Valid for yourai-app.com · Last updated: September 23, 2026 Beta
VGGroup GmbH i.G.
Viktor Gräf
Jörgerstraße 4, 4560 Kirchdorf an der Krems, Austria
info@vggroup.at
| Data category | Details |
|---|---|
| Registration data | Email address, password (bcrypt-hashed, never stored in plain text) |
| Profile data | Name, personal information the user enters themselves |
| Chat history | Messages are stored for session history |
| Knowledge files | Documents uploaded by the user for the AI knowledge base |
| Google Calendar | OAuth token, calendar entries – only if the user actively connects it |
| Usage data | Selected AI models, features used |
| Server logs | IP address, timestamp, endpoints called |
Account and profile data, as well as chat history, are processed under Art. 6(1)(b) GDPR (performance of a contract), since this data is required to provide the service.
Server logs are processed under Art. 6(1)(f) GDPR (legitimate interests) to ensure operation and for error diagnosis.
Through the individual profile and category feature, users may voluntarily enter health-related information (e.g. injuries, complaints, training and recovery data in the context of sports activity). This information constitutes special categories of personal data within the meaning of Art. 9 GDPR.
This data is processed exclusively on the basis of the user's explicit consent (Art. 9(2)(a) GDPR), which is given by voluntarily entering this data into the application. Providing health-related data is never a prerequisite for using YourAI's core features.
Technically, this data is treated no differently from other profile data and is stored in the same database environment (see the "Data Controller" and "Processors" sections). Users can have individual health-related entries deleted at any time via the application or by contacting the data controller.
YourAI uses the following service providers to operate:
| Provider | Purpose & data transmitted |
|---|---|
| Anthropic PBC, USA | AI processing – chat messages are transmitted (Claude models) |
| OpenAI, USA | AI processing – optional, depending on the selected model (incl. image generation via GPT Image) |
| Google LLC | Google Calendar OAuth, image generation (Nano Banana / gemini-2.5-flash-image) |
| HostYourAI (Doornbos Ventures B.V.), Netherlands | AI processing – optional, depending on the selected model (DeepSeek models, hosted on EU infrastructure, no transfer to DeepSeek/China) |
| ElevenLabs, USA | Text-to-speech – text is transmitted for speech synthesis |
| Supabase Inc., USA | Database hosting (server region: Frankfurt, EU) |
| Hetzner Online GmbH, DE | Server hosting (data center in Nuremberg, Germany) |
YourAI uses the OpenAI API for AI-assisted processing of requests. Your conversation data (inputs and outputs) is not used to train or improve OpenAI's models. The organization-wide "Share inputs and outputs" setting was disabled at OpenAI on September 20, 2026; since then, training on your API data is technically excluded.
OpenAI acts as a processor under Art. 28 GDPR. Data transfers to the USA are based on Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR as well as the EU-US Data Privacy Framework.
For further information on data processing by OpenAI, see the OpenAI Privacy Policy.
Note on the beta phase: Until September 20, 2026, "Share inputs and outputs" was active, meaning conversation data could be shared with OpenAI for model improvement during that period. This setting is now permanently disabled. Should it ever be changed again, we will update this privacy policy in advance and proactively inform existing users.
The providers Anthropic, OpenAI, and ElevenLabs are based in the USA. Transfers of data to the USA are based on the EU-US Data Privacy Framework as well as – additionally – on Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR.
Supabase operates its database infrastructure in the EU (Frankfurt), so stored data generally does not leave the EU.
Likewise, when DeepSeek models are used, processing takes place through an EU-based provider (HostYourAI, Netherlands) on European infrastructure, so no transfer to a third country occurs.
| Data category | Retention period |
|---|---|
| Account data | Until deleted by the user or upon request |
| Chat history | Until deleted by the user |
| Server logs | Maximum 14 days, then automatically deleted |
| Google Calendar token | Until you disconnect it in Settings, revoke access directly at Google, or delete your account entirely (see Section 14) |
As a data subject, you have the following rights under the GDPR:
Please send requests to: info@vggroup.at – we process requests within 30 days.
To delete your account, send a request to info@vggroup.at. We delete your account and all associated data within 14 days, provided no statutory retention obligation applies.
YourAI is currently in beta. Features, data processing procedures, and third-party providers used may change. We will announce material changes to this privacy policy by email or a clear notice within the app.
YourAI is an AI assistant built on large language models (LLMs) and other third-party AI services (see Section 5). YourAI is not a high-risk AI system within the meaning of EU Regulation 2024/1689 (the "AI Act") and is not used in the sensitive areas regulated therein.
Transparency in direct contact with AI (Art. 50(1) AI Act): You are informed, when chatting and when generating images, voice, or text, that you are interacting with an AI system. This is also highlighted within the application (e.g. through the notice "YourAI can make mistakes").
Labeling of AI-generated content (Art. 50(2) and (4) AI Act): Content created or modified by YourAI — in particular generated images, voice output, and synthetic text — is labeled as artificially generated wherever technically feasible according to the state of the art (e.g. through metadata, in-app notices, or watermarks). This labeling follows the European Commission's guidelines and codes of practice on labeling AI-generated content.
No profiling by the AI: YourAI's AI systems are not used for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).
Underlying base models: YourAI is built in particular on AI models from Anthropic (Claude), OpenAI (GPT), Google (Gemini), and DeepSeek. These models are provided by their respective vendors as general-purpose AI models and are subject to the requirements of Chapter V of the AI Act. DeepSeek models are provided via HostYourAI (Netherlands) on EU infrastructure (see Sections 5 and 7). We process your inputs only to the extent required to provide the requested feature (see Sections 5 and 6).
Right to lodge a complaint (Art. 77 GDPR, Art. 85 AI Act): You have the right to lodge a complaint with the competent data protection or market surveillance authority if you have concerns about the processing of your data or the use of AI systems. In Austria, the competent authority is the Datenschutzbehörde (dsb.gv.at).
We ensure that staff who develop, operate, or oversee YourAI have sufficient knowledge of AI systems. This includes, in particular, the risks of AI outputs, possible errors ("hallucinations"), and compliance with data protection and security requirements.
Contact for AI-related matters: For questions about the AI systems used, the labeling of AI-generated content, or your rights under the AI Act, reach us at info@vggroup.at.
When you connect your Google Calendar to YourAI, you grant access via Google OAuth to the
scope https://www.googleapis.com/auth/calendar.events (read and write access to events
on your primary calendar). Through
this, we process only your calendar entries (title, date, time, duration, description) and
the associated OAuth access token.
Purpose: This data is used exclusively to answer calendar-related requests in chat, and to show, create, edit, or delete appointments for you when you ask for that in chat.
Purpose-limited loading: Your calendar data is not loaded for every chat message by default. Before each reply, an automated classification step checks whether your specific message actually relates to your calendar; only then is calendar data included in the request sent to an AI model at all. For messages without a calendar connection, your calendar data is left out entirely.
Retention and deletion: Your calendar entries (titles, times, etc.) are not permanently stored in a database. They are fetched live from the Google Calendar API when needed and cached in our server's memory for a maximum of 15 minutes, after which they are automatically discarded and re-fetched if needed. A server restart (e.g. during a deployment) immediately clears this cache entirely.
The OAuth access token itself (the connection authorization, not calendar content) is stored permanently until it is deleted. We do not apply any automatic expiry to it. You can delete it at any time, without affecting the rest of your account, via Settings → Calendar → "Disconnect" – this only deletes the stored token and its associated cache, never your credits, chats, or any other data. Alternatively, the token is also removed if you delete your entire account (see Section 10).
Independently of that, you can revoke access directly at Google at any time, at myaccount.google.com/permissions. Revoking access there immediately renders our stored token non-functional.
Sharing during AI processing: If your request is answered by an AI model, the calendar data loaded for that one request reaches the model provider selected for it (see Section 5 for the full list). No provider uses this data to train its own models – for details and the full explanation of purpose-limited, training-free processing, see our Google API Limited Use Disclosure.
To protect sensitive user data, in particular Google OAuth credentials (Calendar tokens), we apply the following measures:
YourAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, this means for YourAI:
Provider details on the training exclusion:
| Provider | Training status |
|---|---|
| Anthropic (Claude) | No training on API data (standard policy under the Anthropic Commercial Terms of Service) |
| OpenAI (GPT) | No training – "Share inputs and outputs" disabled since September 20, 2026 (see Section 6) |
| Google (Gemini) | No training – paid API tier active; under Google's own policy, the training exclusion applies to paid usage, provided no separate opt-in feature has been enabled |
| DeepSeek models (via HostYourAI) | No training – processing takes place exclusively via HostYourAI (EU infrastructure), with no transfer to DeepSeek as a company (see Sections 5 and 7) |
Questions about this disclosure: Contact us at info@vggroup.at.