Skip to main content

Privacy notice

Last updated: 2026-09-10

This notice explains how Personal Page uses personal data, where it is stored, who receives it, and how it can be deleted. Cloud records are owner-scoped but remain readable by the application and its operator; they are not zero-knowledge encrypted.

Controller and contact

Simonas Bernotas, Vilnius, Lithuania

Contact for privacy requests: simonasbernotas@protonmail.com

Data flows

Account, identity, and profile

Purpose
Sign-in, account security, personalization, and access control.
Data
OAuth provider identifier, email, nickname, role, language, theme, time format, and account/login timestamps. Provider name and avatar may remain in the signed session but are not stored in the current Firestore user document.
Storage and recipients
Firebase Firestore and signed, HTTP-only session cookies; Google or Microsoft processes the OAuth exchange.
Legal basis
Steps requested to provide account features; legitimate interests for security and abuse prevention.
Retention
Until account deletion, subject to provider backup cycles. Session cookies expire under the authentication configuration.
Deletion
Use Delete account in Settings or email the controller. Provider-account records held by Google or Microsoft must be managed with that provider.

Browser and current-device preferences

Purpose
Remember consent, language, theme, music, UI choices, and optional local Progress workspaces.
Data
Preferences, consent choice, temporary UI state, and any local workspace the user intentionally creates. New local Progress workspaces are encrypted before browser storage; legacy plaintext workspaces may remain until converted or deleted.
Storage and recipients
Cookies, localStorage, sessionStorage, IndexedDB, and memory on the current device.
Legal basis
Requested service and consent where applicable; legitimate interests for essential preferences.
Retention
Until expiry or removal by the user, browser, or account-deletion cleanup on that device. Downloads and other devices remain separate copies.
Deletion
Clear site data in the browser and delete local workspaces/exports. Account deletion clears known account-linked private stores only on the device used.

Progress and connected student data

Purpose
Manage private classes, students, assessment, attendance, notes, reports, and Seating Plan connections.
Data
Student and class names, grades, attendance, comments, observations, teacher notes, generated reports, roster identifiers when explicitly supplied, and seating relationships/name snapshots.
Storage and recipients
Owner-scoped, application-readable Neon PostgreSQL records; encrypted browser workspaces when chosen; OpenAI only for an explicitly reviewed AI request. Exports are separate user-held copies.
Legal basis
Requested account service. Users entering another person's data must have lawful authority and provide any required notice.
Retention
Live cloud records remain until deleted. Administrator retention review can identify older records but does not itself erase them. Provider backups age out under provider schedules.
Deletion
Delete individual sets/items where available or delete the account. Independent exports, backups, and recipient copies follow their own retention.

Private application workspaces

Purpose
Provide School Year, Protocols, Long-term Plans, Finance, TV progress, private exercises, Seating Plans, and connected planning tools.
Data
Schedules, attendance drafts, plans, protocols, actions, finance entries, viewing progress, saved exercise content and authorship, and workspace settings.
Storage and recipients
Owner-scoped Neon PostgreSQL and Firebase Firestore records. Server-side cloud records are application-readable.
Legal basis
Steps requested to provide the signed-in service.
Retention
Until the user deletes the relevant item or account, subject to backups and independent exports.
Deletion
Account deletion removes attributable private records, TV progress, and private exercise copies. Shared/canonical exercises remain but the deleted author's identity is removed.

Activities and participant data

Purpose
Run Pi Day, Chess Tournament, and Education Gamification activities.
Data
Pi Day first name, class, exact result and lookup input; chess display name, class, rating and tournament results; gamification participant code, name, team, score and game events.
Storage and recipients
Neon PostgreSQL and public activity views where described at collection. Pi Day does not retain the submitted birth date or request body after lookup.
Legal basis
Requested participation; legitimate interests for activity integrity. The person entering data must have authority to do so.
Retention
Pi Day entries are hidden and deleted 30 days after the latest submission. Tournament and gamification records remain until the organizer/controller deletes them or handles a request.
Deletion
Email the controller for access, correction, portability or deletion. Account deletion removes owned chess tournaments, but not unowned Pi Day or global gamification records.

Lesson booking and confirmations

Purpose
Schedule a lesson and send confirmation or cancellation messages.
Data
Name, email, optional phone, selected time, OAuth identity, event details, and provider event/message identifiers.
Storage and recipients
Personal Page during the request; Google Calendar or Microsoft Graph for calendar copies; Gmail for confirmations. Provider and recipient mailbox copies are separate.
Legal basis
Steps requested to arrange the booking; legitimate interests for reliable delivery and abuse prevention.
Retention
Application records follow booking needs; calendars, mailboxes, logs, and provider copies follow their owners' and providers' retention.
Deletion
Cancel through the service when available and email the controller for application/provider-copy requests. Recipients may retain their own messages.

OpenAI-assisted features

Purpose
Generate requested math objects, reports, dialogue, scenes, or drafts.
Data
The prompt and context selected or reviewed by the user. Free text may identify people even when direct identity fields are omitted. Pseudonymous operation metadata records status, model, token/cost and error categories; optional diagnostics may contain encrypted request/response excerpts.
Storage and recipients
OpenAI processes the request. Personal Page requests the Responses API with storage disabled. It stores pseudonymous operation metadata in Neon for 30 days and, only when diagnostics are enabled, encrypted diagnostics for up to 7 days.
Legal basis
Requested service for generation; legitimate interests for minimal operation, security, cost control, and diagnostics.
Retention
Personal Page operation metadata: 30 days. Optional encrypted diagnostics: 7 days. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless legally required longer; approved modified or zero-retention controls can change this. API data is not used for model training by default unless the operator opts in.
Deletion
Account deletion removes attributable operation identifiers and diagnostics. Generated content saved elsewhere follows that feature's retention.

Analytics and performance measurement

Purpose
Understand use, diagnose performance, and improve the service.
Data
Google Analytics may collect page/device and approximate-location signals after consent. Vercel Web Analytics and Speed Insights collect privacy-oriented page and performance measurements, including technical request signals.
Storage and recipients
Google Analytics and Vercel.
Legal basis
Consent for Google Analytics; legitimate interests for minimal Vercel service measurement and maintenance.
Retention
Vercel's daily visitor hash is discarded after 24 hours; aggregated reporting availability follows the account plan and Vercel may store data longer. Google Analytics follows the configured property and provider retention controls; the browser consent choice persists until changed or cleared.
Deletion
Withdraw Google Analytics consent through the consent controls or clear site data. Email the controller for applicable rights requests.

External media embeds

Purpose
Play embedded music and video.
Data
IP address, device/browser signals, cookies, account state, and media interaction may be sent when an external player loads or is used.
Storage and recipients
Providers such as SoundCloud and YouTube under their own privacy terms.
Legal basis
Requested media playback and, where required, consent.
Retention
Controlled by the external provider and the user's provider account/browser choices.
Deletion
Use provider privacy controls, clear browser data, or contact the provider/controller as applicable.

Infrastructure, security, backups, and exports

Purpose
Serve the site, detect abuse, investigate failures, recover data, and let users export their work.
Data
Request timestamps, routes, coarse technical data, error/security events, pseudonymous identifiers, rate-limit counters, backups, and user-created exports. Logs should not contain feature payloads by design.
Storage and recipients
Vercel, Neon, Firebase/Google Cloud, and authorized operational tools; exports stay wherever the user saves or shares them.
Legal basis
Legitimate interests in security, abuse prevention, service maintenance, and recovery.
Retention
Short operational periods set by each service; security counters expire; backups rotate on provider schedules. Exports remain until their holder deletes them.
Deletion
Live attributable records are included where feasible in account deletion. Rotating backups, de-identified operational records, and independent exports are removed or expire under their separate schedules.

Data about other people

Before entering student, participant, guest, colleague, or other third-party data, you must have lawful authority and provide any notice or obtain any permission required in your context. Personal Page does not claim that a school or organization has authorized your use.

Processors and recipients

Depending on the feature, recipients include Vercel, Neon, Firebase/Google Cloud, Google, Microsoft, OpenAI, SoundCloud, YouTube, the controller, and people who receive bookings, exports, shared links, or public activity results. Access is limited by application roles and owner scoping, but the operator can technically read server-side cloud records when needed to operate the service.

Current provider references

These official pages describe provider processing and may change over time:

International transfers

Some providers may process data outside Lithuania or the European Economic Area. Where GDPR transfer rules apply, processing relies on an adequacy decision, Standard Contractual Clauses, or another provider-documented safeguard. Contact the controller for current provider and safeguard details.

Required and optional data

Fields marked as required are needed to provide the requested account, booking, activity, or workspace function. Optional fields may be left blank. Refusing essential identity or request data can mean that the related service cannot be provided.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time without affecting earlier lawful processing. Email the controller for account data, participant records, provider copies, or exports that self-service tools cannot handle.

You may also complain to Lithuania's supervisory authority: State Data Protection Inspectorate (VDAI).

Automated processing

AI features produce requested drafts, exercises, reports, dialogue, or scenes for human review. Abuse controls and rate limits may automatically permit or block requests. Personal Page is not intended to make solely automated decisions that produce legal or similarly significant effects.

Account deletion

Settings offers authenticated deletion after a fresh Google or Microsoft sign-in and exact confirmation. It removes owner-linked live workspaces and the profile, then signs out. It does not automatically remove unowned global FMT or Education Gamification records, Pi Day submissions, provider calendars or emails, consented analytics, exports, recipient copies, or rotating backups. Those follow their stated retention or an email request. A later sign-in creates a clean account; deleted data is not restored.

Future direction: stronger user-held storage

Client-held encryption and user-managed databases are being evaluated. They do not exist for the current cloud workspaces. Today those records remain owner-scoped and application-readable, as described above.

Privacy