Back to YourAI
DE YourAI

Privacy Policy

Valid for yourai-app.com · Last updated: September 23, 2026 Beta

1. Data Controller

VGGroup GmbH i.G.
Viktor Gräf
Jörgerstraße 4, 4560 Kirchdorf an der Krems, Austria
info@vggroup.at

2. What Data We Process

Data category Details
Registration data Email address, password (bcrypt-hashed, never stored in plain text)
Profile data Name, personal information the user enters themselves
Chat history Messages are stored for session history
Knowledge files Documents uploaded by the user for the AI knowledge base
Google Calendar OAuth token, calendar entries – only if the user actively connects it
Usage data Selected AI models, features used
Server logs IP address, timestamp, endpoints called

3. Legal Basis

Account and profile data, as well as chat history, are processed under Art. 6(1)(b) GDPR (performance of a contract), since this data is required to provide the service.

Server logs are processed under Art. 6(1)(f) GDPR (legitimate interests) to ensure operation and for error diagnosis.

4. Special Categories of Personal Data (Health Data)

Through the individual profile and category feature, users may voluntarily enter health-related information (e.g. injuries, complaints, training and recovery data in the context of sports activity). This information constitutes special categories of personal data within the meaning of Art. 9 GDPR.

This data is processed exclusively on the basis of the user's explicit consent (Art. 9(2)(a) GDPR), which is given by voluntarily entering this data into the application. Providing health-related data is never a prerequisite for using YourAI's core features.

Technically, this data is treated no differently from other profile data and is stored in the same database environment (see the "Data Controller" and "Processors" sections). Users can have individual health-related entries deleted at any time via the application or by contacting the data controller.

5. Third Parties & Processors

YourAI uses the following service providers to operate:

Provider Purpose & data transmitted
Anthropic PBC, USA AI processing – chat messages are transmitted (Claude models)
OpenAI, USA AI processing – optional, depending on the selected model (incl. image generation via GPT Image)
Google LLC Google Calendar OAuth, image generation (Nano Banana / gemini-2.5-flash-image)
HostYourAI (Doornbos Ventures B.V.), Netherlands AI processing – optional, depending on the selected model (DeepSeek models, hosted on EU infrastructure, no transfer to DeepSeek/China)
ElevenLabs, USA Text-to-speech – text is transmitted for speech synthesis
Supabase Inc., USA Database hosting (server region: Frankfurt, EU)
Hetzner Online GmbH, DE Server hosting (data center in Nuremberg, Germany)

6. Data Shared With OpenAI

YourAI uses the OpenAI API for AI-assisted processing of requests. Your conversation data (inputs and outputs) is not used to train or improve OpenAI's models. The organization-wide "Share inputs and outputs" setting was disabled at OpenAI on September 20, 2026; since then, training on your API data is technically excluded.

OpenAI acts as a processor under Art. 28 GDPR. Data transfers to the USA are based on Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR as well as the EU-US Data Privacy Framework.

For further information on data processing by OpenAI, see the OpenAI Privacy Policy.

Note on the beta phase: Until September 20, 2026, "Share inputs and outputs" was active, meaning conversation data could be shared with OpenAI for model improvement during that period. This setting is now permanently disabled. Should it ever be changed again, we will update this privacy policy in advance and proactively inform existing users.

7. Transfers to Third Countries

The providers Anthropic, OpenAI, and ElevenLabs are based in the USA. Transfers of data to the USA are based on the EU-US Data Privacy Framework as well as – additionally – on Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR.

Supabase operates its database infrastructure in the EU (Frankfurt), so stored data generally does not leave the EU.

Likewise, when DeepSeek models are used, processing takes place through an EU-based provider (HostYourAI, Netherlands) on European infrastructure, so no transfer to a third country occurs.

8. Retention Periods

Data category Retention period
Account data Until deleted by the user or upon request
Chat history Until deleted by the user
Server logs Maximum 14 days, then automatically deleted
Google Calendar token Until you disconnect it in Settings, revoke access directly at Google, or delete your account entirely (see Section 14)

9. Your Rights

As a data subject, you have the following rights under the GDPR:

Access – You can request information about the data we hold about you (Art. 15 GDPR).
Rectification – You have the right to have inaccurate data corrected (Art. 16 GDPR).
Erasure – You can request deletion of your data, provided no retention obligation applies (Art. 17 GDPR).
Restriction – You can request restriction of processing (Art. 18 GDPR).
Objection – You can object to processing based on legitimate interest (Art. 21 GDPR).

Please send requests to: info@vggroup.at – we process requests within 30 days.

10. Deleting Your Account

To delete your account, send a request to info@vggroup.at. We delete your account and all associated data within 14 days, provided no statutory retention obligation applies.

11. Beta Notice

YourAI is currently in beta. Features, data processing procedures, and third-party providers used may change. We will announce material changes to this privacy policy by email or a clear notice within the app.

12. Information on AI Systems (EU AI Act)

YourAI is an AI assistant built on large language models (LLMs) and other third-party AI services (see Section 5). YourAI is not a high-risk AI system within the meaning of EU Regulation 2024/1689 (the "AI Act") and is not used in the sensitive areas regulated therein.

Transparency in direct contact with AI (Art. 50(1) AI Act): You are informed, when chatting and when generating images, voice, or text, that you are interacting with an AI system. This is also highlighted within the application (e.g. through the notice "YourAI can make mistakes").

Labeling of AI-generated content (Art. 50(2) and (4) AI Act): Content created or modified by YourAI — in particular generated images, voice output, and synthetic text — is labeled as artificially generated wherever technically feasible according to the state of the art (e.g. through metadata, in-app notices, or watermarks). This labeling follows the European Commission's guidelines and codes of practice on labeling AI-generated content.

No profiling by the AI: YourAI's AI systems are not used for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

Underlying base models: YourAI is built in particular on AI models from Anthropic (Claude), OpenAI (GPT), Google (Gemini), and DeepSeek. These models are provided by their respective vendors as general-purpose AI models and are subject to the requirements of Chapter V of the AI Act. DeepSeek models are provided via HostYourAI (Netherlands) on EU infrastructure (see Sections 5 and 7). We process your inputs only to the extent required to provide the requested feature (see Sections 5 and 6).

Right to lodge a complaint (Art. 77 GDPR, Art. 85 AI Act): You have the right to lodge a complaint with the competent data protection or market surveillance authority if you have concerns about the processing of your data or the use of AI systems. In Austria, the competent authority is the Datenschutzbehörde (dsb.gv.at).

13. AI Literacy (Art. 4 AI Act)

We ensure that staff who develop, operate, or oversee YourAI have sufficient knowledge of AI systems. This includes, in particular, the risks of AI outputs, possible errors ("hallucinations"), and compliance with data protection and security requirements.

Contact for AI-related matters: For questions about the AI systems used, the labeling of AI-generated content, or your rights under the AI Act, reach us at info@vggroup.at.

14. Google User Data: Purpose, Storage & Sharing

When you connect your Google Calendar to YourAI, you grant access via Google OAuth to the scope https://www.googleapis.com/auth/calendar.events (read and write access to events on your primary calendar). Through this, we process only your calendar entries (title, date, time, duration, description) and the associated OAuth access token.

Purpose: This data is used exclusively to answer calendar-related requests in chat, and to show, create, edit, or delete appointments for you when you ask for that in chat.

Purpose-limited loading: Your calendar data is not loaded for every chat message by default. Before each reply, an automated classification step checks whether your specific message actually relates to your calendar; only then is calendar data included in the request sent to an AI model at all. For messages without a calendar connection, your calendar data is left out entirely.

Retention and deletion: Your calendar entries (titles, times, etc.) are not permanently stored in a database. They are fetched live from the Google Calendar API when needed and cached in our server's memory for a maximum of 15 minutes, after which they are automatically discarded and re-fetched if needed. A server restart (e.g. during a deployment) immediately clears this cache entirely.

The OAuth access token itself (the connection authorization, not calendar content) is stored permanently until it is deleted. We do not apply any automatic expiry to it. You can delete it at any time, without affecting the rest of your account, via Settings → Calendar → "Disconnect" – this only deletes the stored token and its associated cache, never your credits, chats, or any other data. Alternatively, the token is also removed if you delete your entire account (see Section 10).

Independently of that, you can revoke access directly at Google at any time, at myaccount.google.com/permissions. Revoking access there immediately renders our stored token non-functional.

Sharing during AI processing: If your request is answered by an AI model, the calendar data loaded for that one request reaches the model provider selected for it (see Section 5 for the full list). No provider uses this data to train its own models – for details and the full explanation of purpose-limited, training-free processing, see our Google API Limited Use Disclosure.

15. Data Protection Mechanisms for Sensitive Data

To protect sensitive user data, in particular Google OAuth credentials (Calendar tokens), we apply the following measures:

Encryption at rest. OAuth access and refresh tokens are encrypted using symmetric encryption (Fernet/AES) before storage – both in our database and in server-side token caches. Without the server-held encryption key, stored values cannot be read.
Encryption in transit. All traffic between client and server, and between server and database, is transmitted exclusively over HTTPS/TLS.
Access control. Row-Level Security ensures users can only access their own data. Server-side read/write access to stored credentials is restricted to a single, tightly controlled administrative service account.
User-initiated revocation. Users can disconnect the calendar integration at any time directly within the app ("Disconnect" in Calendar settings), or revoke access via their Google Account (myaccount.google.com/permissions).

16. Google API Limited Use Disclosure

YourAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, this means for YourAI:

No training on Google user data. Your Google Calendar data is not used by any of the AI model providers we use to train or improve their own models – not by Anthropic, OpenAI, Google/Gemini itself, or DeepSeek (see the table below).
Only for the requested feature. Calendar data is used exclusively to answer your specific, calendar-related chat request (see Section 14) – for no other purpose, in particular not for advertising, profiling, or disclosure to third parties beyond the processors named in Section 5.
No disclosure to unauthorized third parties. Your calendar data only ever reaches the processors listed in Section 5, never any other third party.

Provider details on the training exclusion:

Provider Training status
Anthropic (Claude) No training on API data (standard policy under the Anthropic Commercial Terms of Service)
OpenAI (GPT) No training – "Share inputs and outputs" disabled since September 20, 2026 (see Section 6)
Google (Gemini) No training – paid API tier active; under Google's own policy, the training exclusion applies to paid usage, provided no separate opt-in feature has been enabled
DeepSeek models (via HostYourAI) No training – processing takes place exclusively via HostYourAI (EU infrastructure), with no transfer to DeepSeek as a company (see Sections 5 and 7)

Questions about this disclosure: Contact us at info@vggroup.at.