Privacy Policy

Last Updated: March 2026

1. Introduction

Welcome to Sidekick. This Privacy Policy explains how we collect, use, store, and protect information when you use Sidekick mobile application. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

We may collect the following types of information:

  • 2.1 Account Information: When you create an account, we collect your email address, name, and a securely hashed password. This information is used strictly to identify you and secure your access to the Service.

  • 2.2 User Content: When you interact with the chatbot we may collect messages you send, prompts or queries you submit, and generated responses.

    Data Storage Notice: All conversations and messages are stored in our encrypted database in the AWS EU Frankfurt Region. For safety and abuse monitoring, prompts shared with OpenAI are retained by them for up to 30 days unless legally required otherwise.

  • 2.3 Usage and Technical Data: We automatically collect essential technical information to ensure the app works correctly. This includes your device type, operating system version, and IP address. To provide push notifications, we collect a unique device token via Google Firebase. In the event of an error, we also collect crash logs to help us diagnose and fix technical issues.

3. How We Use Information

Our legal basis for processing your information includes: (a) Contractual Necessity to provide the Service; (b) Legal Obligation (e.g., tax/compliance); and (c) Legitimate Interests in improving our AI and maintaining security. We use the collected information for the following purposes:

  • To provide and maintain our AI chatbot service

  • To provide customer support and respond to your requests

  • To monitor the usage of our Service and detect technical issues

  • To prevent fraud, abuse, and ensure the security of our platform

AI Training & Data Usage:

Premium Users: Your conversation data is not shared with our AI provider (OpenAI) for model training purposes.

Free Users: To provide the service at no cost, your conversation data may be shared with our AI provider (OpenAI) to improve their services, including the improving and training of their models.

4. Third-Party Services

To provide the Service, we share certain information with trusted third-party providers:

These third parties process your data according to their own privacy policies. We do not sell your personal data to any third parties.

5. International Data Transfers

The Service is available worldwide. Because we use providers like OpenAI and Google Firebase, your information may be transferred to and processed in the United States. To ensure your data remains protected, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. You can view the specific data processing agreements below:

  • OpenAI Data Processing Addendum
  • Supabase DPA
  • Hetzner Data Protection
  • Vercel DPA
  • Google Firebase SCCs
  • Better Stack Security & DPA

6. Data Storage and Security

We implement reasonable security measures to protect user information. Data will be stored on servers located in EU. We take appropriate technical and organizational measures to protect personal data from unauthorized access.

7. Data Retention

We retain personal data only as long as necessary to provide the service, comply with legal obligations, or resolve disputes. We store raw user information for as long as the user has an account in Sidekick. Partial usage data and technical logs tied to user's activity could remain in our systems for longer period, for example Telemetry & Usage data or abuse monitoring. We provide the ability for the users to delete their account, which will result in the deletion of their complete profile data from our database.

8. Your Privacy Rights

We provide all users with the ability to access, correct, or delete their personal data. Depending on your location, you may also have the right to request restriction of processing or data portability where applicable.

These rights are provided in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users located in the European Economic Area.

You have the right to lodge a complaint with the data protection authority of the EU/EEA member state you are residing.

AI Processing Notice: To provide the service at no cost, your conversation data may be shared with our AI provider (OpenAI) to improve their services, including the improving and training of their models.

If you prefer not to have your data processed through these providers, you may choose a different account type (where data-sharing is disabled) or discontinue use of the service and request account deletion.

To exercise any of these rights, please contact us at: support@sidekick-ai.app.

9. Children's Privacy

The Service is not intended for individuals under the age of 14. We do not knowingly collect personal data from children under 14. If we become aware that a child under 14 has provided personal data without parental consent, we will take steps to delete such information immediately.

10. Account Deletion

Users may request deletion of their account and associated data by using the Delete Account option in the app or contacting us at support@sidekick-ai.app.

11. Changes to This Policy

We may update this policy periodically. Significant changes will be notified via the app or website.

12. Contact

Email: support@sidekick-ai.app

Company: Boris Veselinov Georgiev

For privacy-related inquiries, you may contact our Privacy Lead at support@sidekick-ai.app.

If you have questions regarding these documents, please contact our support team.