Logopeda - Privacy Policy
Last updated: 2026-10-04
Wersja polska · home · Terms of Service · Data Processing Agreement · Account deletion
Privacy Policy
This Privacy Policy explains how Logopeda ("we", "us") collects, uses, stores, and shares data when you use the Logopeda app (domain logopeda.app).
Logopeda is a notebook / CRM and a library of professional educational materials for adult users — speech-language pathologists running their professional practice and parents/guardians. App functions: a library of work areas with material templates (for manual adaptation by the specialist), user-created plans (selecting stages and substages, configuring elements), manual status marking for elements (not started / in progress / completed), exercise sets, sharing status updates with the recipient. Material templates are selected and configured manually by the adult user. The app does not recommend, rank, or select materials automatically. The app is not directed to children as end users — accounts are operated exclusively by adults. Logopeda uses Supabase (Auth, Postgres, Edge Functions), Firebase Cloud Messaging (push), Firebase Crashlytics (crash reporting), Amplitude (product analytics — see section 4), and Resend (authentication and account emails). Online payments for Solo and Pro will use Stripe once enabled. The iOS/Android apps do not include in-app purchases or payment links.
1) Data we collect
Therapists may enter therapy-recipient records, including identity and contact details, notes, form answers, therapy and health information, progress markers, and uploaded files. The therapist determines the purposes and legal bases for this processing.
- User account (therapist or parent/guardian): name, email,
authentication data (including, if the user enables the "Stay signed in after
reinstall" option — a session token stored in the iOS device keychain),
pilot access-entitlement data.
- Therapy-recipient records: profiles, contact details, notes, plans, progress markers, form answers, therapy and health information, and uploaded files.
- Device and usage data: app version, crash logs (Firebase Crashlytics), region settings, pseudonymised product events in Amplitude (e.g., screen opened, section used).
- Support and feedback messages you send us.
2) How we use data
- To authenticate and secure accounts.
- To provide documentation, exercise-library, reminders and workflow features for therapists/parents.
- To render correct UI, language, and notifications.
- To improve reliability, fix bugs, and improve product quality.
- To verify access rights to product features.
- For transactional communication: reminders, confirmations, and account notices.
3) Legal basis
- Jetware Software sp. z o.o. acts as a separate controller for account, security, billing, and its own service analytics data. The legal basis depends on the purpose and may include contract performance, a legal duty, or legitimate interests.
- The therapist determines the legal bases for recipient records, including health data. The therapist assesses the grounds under Articles 6 and 9 GDPR and the related notice duties.
- We send marketing messages based on consent where the law requires it. You can withdraw consent at any time.
4) Sharing and processors
We share personal data only with service providers needed to run the service:
- Supabase (PostgreSQL, Auth, Edge Functions, Storage) - primary host for application data. The production project is in
eu-west-1 (Ireland). Staff access, subprocessors, backups, and transfers follow the agreements and safeguards in the Data Processing Agreement.
- Stripe — planned online payment provider after Solo and Pro sales begin. It is expected to process account, subscription, and transaction data; verify actual payloads before sales.
- Amplitude - product analytics. It processes pseudonymised adult-use events without user-entered content. The operator confirms the production EU project, EU endpoint, and payload review. Therapy records are not sent to Amplitude.
- Firebase Cloud Messaging + Crashlytics (Google LLC) - push notifications and crash reports. The operator confirms review of project settings and payloads; they contain no therapy content. Google says Crashlytics report deletion starts after 90 days. Firebase Installation IDs may remain until deletion is requested; removal from active systems and backups can take up to 180 days.
- Resend - delivers authentication and account emails. It processes their addresses, content, and metadata, but receives no application logs or therapy records. Resend stores customer data in the US. Its published Free, Pro, and Scale terms provide 30-day retention for email and logs, 7-day backup retention, and deletion of remaining customer data within 90 days after account termination. Resend retention is separate from retention of app data.
- Apple App Store / Google Play - distribution of free companion apps and application of the download platform's terms; they do not process Logopeda subscriptions.
We do not sell personal data for advertising. Integration payloads do not contain therapy records. Resend receives no application logs or therapy records.
5) Retention and security
- Account data and user content are retained as long as needed to provide the service and in line with applicable retention rules.
- After an erasure request is confirmed, we delete active records and files within five days. Database backups follow the Pro plan's seven-day recovery window; this is a recovery period, not a guaranteed deletion time for each backup. Newly appointed subprocessors cannot access earlier generations of managed database backups. Records held by a therapist outside the Service remain outside our control.
- The Service uses Supabase. Jetware applies access controls, RLS, encryption in transit and at rest, and the security measures described in the Data Processing Agreement.
- "Stay signed in after reinstall" option (iOS only, off by default).
The mobile app offers an optional feature that stores authentication data
(a session token) in the device keychain in a way that may allow automatic
sign-in after the app is reinstalled. The feature is off by default
and must be explicitly enabled by the user in account settings.
- Platform: this feature applies to iOS devices (iPhone, iPad)
only. On Android, the session is always cleared when the app is uninstalled —
regardless of settings — and the user must sign in again after reinstall.
- Nature of storage: the session token remains in the iOS
keychain after the app is uninstalled. This is a deliberate departure from the
default behaviour, in which uninstalling the app clears authentication data.
Token survival after uninstall on iOS relies on undocumented system behaviour
and is not guaranteed by Apple — Apple may change this behaviour in future OS
versions.
- Disabling the feature and signing out: signing out of the
app (the "Sign out" button in account settings) deletes the stored session token
from the keychain and disables the feature. This is the recommended way to
secure your account before handing over or selling a device. You may also object
to this processing at any time by contacting us at
jetware.software@gmail.com.
- Lost or stolen device risk: if an iOS device is lost or
taken by another person while this feature is enabled, an unauthorised person
may be able to access your account without a password until you remotely
invalidate the session. If your device is lost, we recommend signing out from
another device or contacting us immediately at
jetware.software@gmail.com
so we can invalidate active sessions.
6) Your rights
You can request access, correction, deletion, restriction, or portability of your data; you can object to processing based on legitimate interests. Where consent is the legal basis, you can withdraw consent at any time (withdrawal does not affect processing performed before withdrawal).
Send requests to jetware.software@gmail.com. You can also lodge a complaint with the Polish Data Protection Authority (UODO) or your local supervisory authority. For account deletion - see section 14 or the Account deletion page.
7) App audience and sensitive data
The Service is for adult users. A therapist may keep records about therapy recipients in the Service. These records may contain personal data about children and health data.
- The therapist sets the purposes, scope, and legal bases for the therapist's recipient records.
- Jetware processes those records as a data processor, only on the therapist's documented instructions and under the Data Processing Agreement version DPA-1.0, incorporated into the Terms version TERMS-1.1.
- A parent who uses an account without a linked therapist is not automatically covered by this role split. Jetware is controller for the parent account and content the parent enters for their own purposes without a therapist’s instructions. Do not enter a child's health data in that account until we define the purpose and legal bases for that processing.
- Adults operate accounts. Children cannot create accounts on their own.
- The app does not show ads. Service analytics and diagnostics should not receive therapy records.
Additional Legal Notice
8) Roles and Data Processing Agreement
For data about therapy recipients, guardians, and other people entered by a therapist into the therapist's records, the therapist sets the purposes and legal bases as controller. Under the Data Processing Agreement DPA-1.0, Jetware Software sp. z o.o. stores and makes those data available in the Service as processor, on the therapist's documented instructions.
Jetware acts as a separate controller for account, login, security, billing, and its own service analytics data. Jetware does not use therapy records for its own purposes, such as advertising, profiling, or model training.
The following Jetware duties apply under Data Processing Agreement version DPA-1.0:
- Records may include recipient and guardian identity and contact details, session notes, therapy and health information, form answers, progress, and files entered by the therapist.
- The Data Processing Agreement sets the purpose, term, nature, scope, data categories, and party duties under Article 28 GDPR.
- Jetware assists the therapist with data-subject rights, impact assessments, and security duties as required by Article 28 GDPR.
- Jetware uses subprocessors only under the terms in the Data Processing Agreement and flows down the required duties.
- When the Service ends, Jetware returns or deletes data as the therapist chooses, subject to legal duties and the backup deletion cycle.
9) International transfers
- The primary production Supabase project is in
eu-west-1 (Ireland). Provider roles, backup locations, and staff access are covered by the supplier and security schedule in the Data Processing Agreement.
- Google Firebase, Amplitude, Stripe, and Resend process limited data for their roles. The production Amplitude project and endpoint use the EU region; analytics payloads contain no therapy records. Firebase project settings and FCM and Crashlytics payloads have been reviewed and contain no therapy content. Google says Crashlytics report deletion starts after 90 days. Firebase Installation IDs may remain until deletion is requested and then take up to 180 days to leave active systems and backups.
- Resend processes customer data in the US and uses Standard Contractual Clauses and the applicable transfer mechanism. It receives authentication and account emails only, with no application logs or therapy records. Resend retention follows its published terms and is separate from retention of app data.
10) Required data and automated decisions
- Some data (e.g., login, child identification within the controller's account) is required to provide the service. Without it, core features will not work.
- The Logopeda app is a notebook / CRM and a library of speech-therapy materials for adult users. The app does not make clinical decisions, does not diagnose, does not generate therapy recommendations, and does not perform clinical progress assessment. All clinical decisions, choice of therapeutic materials, plans, and interpretation of progress are made exclusively by a qualified therapist. Logopeda does not perform automated decisions producing legal or similarly significant effects about individuals.
11) EEA / UK / Swiss privacy rights
- Subject to applicable law, you may request access, correction, deletion, restriction, objection, and data portability.
- Where processing is based on consent, you can withdraw it at any time.
- You may lodge a complaint with your local supervisory authority (in Poland: UODO).
12) California notice (CCPA/CPRA)
- California residents may request to know, correct, delete, and obtain a portable copy of personal information, subject to legal exceptions.
- We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
- The app may store health and therapy data entered by a therapist in recipient records. When the final Data Processing Agreement takes effect, Jetware will process these records on the therapist’s documented instructions. Jetware acts as a separate controller for account, security, and service-operation data.
- We do not discriminate against users for exercising privacy rights.
- Rights requests may be submitted by emailing jetware.software@gmail.com.
13) Plans and payments
- Start is free. Solo and Pro have monthly prices. The Terms and the Service before purchase show prices and limits.
- Paid billing needs an enabled payment provider and billing notices. Confirm the billing setup before sales start.
- The iOS/Android apps do not include in-app purchases or payment links.
14) Account and data deletion
To delete your account and associated data, use the in-app flow: Settings → Irreversible zone → Delete account. If you cannot use the app or need help, send a request to jetware.software@gmail.com. The full procedure is on the Account deletion page. After identity confirmation, we start email requests within five days. An in-app request starts after email-code confirmation.
After account deletion is confirmed, we delete active records and files within five days. Database backups follow the Pro plan's seven-day recovery window; this is a recovery period, not a guaranteed deletion time for each backup. Newly appointed subprocessors cannot access earlier generations of managed database backups. Legal duties may require us to retain some data, such as accounting documents or minimum proof of contract acceptance.
15) No AI / generative models
The Logopeda app does not use artificial intelligence or generative models. All content (exercise sets, session templates, plans, notes, progress markers) is entered directly by the user. We do not send user data to any external AI models (OpenAI, Anthropic, Google Gemini, etc.) and we do not use it to train our own models.
If AI-assisted features are added in the future, their scope will be limited to text editing (e.g., language proofreading of notes entered by the therapist) or material search in the exercise library. AI will not select therapy, generate recommendations, or assess progress clinically. Any new AI feature will require an update to this policy and a separate, explicit user consent.
16) Nature of the service and liability limits
Logopeda is a digital tool playing three roles: notebook / CRM (user-entered working notes and progress markers), a library of supporting materials (exercise sets and session templates to choose from), and workflow organisation (reminders, schedules, reports). The app's status under the EU Medical Device Regulation (MDR 2017/745), including rules for medical device software, requires an assessment of its intended purpose. This assessment is not complete.
The app does not diagnose, recommend therapy, assess progress clinically, or optimise the plan. Content entered by the user is their own working notes, exercise sets, session templates, and progress markers. The app does not replace a consultation with a qualified specialist and is not intended for self-treatment. All clinical decisions and the interpretation of data remain within the exclusive competence of the therapist.
17) Contact and complaints
- Privacy requests and legal questions: jetware.software@gmail.com.
- Supervisory authority (PL): Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.