Texto legal en inglés
This version is still under legal review
The text is complete and in force. Version 1.0.2 is in final review by our counsel; changes will be published here with a new revision date.
Questions about this are answered at legal@screensolve.app.
Privacy Policy
Version: 1.0.2 · Last updated: 2026-08-27
1. Controller
Veqra GmbH
Bohnackerweg 2, 2545 Selzach, Schweiz
E-mail: hello@screensolve.app
Privacy contact: legal@screensolve.app
2. EU & UK Representatives
As a Swiss-based controller processing personal data of EU residents, we have appointed an EU representative pursuant to Art. 27 GDPR:
The EU representative under Art. 27 GDPR is being appointed. Until publication, EU residents can reach us directly for all data-protection matters at legal@screensolve.app.
For UK residents, our UK representative pursuant to Art. 27 UK GDPR:
The UK representative under Art. 27 UK GDPR is being appointed. Until publication, UK residents can reach us directly at legal@screensolve.app.
3. Categories of data, purposes, legal bases
3.1 Account & Login
Email address, optional name, locale preference, country (optional).
Purpose: creation and maintenance of your user account, sign-in via Magic-Link or OAuth (Google/Apple).
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.2 Subscription & billing
Email, billing address (collected by Stripe), Stripe customer/subscription IDs, tier, period dates, cancellation status.
Legal basis: Art. 6(1)(b) + (c) GDPR (contract performance + tax/invoicing duties under Swiss MwStG / EU VAT directives)
Card data: never seen by us. Stripe handles PCI-DSS scope. We only store tokenized references.
3.3 AI features
Screenshots (transient), OCR text, prompts, AI-generated answers, token usage.
Purpose: providing the solver/explain/lecture/digest features. Screenshots are processed in-memory and not persisted server-side. AI-providers may temporarily process the prompt + response for the duration of the API call.
Legal basis: Art. 6(1)(b) GDPR.
EU AI Act Art. 50 transparency: AI-generated outputs are clearly marked. We do NOT operate predictive-grading or other Annex III §3 high-risk systems.
3.4 Device registration
Hashed hardware fingerprint (SHA-256, salted with account ID), device name, platform, last-seen timestamp.
Purpose: license enforcement, multi-device sync, anti-fraud.
Legal basis: Art. 6(1)(b) + (f) GDPR (contract + legitimate interest in license-protection).
3.5 Audit log
Account ID, action (login, subscription change, etc.), timestamp, hashed IP (per-day-salted), truncated user agent. No PII (no plain emails, no plain IPs, no payment data).
Legal basis: Art. 6(1)(c) + (f) GDPR (legal retention obligations + legitimate security interest).
Retention: 7 years for billing-related events (Swiss CO Art. 957a / German HGB). Login events: 12 months.
3.6 Transactional emails
Email address (recipient), email body (Magic-Link, invitation, deletion confirmation).
Legal basis: Art. 6(1)(b) GDPR.
We do not send marketing emails without explicit opt-in (CAN-SPAM-equivalent / German UWG §7).
3.7 Error tracking & logs
Stack traces, app version, OS, anonymized error messages — sent to Sentry. No PII (no email, no license key).
Legal basis: Art. 6(1)(f) GDPR.
3.8 Cookies & local storage
Strictly necessary (sign-in session, locale preference, consent state) — no consent required (ePrivacy-exempt).
Optional (analytics): currently NOT used. If introduced later, we will request explicit opt-in via the cookie banner. Reject = strictly-necessary-only.
3.9 Free-Tier abuse protection
We process a pseudonymised hardware fingerprint of your device (HMAC-SHA256 hash with server-side pepper, no raw data) to prevent free-tier abuse via account-cycling. The server stores only the 64-hex-character hash; raw values (machine_uuid, boot_disk_uuid, cpu_serial) NEVER leave the device.
Purpose: detection when 5+ free accounts share the same device hash within 30 days → manual operator review. Without this measure free-tier costs would be infinitely exploitable via automation.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the economic viability of the service). LIA documentation available on request.
Retention: 180 days after last activity (automatic DELETE via pg_cron). Pepper rotation: every 12 months (after rotation new hashes do not match old ones — auto-forget). You may object to processing under Art. 21 GDPR — consequence: the free-tier account is suspended or must upgrade to a paid tier (where this fingerprint is not required).
4. Recipients & subprocessors
We engage the following processors under Art. 28 GDPR. All have signed DPAs in place:
| Processor | Purpose | Region | DPA |
|---|---|---|---|
| Supabase | Database, Auth, Storage | EU (Frankfurt) + US Backups | DPA |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payment processing, invoicing, tax determination | EU (IE) + US | DPA |
| Vercel Inc. | Web dashboard hosting, static content delivery | Global Edge | DPA |
| Resend | Transactional email delivery (login links, invitations) | US | DPA |
| Google Cloud (Gemini API) | AI model provider for solver functions | Global | DPA |
| Anthropic PBC (Claude API) | AI model provider for verification (Second-Opinion) | US | DPA |
| Functional Software, Inc. (Sentry) | Error tracking + performance monitoring | US | DPA |
| Cloudflare, Inc. | CDN, DDoS protection, DNS | Global Edge | DPA |
Updated subprocessor list and material changes: see subprocessors page.
5. International data transfers
Several processors are based in the United States. Transfers occur on the following legal bases:
- EU-US Data Privacy Framework (DPF) — Stripe, Vercel, Resend, Google Cloud, Anthropic, Sentry, Cloudflare are DPF-certified.
- Standard Contractual Clauses (SCC, Module 2 — Controller-to-Processor) for any transfer not covered by DPF.
- For Switzerland: Swiss-US DPF + revFADP-conformant TIA (Transfer Impact Assessment).
6. Retention periods
- Account data: for the duration of your account + 7-day soft-delete recovery window after deletion.
- Subscription/billing: 10 years (Swiss CO Art. 958f) / German HGB §257).
- Audit log (billing-related): 7 years.
- Audit log (security): 12 months.
- Devices (revoked): 30 days, then deleted.
- Email content: not retained server-side after delivery (Resend log: 14 days).
7. Your rights
Under GDPR Art. 15-22 and revFADP Art. 25-26 you have the right to:
- Access (Art. 15) — see what we hold about you
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Data portability (Art. 20) — machine-readable export
- Object (Art. 21)
- Withdraw consent (Art. 7(3)) — does not affect prior processing
Self-service: /dashboard/privacy (Export + Delete) · or write to legal@screensolve.app.
Right to lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). In the EU: with your local DPA. The list is at edpb.europa.eu.
8. Automated decisions
We do NOT make decisions producing legal or similarly significant effects on you based solely on automated processing (Art. 22 GDPR). AI-generated content is delivered for your review; you remain in control.
9. Minors
Use of ScreenSolve requires the applicable digital-consent age in the user's country. For EU/EEA markets we use a versioned country table reviewed against national implementation of GDPR Art. 8 and require re-review by the competent national DPA; the range is 13–16. The Swiss revFADP has no equivalent fixed threshold, and Turkey has no approved threshold in our current release policy, so external-provider eligibility for both markets remains blocked pending written DPO approval. Younger users require parental/guardian consent. Schools using ScreenSolve in classroom settings act as the controller for student data; we are processor.
Provider-specific guardian consent is scoped to one named provider, operation, policy version, and processing region. The verification request states the purpose and data category before confirmation. Verified evidence is valid for at most 90 days and can be revoked for future use. The one-time token is stored only as a SHA-256 digest; the guardian email is kept in an isolated private contact store and deleted after 24 hours. The account holder can revoke in account settings; a guardian can request revocation at legal@screensolve.app. No external-provider route is released for minors until its exact policy and contract evidence have been approved.
10. Security measures
- TLS 1.3 for all data in transit; HSTS preload.
- AES-256-GCM at rest (Supabase database + storage encryption).
- Argon2id password hashing (where applicable). Magic-Link / OAuth preferred.
- Row-Level Security (PostgreSQL RLS) on all user-data tables.
- Refresh-token reuse-detection — token-family revocation on detected reuse.
- Per-license HMAC keys for desktop API auth.
- Idempotency-keys on all Stripe writes; webhook signature verification.
- Audit-log table append-only enforced via PostgreSQL triggers.
- PII redaction: no plain emails/IPs/license-keys in audit log.
- Defense-in-depth: 23-key PII-strip on audit metadata; SHA-256 IP-hash with per-day-salt.
Pentest scheduled pre-launch (Cure53 / Bishop Fox class).
11. Switzerland-specific (revFADP)
Under the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023), Swiss residents have additional rights:
- Art. 25 — Right of access (information about processing).
- Art. 32 — Right to data portability (matches GDPR Art. 20).
- EDÖB notification: as Swiss-based controller, we may be subject to mandatory breach reporting (Art. 24 revFADP) within 72 hours.
12. Cookie & consent management
We use only strictly-necessary cookies/local-storage at this time (sign-in session, locale, consent state). No analytics, no marketing trackers. The cookie banner reflects this and provides Accept all / Reject all with equivalent prominence (CNIL TARTE-conform).
13. Changes to this policy
We will notify users of material changes via email and an in-app banner. Continued use after the effective date constitutes acceptance. Past versions are archived; we publish a changelog.