Privacy Policy
English version of the Pivona privacy policy. The Ukrainian text at pivona.io/polityka-konfidentsiynosti is the legally binding one; this page is provided for international users and reviewers.
This Policy explains which personal data the Pivona service processes, for what purpose, on what basis, and how it is protected. It forms an integral part of the Public Offer Agreement.
Data controller: Sole Proprietor Kyslenko Anastasiia Dmytrivna, contact: [email protected].
Processing is carried out in accordance with the Law of Ukraine “On Personal Data Protection” No. 2297-VI and, for users in the EU, with regard to GDPR principles.
1. Data we process
1.1. Registration data (provided by you): name, email address, Telegram handle (optional), specialisation / field of activity.
1.2. Content data you enter into the Service: information about your clients, leads, projects, commercial proposals, notes, tasks, and financial metrics of your activity. You enter this data yourself and remain its owner; with regard to your clients’ personal data, you act as an independent controller, while the Contractor acts as a processor on your instructions within the scope of this Agreement.
1.3. Payment data: processed by the payment system (Monobank). The Contractor does not store full card details — only an anonymised token and payment status.
1.4. Technical data: IP address, device and browser type, activity logs, cookies — for the operation, security and diagnostics of the Service.
1.5. Particularly sensitive planner data. The Service includes features that work with your personal state (mood, energy level, cycle). This data is used exclusively within your account for the planner to work, and is NOT passed to external analytics, not used for advertising, and not shared with third parties. (A zero-analytics principle for personal data.)
2. Purpose and legal basis
Providing the service under our terms, processing payments, support, security, product improvement and — with consent — marketing communication.
| Purpose | Legal basis |
|---|---|
| Providing access to the Service, operation of its features | Performance of the contract (the Offer) |
| Processing payments and issuing receipts | Performance of the contract + legal requirements |
| Support, communication about the service | Performance of the contract |
| Security, prevention of abuse | Legitimate interest of the Contractor |
| Improving the Service (anonymised statistics) | Legitimate interest / consent |
| Marketing communications (where applicable) | User consent (may be withdrawn at any time) |
3. Third parties (sub-processors)
The Contractor does not sell personal data. For the Service to operate, data may be processed by the following service providers:
| Provider | Purpose | Location of processing |
|---|---|---|
| Monobank (JSC Universal Bank) | Payment acceptance, recurring payments | Ukraine |
Hosting provider Hetzner Online GmbH, Germany |
Hosting of servers and data | EU (Germany) |
| OpenAI | Processing of text for AI features | USA |
| DeepSeek | Processing of text for AI features | PRC |
| Microsoft (Clarity) | Heatmaps and anonymised recordings of user interaction — only on the pivona.io website, the sign-in/registration pages and in the demo cabinet. Does not run in the app | USA |
| Meta Platforms Ireland Ltd. | Advertising measurement and remarketing: which ads lead to the site, to completing the test and to creating an account. No advertising scripts run in the app | EU (Ireland), with transfer to the USA |
| Telegram (Telegram Messenger Inc.) | Notifications about submissions from the contact form on the website: name, contact details, subject and message text, referral source and the page it was sent from. No data from your account in the app is shared | The group of companies is registered in the British Virgin Islands and the UAE; under Telegram’s policy, data of users from Europe is stored in data centres in the Netherlands |
Email / mailing service Resend |
Transactional emails, receipts | USA |
3.1. AI features and text transfer. In the Service’s interface, AI features are presented under the name Pivi — the mascot of the AI assistant, not a separate technology: everything Pivi does is performed by the providers’ models listed in the table above. When you use AI features (generating commercial proposals, client analysis, suggestions, etc.), the relevant text (which may include data you have entered) is sent to the chosen AI provider to process the request. Providers treat the data sent to them differently: under its current API terms, OpenAI does not use this data to train its models; DeepSeek uses the text the Service currently sends it to train its models. For this reason, the Service routes data automatically: sensitive text — your correspondence with clients and leads, uploaded materials, analysis of correspondence — is never sent to DeepSeek at all and is processed only by OpenAI; whatever does go to DeepSeek is de-identified before sending (client names, companies and websites from your database are replaced with labels, and phone numbers, emails and other details in free text are caught by pattern matching), and the response comes back with the real data. De-identification is imperfect: a name in an inflected form or a number written out in words may slip through, and whatever slips through to DeepSeek is used to train its models and is stored in the PRC, from where the Service cannot recall or delete it. Data of clients and leads you have marked confidential is not sent to AI features at all. You cannot limit processing to OpenAI only: routing is decided by the Service. Regardless of this, you should bear in mind the nature of this transfer and not enter data into AI requests that you cannot share with third parties.
3.2. Cross-border transfer. Some of the providers listed in the table above are located outside Ukraine and the EU: in the USA (OpenAI, Resend, Microsoft Clarity) and in the PRC (DeepSeek). Data transferred to the PRC is stored and processed there under PRC law, which allows state authorities to request access lawfully under that law; this law does not provide the guarantees customary under Ukrainian or EU legislation. By using AI features, you consent to the storage and processing of transferred text in these countries under their law (for the PRC — including possible access by state authorities) and to the use of text sent to DeepSeek for training its models. The Service cannot guarantee deletion of transferred text by AI providers, in particular by DeepSeek and in the PRC. You may choose not to use AI features: they are triggered only by your direct action (clicking the generate button, starting Unpack) or by automations you have enabled, and do not process your data without such action or consent. The Service does not currently offer a separate option to “turn off AI permanently” or to “process in the EU only”.
3.3. Advertising measurement. The Service buys advertising on Instagram and Facebook, so it needs to know which ads bring people in. For this, Meta’s advertising tool runs on the marketing site pivona.io and in the demo cabinet demo.pivona.io. It records the fact of an action on the page — opening the site, starting and finishing the test, clicking the sign-up button — and does not read the content of form fields or know your name or email. The Service also sends the same events to Meta from its own server, so that one action is not counted twice.
In the app, app.pivona.io, Meta’s advertising script never loads. The only thing that goes to Meta from the app is one server-side message — “account created” — at the moment of registration: IP address, browser type, and the advertising cookies _fbp/_fbc, if they were set earlier on pivona.io. It contains none of your name, email, phone number or any data from your cabinet — including your clients’ data — in any form. The purpose is twofold: to see which ads lead to sign-up, and to avoid showing ads to people who have already registered. For visitors from the EEA, the UK and Switzerland without stored consent, it is not sent at all.
Meta Platforms Ireland Ltd. acts as an independent controller of this data under its own terms and may transfer it to the USA.
4. Storage and deletion
4.1. Retention. Data is kept while your account exists and for as long as necessary for the purposes stated in this Policy, or to comply with legal requirements (including tax requirements — regarding payment documents).
4.2. Account deletion. You can delete your account at any time. After deletion, personal data is deleted or anonymised within 30 days, except data the Contractor is required to retain by law (accounting/tax documents).
4.3. Backups. Technical backups of the Service may contain personal data for up to a further 30 days after it has been deleted from the main system — until the relevant backup is automatically destroyed. Deleted accounts are not restored from backups: if the Service is restored from a backup, data of deleted users is deleted from it again.
5. Your rights
Access, rectification, deletion, withdrawal of consent, and the right to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights, and, for users in the European Economic Area, also with the personal data protection supervisory authority of the country of their residence, place of work, or place of the alleged infringement. Contact: [email protected].
6. Cookies
Cookies required for authentication and interface operation, and — with consent — anonymised product analytics.
7. Security
TLS encryption, access separation, data isolation between accounts, secrets stored outside the client side. No system guarantees absolute security. In case of an incident that threatens users’ rights, we notify each affected user no later than 72 hours after we learn of the incident: what happened, which data was affected and what measures were taken. We accept vulnerability reports at [email protected] and reply within two business days; we do not take action against researchers who report an issue in good faith and privately. More on security: the “Data security” page.
8. Google Calendar data
8.1. What we receive. If you connect Google Calendar, Pivona receives through the Google Calendar API: busy intervals (freebusy), and the start time, duration and titles of events from the selected calendar. Access is limited to two scopes: calendar.freebusy (view availability) and calendar.events (view and edit events). We do not request permission to create or delete calendars themselves.
8.2. Why. The planner subtracts meeting time from your daily capacity and shows you which meetings consumed it — otherwise the missing hours cannot be verified. On your explicit action (“Send to calendar”) Pivona creates events in your calendar for scheduled tasks.
8.3. Storage. Access tokens are stored encrypted on our servers and bound to your account. Calendar events themselves are not stored: they are fetched while building the plan and held in memory for no longer than 60 seconds.
8.4. Sharing. Google Calendar data is not shared with third parties, not used for advertising, and not sent to AI services (OpenAI, DeepSeek). Event titles, times and attendees are never included in AI requests: those contain only your own tasks and the resulting number of free hours in a day that meetings affected.
8.4.1. Artificial intelligence and model training. Data obtained through Google Workspace APIs, including Google Calendar, is not used to develop, train or improve artificial intelligence or machine learning models, whether our own or those of third parties. This applies both to the data itself and to any derivatives of it.
8.5. Revoking access. You can revoke access at any time — in Pivona (Profile → Integrations → Disconnect) or in your Google Account settings. Stored tokens are deleted on revocation.
8.6. Pivona’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Freelancehunt data
9.1. What it is. You can connect your Freelancehunt account with a personal API token that you create yourself at freelancehunt.com/my/api and paste into Pivona. This is an unofficial integration: Freelancehunt has not approved it and does not grant third-party services any “approved” status, and according to Freelancehunt support’s reply of 9 September 2026, the platform does not support its public API. The integration may stop working at any time; we do not guarantee that it will work in the future.
9.2. Two access modes. When connecting, you choose a mode yourself: there is no default, and the token is not saved until you do.
- “Projects only” — Pivona reads your profile and the public project feed to score projects and prepare draft proposals. It does not read or store your conversations with clients.
- “Projects + messages” — in addition, Pivona reads your project threads so that new conversations become leads in your CRM, shows them in the app and stores copies of them in your account.
You can change the mode at any time (Profile → Integrations). When you turn messages off, reading stops; copies already stored are not deleted automatically, and you can delete them in the same step. You choose how long stored copies are kept: indefinitely (while your account exists), 30 or 90 days; older copies are deleted automatically. You can mark a client or a lead as confidential: for them no copies of messages are stored, their message text is not passed to AI features, and the client portal is unavailable.
9.3. What Pivona does not do. Pivona sends nothing to Freelancehunt on your behalf: no messages, no proposals, no bids, no other actions. You copy drafts and send them on the marketplace yourself. Pivona reads nothing from Freelancehunt except your profile, the project feed, public client profiles with reviews about them and, with your separate consent, your threads.
9.4. Storage and access. The token is stored encrypted and bound to your account; one user’s data is not accessible to others. As the operator, we have technical access to the servers, but we do not read your conversations ourselves (automated processing by AI features is described in 9.5) and use the data only for the purposes set out in section 2.
9.5. AI features. To score projects and prepare draft proposals, Pivona passes the project text, the client’s public profile and reviews about the client to AI features (section 3). If the “projects + messages” mode is on, message text may be used by AI features (reply drafts, lead scoring) in the same way, after personal data has been anonymised. Pivona caches public client profiles for up to three days in a store shared between users; this cache holds only public Freelancehunt profiles, no user data. Pivona does not read profiles of other Freelancehunt freelancers.
9.6. Revoking access. You can disconnect the integration in Pivona (Profile → Integrations → Disconnect) or delete the token on Freelancehunt. On disconnection the token is deleted. Leads and clients created from the integration remain in your account until you delete them; stored copies of messages are not deleted by disconnection either, you delete them by turning messages off with the “delete stored copies” option or by deleting your account.
10. Changes to this policy
We may update this policy. The current version is always available at https://pivona.io/en/privacy-policy/. Users are notified of material changes by email or in the service interface.
Last updated: 09.09.2026