Last updated: 2026-09-10
This notice explains how Personal Page uses personal data, where it is stored, who receives it, and how it can be deleted. Cloud records are owner-scoped but remain readable by the application and its operator; they are not zero-knowledge encrypted.
Controller and contact
Simonas Bernotas, Vilnius, Lithuania
Contact for privacy requests: simonasbernotas@protonmail.com
Data flows
Account, identity, and profile
- Purpose
- Sign-in, account security, personalization, and access control.
- Data
- OAuth provider identifier, email, nickname, role, language, theme, time format, and account/login timestamps. Provider name and avatar may remain in the signed session but are not stored in the current Firestore user document.
- Storage and recipients
- Firebase Firestore and signed, HTTP-only session cookies; Google or Microsoft processes the OAuth exchange.
- Legal basis
- Steps requested to provide account features; legitimate interests for security and abuse prevention.
- Retention
- Until account deletion, subject to provider backup cycles. Session cookies expire under the authentication configuration.
- Deletion
- Use Delete account in Settings or email the controller. Provider-account records held by Google or Microsoft must be managed with that provider.
Browser and current-device preferences
- Purpose
- Remember consent, language, theme, music, UI choices, and optional local Progress workspaces.
- Data
- Preferences, consent choice, temporary UI state, and any local workspace the user intentionally creates. New local Progress workspaces are encrypted before browser storage; legacy plaintext workspaces may remain until converted or deleted.
- Storage and recipients
- Cookies, localStorage, sessionStorage, IndexedDB, and memory on the current device.
- Legal basis
- Requested service and consent where applicable; legitimate interests for essential preferences.
- Retention
- Until expiry or removal by the user, browser, or account-deletion cleanup on that device. Downloads and other devices remain separate copies.
- Deletion
- Clear site data in the browser and delete local workspaces/exports. Account deletion clears known account-linked private stores only on the device used.
Progress and connected student data
- Purpose
- Manage private classes, students, assessment, attendance, notes, reports, and Seating Plan connections.
- Data
- Student and class names, grades, attendance, comments, observations, teacher notes, generated reports, roster identifiers when explicitly supplied, and seating relationships/name snapshots.
- Storage and recipients
- Owner-scoped, application-readable Neon PostgreSQL records; encrypted browser workspaces when chosen; OpenAI only for an explicitly reviewed AI request. Exports are separate user-held copies.
- Legal basis
- Requested account service. Users entering another person's data must have lawful authority and provide any required notice.
- Retention
- Live cloud records remain until deleted. Administrator retention review can identify older records but does not itself erase them. Provider backups age out under provider schedules.
- Deletion
- Delete individual sets/items where available or delete the account. Independent exports, backups, and recipient copies follow their own retention.
Private application workspaces
- Purpose
- Provide School Year, Protocols, Long-term Plans, Finance, TV progress, private exercises, Seating Plans, and connected planning tools.
- Data
- Schedules, attendance drafts, plans, protocols, actions, finance entries, viewing progress, saved exercise content and authorship, and workspace settings.
- Storage and recipients
- Owner-scoped Neon PostgreSQL and Firebase Firestore records. Server-side cloud records are application-readable.
- Legal basis
- Steps requested to provide the signed-in service.
- Retention
- Until the user deletes the relevant item or account, subject to backups and independent exports.
- Deletion
- Account deletion removes attributable private records, TV progress, and private exercise copies. Shared/canonical exercises remain but the deleted author's identity is removed.
Activities and participant data
- Purpose
- Run Pi Day, Chess Tournament, and Education Gamification activities.
- Data
- Pi Day first name, class, exact result and lookup input; chess display name, class, rating and tournament results; gamification participant code, name, team, score and game events.
- Storage and recipients
- Neon PostgreSQL and public activity views where described at collection. Pi Day does not retain the submitted birth date or request body after lookup.
- Legal basis
- Requested participation; legitimate interests for activity integrity. The person entering data must have authority to do so.
- Retention
- Pi Day entries are hidden and deleted 30 days after the latest submission. Tournament and gamification records remain until the organizer/controller deletes them or handles a request.
- Deletion
- Email the controller for access, correction, portability or deletion. Account deletion removes owned chess tournaments, but not unowned Pi Day or global gamification records.
Lesson booking and confirmations
- Purpose
- Schedule a lesson and send confirmation or cancellation messages.
- Data
- Name, email, optional phone, selected time, OAuth identity, event details, and provider event/message identifiers.
- Storage and recipients
- Personal Page during the request; Google Calendar or Microsoft Graph for calendar copies; Gmail for confirmations. Provider and recipient mailbox copies are separate.
- Legal basis
- Steps requested to arrange the booking; legitimate interests for reliable delivery and abuse prevention.
- Retention
- Application records follow booking needs; calendars, mailboxes, logs, and provider copies follow their owners' and providers' retention.
- Deletion
- Cancel through the service when available and email the controller for application/provider-copy requests. Recipients may retain their own messages.
OpenAI-assisted features
- Purpose
- Generate requested math objects, reports, dialogue, scenes, or drafts.
- Data
- The prompt and context selected or reviewed by the user. Free text may identify people even when direct identity fields are omitted. Pseudonymous operation metadata records status, model, token/cost and error categories; optional diagnostics may contain encrypted request/response excerpts.
- Storage and recipients
- OpenAI processes the request. Personal Page requests the Responses API with storage disabled. It stores pseudonymous operation metadata in Neon for 30 days and, only when diagnostics are enabled, encrypted diagnostics for up to 7 days.
- Legal basis
- Requested service for generation; legitimate interests for minimal operation, security, cost control, and diagnostics.
- Retention
- Personal Page operation metadata: 30 days. Optional encrypted diagnostics: 7 days. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless legally required longer; approved modified or zero-retention controls can change this. API data is not used for model training by default unless the operator opts in.
- Deletion
- Account deletion removes attributable operation identifiers and diagnostics. Generated content saved elsewhere follows that feature's retention.
Analytics and performance measurement
- Purpose
- Understand use, diagnose performance, and improve the service.
- Data
- Google Analytics may collect page/device and approximate-location signals after consent. Vercel Web Analytics and Speed Insights collect privacy-oriented page and performance measurements, including technical request signals.
- Storage and recipients
- Google Analytics and Vercel.
- Legal basis
- Consent for Google Analytics; legitimate interests for minimal Vercel service measurement and maintenance.
- Retention
- Vercel's daily visitor hash is discarded after 24 hours; aggregated reporting availability follows the account plan and Vercel may store data longer. Google Analytics follows the configured property and provider retention controls; the browser consent choice persists until changed or cleared.
- Deletion
- Withdraw Google Analytics consent through the consent controls or clear site data. Email the controller for applicable rights requests.
External media embeds
- Purpose
- Play embedded music and video.
- Data
- IP address, device/browser signals, cookies, account state, and media interaction may be sent when an external player loads or is used.
- Storage and recipients
- Providers such as SoundCloud and YouTube under their own privacy terms.
- Legal basis
- Requested media playback and, where required, consent.
- Retention
- Controlled by the external provider and the user's provider account/browser choices.
- Deletion
- Use provider privacy controls, clear browser data, or contact the provider/controller as applicable.
Infrastructure, security, backups, and exports
- Purpose
- Serve the site, detect abuse, investigate failures, recover data, and let users export their work.
- Data
- Request timestamps, routes, coarse technical data, error/security events, pseudonymous identifiers, rate-limit counters, backups, and user-created exports. Logs should not contain feature payloads by design.
- Storage and recipients
- Vercel, Neon, Firebase/Google Cloud, and authorized operational tools; exports stay wherever the user saves or shares them.
- Legal basis
- Legitimate interests in security, abuse prevention, service maintenance, and recovery.
- Retention
- Short operational periods set by each service; security counters expire; backups rotate on provider schedules. Exports remain until their holder deletes them.
- Deletion
- Live attributable records are included where feasible in account deletion. Rotating backups, de-identified operational records, and independent exports are removed or expire under their separate schedules.
Data about other people
Before entering student, participant, guest, colleague, or other third-party data, you must have lawful authority and provide any notice or obtain any permission required in your context. Personal Page does not claim that a school or organization has authorized your use.
Processors and recipients
Depending on the feature, recipients include Vercel, Neon, Firebase/Google Cloud, Google, Microsoft, OpenAI, SoundCloud, YouTube, the controller, and people who receive bookings, exports, shared links, or public activity results. Access is limited by application roles and owner scoping, but the operator can technically read server-side cloud records when needed to operate the service.
Current provider references
These official pages describe provider processing and may change over time:
International transfers
Some providers may process data outside Lithuania or the European Economic Area. Where GDPR transfer rules apply, processing relies on an adequacy decision, Standard Contractual Clauses, or another provider-documented safeguard. Contact the controller for current provider and safeguard details.
Required and optional data
Fields marked as required are needed to provide the requested account, booking, activity, or workspace function. Optional fields may be left blank. Refusing essential identity or request data can mean that the related service cannot be provided.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time without affecting earlier lawful processing. Email the controller for account data, participant records, provider copies, or exports that self-service tools cannot handle.
You may also complain to Lithuania's supervisory authority: State Data Protection Inspectorate (VDAI).
Automated processing
AI features produce requested drafts, exercises, reports, dialogue, or scenes for human review. Abuse controls and rate limits may automatically permit or block requests. Personal Page is not intended to make solely automated decisions that produce legal or similarly significant effects.
Account deletion
Settings offers authenticated deletion after a fresh Google or Microsoft sign-in and exact confirmation. It removes owner-linked live workspaces and the profile, then signs out. It does not automatically remove unowned global FMT or Education Gamification records, Pi Day submissions, provider calendars or emails, consented analytics, exports, recipient copies, or rotating backups. Those follow their stated retention or an email request. A later sign-in creates a clean account; deleted data is not restored.
Future direction: stronger user-held storage
Client-held encryption and user-managed databases are being evaluated. They do not exist for the current cloud workspaces. Today those records remain owner-scoped and application-readable, as described above.