host, EU-Frankfurt), Google LLC (Firebase Cloud Messaging, Crashlytics), Amplitude Inc. (analytics for adult signed-in users only, EU data center). Apple Inc. and Google LLC also operate the distribution platforms for the free companion apps. The Provider will inform the user of any planned change to subprocessors with at least 30 days' notice by updating this policy published at
legal.logopeda.app.
- On user account closure the Provider, at the user's election, returns the content (by request to the contact email) or deletes it, subject to mandatory retention periods required by law.
- The user has the right to audit the processor's compliance - a remote audit (questionnaire + technical documentation) is provided once per year at no additional charge; an on-site or more frequent audit is subject to commercial terms agreed in writing.
For user-account data, login data, access-entitlement data, product diagnostics, and security, the Provider is the data controller.
9) International transfers
- Primary application data is hosted in the EU (Supabase Frankfurt).
- Amplitude hosts project data in its EU data center (Frankfurt). Firebase data (Cloud Messaging, Crashlytics) may be processed in the United States under the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards.
- Apple and Google process data related to downloading and operating the companion apps under their own distribution-platform policies.
10) Required data and automated decisions
- Some data (e.g., login, child identification within the controller's account) is required to provide the service. Without it, core features will not work.
- The Terapeuta app is a notebook / CRM and a library of speech-therapy materials for adult users. The app does not make clinical decisions, does not diagnose, does not generate therapy recommendations, and does not perform clinical progress assessment. All clinical decisions, choice of therapeutic materials, plans, and interpretation of progress are made exclusively by a qualified therapist. Terapeuta does not perform automated decisions producing legal or similarly significant effects about individuals.
11) EEA / UK / Swiss privacy rights
- Subject to applicable law, you may request access, correction, deletion, restriction, objection, and data portability.
- Where processing is based on consent, you can withdraw it at any time.
- You may lodge a complaint with your local supervisory authority (in Poland: UODO).
12) California notice (CCPA/CPRA)
- California residents may request to know, correct, delete, and obtain a portable copy of personal information, subject to legal exceptions.
- We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
- We do not require users to enter sensitive personal information; any such data entered by the user contrary to our guidance is processed only to provide and secure the service the user requests.
- We do not discriminate against users for exercising privacy rights.
- Rights requests may be submitted by emailing jetware.software@gmail.com.
13) Pilot access and no in-app payments
- In the production pilot, therapist access is granted administratively by the Provider. Terapeuta does not yet process payments, invoices, refunds, or paid subscriptions.
- The iOS/Android apps are free companion apps and do not include in-app purchases, subscriptions, pricing screens, upgrade screens, or payment links.
14) Account and data deletion
To delete your account and associated data, you can use the in-app flow: Settings → Irreversible zone → Delete account. If you cannot use the app or need assistance, send a request to jetware.software@gmail.com. The full procedure (identity verification, data scope, billing information) is on the Account deletion page. Email requests are verified and started within 30 days; in-app deletion is performed after successful confirmation with an email code.
When a user account is deleted, content stored in that account is deleted together with the account, unless applicable law (e.g., retention periods for therapy records in a therapist's practice) requires it to be retained longer.
15) No AI / generative models
The Terapeuta app does not use artificial intelligence or generative models. All content (exercise sets, session templates, plans, notes, progress markers) is entered directly by the user. We do not send user data to any external AI models (OpenAI, Anthropic, Google Gemini, etc.) and we do not use it to train our own models.
If AI-assisted features are added in the future, their scope will be limited to text editing (e.g., language proofreading of notes entered by the therapist) or material search in the exercise library. AI will not select therapy, generate recommendations, or assess progress clinically. Any new AI feature will require an update to this policy and a separate, explicit user consent.
16) Nature of the service and liability limits
Terapeuta is a digital tool playing three roles: notebook / CRM (user-entered working notes and progress markers), a library of supporting materials (exercise sets and session templates to choose from), and workflow organisation (reminders, schedules, reports). The app is not a medical device or clinical-use software within the meaning of the EU Medical Device Regulation (MDR 2017/745) or MDSW classification.
The app does not diagnose, recommend therapy, assess progress clinically, or optimise the plan. Content entered by the user is their own working notes, exercise sets, session templates, and progress markers. The app does not replace a consultation with a qualified specialist and is not intended for self-treatment. All clinical decisions and the interpretation of data remain within the exclusive competence of the therapist.
17) Contact and complaints
- Privacy requests and legal questions: jetware.software@gmail.com.
- Supervisory authority (PL): Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.