AI STEP

AI STEP — Privacy Policy

Version date: {{ДАТА}}

This Policy explains, in plain words, what data AI STEP collects, why, who else sees it, how long we keep it and what you can demand from us at any moment.

We are a Ukrainian service. This Policy is governed by the law of Ukraine — in particular the Law of Ukraine "On Personal Data Protection", the Law of Ukraine "On Electronic Commerce", the Law of Ukraine "On Protection of Consumer Rights" and the Law of Ukraine "On Copyright and Related Rights". If you are in the European Economic Area or the United Kingdom, the GDPR applies to you in addition, and we describe your GDPR rights below.

This English text is provided for the convenience of international users. In case of any discrepancy, the Ukrainian version of this Policy prevails legally.


1. Who controls your data and how to reach us

1.1. The data controller is {{ФОП/ТОВ, ІПН/ЄДРПОУ, адреса}} (Ukraine) — below, "we", "us", "AI STEP".

1.2. Contacts for any data question, request or complaint: support@aistep.app · {{ТЕЛЕФОН}}. Write to the e-mail address for anything related to your data — it is the fastest channel and it is the one we monitor.

1.3. What the service is, so you can see why we need each piece of data. AI STEP is a web service that teaches how to earn with the help of AI, on a subscription basis. It includes: learning programs (3 programs, 16 courses, 64 lessons, each lesson built as text → practice → quiz); completion certificates; an AI Mentor (chat); AI tools (ready-made prompts for a post, an e-mail, a content plan and similar); and progress and streak tracking. The first course of the flagship program is free; the rest is available by subscription.

1.4. We are an educational product and we do not guarantee income. We teach skills. We do not promise, guarantee or forecast any earnings, profit, clients or employment. Your result depends on your own effort, your skill and the market. Any figures you see in lessons or marketing are illustrations, not a promise.

1.5. A completion certificate in AI STEP is an internal badge of the service confirming that you finished a course inside AI STEP. It is not an accredited diploma and not a state-recognised educational document. We store the fact of completion in our database and nothing more.

1.6. The service is for adults, 18+. It is a paid product about earning money, and we do not target or knowingly onboard minors.

1.7. Payments are taken directly through WayForPay (Ukrainian acquiring, Visa / Mastercard cards), not through the App Store or Google Play. Practically this means two things: no app-store platform stands between us, and we handle billing questions and refunds ourselves.


2. What data we collect

2.1. We collect only what the product actually needs. Below is the full list.

Data When it is collected Why we need it Legal basis
Quiz answers — your goal, experience level, time available, income orientationWhen you go through the onboarding quiz, before or after registrationTo assemble a relevant learning path and show a suitable program; to understand which content to developConsent (before an account exists) / performance of the contract (after you have an account) — Art. 6(1)(a) and 6(1)(b) GDPR
E-mailIn the lead form and at registrationAccount login and identification, service messages (access, payment, subscription, password reset); with separate consent — marketing e-mailsPerformance of the contract; consent for marketing — Art. 6(1)(b), 6(1)(a) GDPR
NameOnly if you enter itTo address you inside the service and on the certificate badgePerformance of the contract — Art. 6(1)(b) GDPR
Account data, including the password as a hashAt registration and at each loginAuthentication and account security. The password is stored only as a hash and is managed by Supabase Auth — we never see or store your plaintext passwordPerformance of the contract; legitimate interest in security — Art. 6(1)(b), 6(1)(f) GDPR
Learning progress and streak — lessons opened and completed, quiz results, courses finished, streak daysWhile you use the serviceTo continue learning from where you stopped, to keep progress and streak, to issue the completion badgePerformance of the contract — Art. 6(1)(b) GDPR
Subscription status and payment history — date, amount, plan, transaction status. No card detailsAt each payment, renewal, cancellation or refundTo open and keep your access, to run and stop auto-renewal, to process refunds, to comply with accounting and tax dutiesPerformance of the contract; legal obligation — Art. 6(1)(b), 6(1)(c) GDPR
Texts of your AI requests — what you type to the AI Mentor and into AI toolsAt the moment you send a requestTo generate the answer, and to keep your chat history available to youPerformance of the contract — Art. 6(1)(b) GDPR
Interface languageWhen you choose a language or on first loadTo show the service in your language and to pass the language code to the AI provider so the answer comes back in that languagePerformance of the contract — Art. 6(1)(b) GDPR
Product usage events — for example opening a lesson, finishing a quiz, reaching the payment screen, cancelling a subscriptionWhile you use the serviceTo see where the product breaks or confuses people and to fix it; to detect abuse. Our analytics is our own, stored in our own databaseLegitimate interest — Art. 6(1)(f) GDPR
Technical logs — IP address, browser typeAutomatically, with every request to the service, on the side of Supabase / the hosting providerService delivery, protection against attacks and abuse, incident investigationLegitimate interest — Art. 6(1)(f) GDPR

2.2. We do not build hidden profiles beyond what is listed above, and we do not enrich your record with data bought from third parties.

2.3. Subscription, auto-renewal and refunds — what we disclose and when. These are contractual terms rather than privacy terms, but they explain the payment data above, so we state them here too.

2.3.1. The price of the plan, the billing period and the fact that auto-renewal is on by default are disclosed to you before you pay, on the payment screen. Trial access costs ₴149 for 3 days and then renews automatically at the price of the selected plan. The current plan prices (weekly, monthly, annual, with and without the promo) are always shown before payment.

2.3.2. Cancelling is one tap in the "Subscription" section of the app. No calls, no letters, no explanations required. After cancellation your access remains until the end of the period you have already paid for.

2.3.3. Discounts are real: a promo has a real deadline, the discount wheel is genuinely random (5–30%) and the discount it gives is genuinely applied, and the final offer at exit is a real offer.

2.3.4. Refunds: within 14 days of the payment we refund on your request, without asking for reasons, provided you have not consumed a substantial part of the content. After that period, refunds follow the applicable law. The refund goes back by the same method you paid with, within up to 14 days — usually faster. We say this openly: writing to support@aistep.app is faster and simpler than opening a chargeback dispute with your bank, and we would rather solve it with you directly.


3. Legal bases we rely on

3.1. Performance of the contract (Art. 6(1)(b) GDPR; the Law of Ukraine "On Personal Data Protection" and the Law of Ukraine "On Electronic Commerce") — creating and running your account, giving access to programs, courses and lessons, saving progress and streak, running the AI Mentor and AI tools, managing the subscription, processing payments and refunds, sending service messages about your access and billing.

3.2. Legitimate interest (Art. 6(1)(f) GDPR) — keeping the service secure, preventing fraud and abuse of free access, investigating incidents, and improving the product using aggregated usage events. Where we rely on legitimate interest, you may object — see clause 9.

3.3. Consent (Art. 6(1)(a) GDPR) — the marketing newsletter, and the quiz answers you give before you have an account. Consent is voluntary, refusing it does not block your access to the paid product, and you may withdraw it at any time (an unsubscribe link in every marketing e-mail, or a message to support@aistep.app). Withdrawal does not affect processing already carried out.

3.4. Legal obligation (Art. 6(1)(c) GDPR) — keeping payment and accounting records for the periods required by Ukrainian accounting and tax legislation, and replying to lawful requests from authorities.


4. What we do not collect, and what not to send us

4.1. We never receive or store your card number, expiry date or CVV. Card data is entered on the WayForPay side and processed by WayForPay. We only see the outcome of the transaction: date, amount, plan, status.

4.2. We do not ask for and do not intentionally collect "special category" data — health, racial or ethnic origin, religious or political views, trade-union membership, sexual life, biometrics or genetic data. We have no product feature that needs them.

4.3. Please do not put into the AI chat: medical or diagnostic information, your banking or financial details, passwords, documents' numbers, or personal data of other people (clients, colleagues, family). The AI Mentor is a learning tool, not a secure vault, and text you send becomes part of a request to an external AI provider (see clause 5).

4.4. AI disclaimer — read this before relying on any AI answer. Answers of the AI Mentor and outputs of the AI tools are generated automatically. They can be inaccurate, outdated or entirely invented, including confident-sounding facts, figures, names and links. Always verify anything important before you act on it. The AI does not give medical, legal or financial advice, and it must not be treated as such. Do not rely on AI output when making decisions that affect other people.


5. Who else receives your data

5.1. We use a short list of processors. There are no others.

Recipient What it receives Why Where the processing happens
Supabase (Postgres, Auth, Edge Functions)Accounts and password hashes, subscription status and payment history, learning progress and streak, leads, analytics events, AI chat history, technical logs (IP, browser)Our database, authentication and server functions — the core storage of the serviceHosting in the EU (Frankfurt)
WayForPayCard data you enter on their page (we do not see it), transaction amount, currency, plan and statusPayment processing, recurring charges, refunds, acquiring obligationsUkraine
OpenAI (currently) and/or AnthropicOnly the text of your request and the interface language code. No name, no e-mail, no payment data, no device identifiers, no geolocationTo generate the AI Mentor's answer and the AI tools' outputMay be outside the EEA — see clause 7
Google CDN (CanvasKit)The technical data inherent to any browser request for a file — IP address, browser typeDelivering the CanvasKit rendering engine so the web interface draws correctlyGoogle's global CDN

5.2. Fonts are bundled locally in the application. Google Fonts is not called at runtime. Beyond the four recipients above we use no advertising networks and no third-party analytics trackers — our usage analytics is our own and lives in our own database.

5.3. We do not sell personal data to anyone, we do not rent it and we do not trade it for services.

5.4. We do not hand your AI conversations over for training AI models. We send a request to the AI provider to get you an answer, and that is the only purpose of that transfer.

5.5. We may disclose data where a law of Ukraine obliges us to do so — for example, a lawful request from a court or a state authority acting within its powers. We disclose only what is actually demanded.


6. How long we keep data

6.1. Account, learning progress, streak and certificate badges — while your account exists. If you delete the account, we delete them (see clause 10).

6.2. Payment and accounting records — for the periods required by Ukrainian accounting and tax legislation. We cannot delete these earlier even at your request, because keeping them is a legal duty; after the statutory period expires, they are deleted.

6.3. Leads (an e-mail left in the form without registration) — until you withdraw consent or unsubscribe, after which we remove the e-mail from the mailing base.

6.4. AI request texts — the chat history is stored in our database while your account exists and is deleted with it. On the AI provider's side, the retention period for a transmitted request is governed by that provider's own policy, not by ours.

6.5. Technical logs — kept for a short operational period on the side of Supabase / the hosting provider and rotated automatically.

6.6. Usage events — kept in our database while they remain useful for product decisions; they are tied to your account and are removed or de-identified when the account is deleted.


7. Transfers outside Ukraine and outside the EEA

7.1. Our database and server functions are hosted in the EU (Frankfurt) by Supabase.

7.2. AI providers (OpenAI, Anthropic) may process the transmitted request text outside the EEA, including in the United States. For such transfers we rely on the legal mechanisms available under the GDPR and Ukrainian law — an adequacy decision where one covers the recipient, or the European Commission's Standard Contractual Clauses (SCC) in the provider's data processing terms.

7.3. Regardless of the mechanism, we apply minimisation: only the request text and the language code go to the AI provider (clause 5.1), and everything travels over an encrypted TLS connection.


8. How we protect data

8.1. Row Level Security (RLS) is enabled in our database: the rules are written so that a user's requests reach only that user's own rows — your progress, your subscription, your chat.

8.2. Private keys and API keys live only on the server (Supabase Edge Functions) and are never shipped to the browser or embedded in the client application.

8.3. Encryption in transit — all traffic between your browser, our service and our processors runs over TLS.

8.4. Passwords are stored only as hashes, handled by Supabase Auth. Nobody on our side can read your password.

8.5. Access is limited — administrative access to production data is granted only to the people who need it for support, billing and operations, and only to the extent needed.

8.6. Honestly: absolute security does not exist. No service can promise that data will never be compromised. What we can promise is minimisation, the measures above, and that if a breach occurs that is likely to affect your rights, we will notify you and the competent supervisory authority as the law requires.


9. Your rights

9.1. You have the right to:

9.1.1. know and access — get confirmation of what data about you we process and receive a copy;

9.1.2. rectify — correct inaccurate or incomplete data (name, e-mail, quiz answers);

9.1.3. erase — have your data deleted, except what we must keep by law (clause 6.2);

9.1.4. restrict processing — for example while a dispute over accuracy is being resolved;

9.1.5. data portability — receive the data you gave us in a structured, machine-readable format;

9.1.6. object — to processing based on our legitimate interest, and at any time to marketing;

9.1.7. withdraw consent — for the newsletter and for the quiz answers collected on consent, at any time and without explanation;

9.1.8. not be subject to a decision made solely automatically with legal effect for you — we make no such decisions.

9.2. How to use them: write to support@aistep.app from the e-mail address of your account (this is how we verify it is you) and describe what you want. Nothing more formal is needed.

9.3. How fast we answer: within 30 days as required by Ukrainian law. For requests under the GDPR — within one month, which may be extended by up to two further months for complex or numerous requests, in which case we will tell you about the extension and the reason within the first month.

9.4. Complaints. If you think we mishandled your data, please tell us first — most issues are a misunderstanding we can fix quickly. You also have the right to complain to a supervisory authority: in Ukraine — the Ukrainian Parliament Commissioner for Human Rights; in the EEA or the UK — your local data protection authority.


10. Deleting your account

10.1. To delete your account, send a request from your account e-mail to support@aistep.app. We do not require a reason.

10.2. What is deleted: the account and login data (including the password hash), your name, learning progress, streak and internal certificate badges, quiz answers, AI chat history, and the link between usage events and you.

10.3. What remains: payment and accounting records (date, amount, plan, transaction status) — we are obliged to keep them for the statutory accounting and tax periods, and they are deleted once those periods expire. Data already transmitted to an AI provider as a request is retained on that provider's side under its own policy.

10.4. Deleting the account does not by itself refund a payment and does not by itself stop a subscription. Cancel the subscription first in the "Subscription" section (one tap), and if you want a refund, see clause 2.3.4.


11. Cookies and local storage

11.1. We do not run advertising trackers and we do not embed third-party analytics. What the service keeps in your browser is what it needs to work.

11.2. Stored locally in your browser (localStorage / similar) and on our side as part of your account:

11.2.1. quiz answers — so the funnel and the learning path survive a page reload;

11.2.2. learning progress — so a lesson opens where you left it;

11.2.3. interface language — so you are not asked again on every visit;

11.2.4. the display status of offers — so a promo, the discount wheel or the final offer is not shown to you over and over;

11.2.5. the authentication session — technically necessary, managed by Supabase Auth; without it you would be logged out on every page load.

11.3. How to clear it: use your browser settings (clearing site data / cookies and local storage for our domain), or your browser's private mode. Clearing will log you out and may reset locally stored quiz answers and offer states; your progress and subscription stay safe in your account.

11.4. Loading the CanvasKit rendering engine from Google's CDN involves a normal HTTP request from your browser to Google, which inherently reveals your IP address and browser type to that CDN. It is required to draw the interface.


12. Children

12.1. AI STEP is intended for persons aged 18 and over. We do not knowingly collect data of minors and we do not direct the service at them.

12.2. If you believe a person under 18 has created an account, write to support@aistep.app — we will check and delete the account and the associated data.


13. Changes to this Policy

13.1. This Policy may change as the product changes — for example if we add or replace a processor. The current version is always the one published in the service, with the version date at the top.

13.2. About material changes — new categories of data, a new recipient, a new purpose — we will notify you in advance by e-mail and/or with a notice inside the service, so you can read them and decide.

13.3. Purely editorial edits (wording, typos, clearer structure) take effect on publication with an updated version date.


14. Contacts for data requests

14.1. E-mail: support@aistep.app — access, correction, deletion, portability, objection, withdrawal of consent, refund questions, security reports. This is the primary and fastest channel.

14.2. Phone: {{ТЕЛЕФОН}}.

14.3. Controller: {{ФОП/ТОВ, ІПН/ЄДРПОУ, адреса}}, Ukraine.

14.4. Version date of this Policy: {{ДАТА}}.

Back to AI STEP Support: support@aistep.app All languages
© 2026 AI STEP