Privacy Policy

Draft. Requires legal review before publication.

Version1.0
Effective Date2026-08-29
Applicable toaiput.site, REST API and MCP interface of the service

The primary version of the document is in English. Texts in other languages are provided for convenience; in case of discrepancies, the primary version shall prevail, except where mandatory provisions require interpretation in the language of the consumer.

1. Who processes your data

Data Controller in the context of Regulation (EU) 2016/679 (GDPR):

NamePavel Kanakhistov — self-employed individual (autónomo)
NIFZ1825610J
CountrySpain (postal address – upon request)
Emailpavel.knx@gmail.com
Websitehttps://aiput.site

Further – "we", "service". We do not appoint a Data Protection Officer (DPO): the scale of data processing does not require it.

2. Two different roles

This is the key distinction, from which everything else depends.

Regarding the data associated with your account – we are in control. Email address, name, session data, payment information: we determine how and for what purpose this data is processed, and we are responsible for this before you.

Regarding the content of your websites: you are the controller, and we are the processor. We store and provide files according to your instructions, without determining the purposes of their processing. If the published website contains personal data of third parties – texts about employees, customer reviews, photographs, a contact form – you are responsible for providing the legal basis for their processing. For business users, we conclude a separate agreement on data processing upon request (DPA).

The published website is accessible to anyone on the internet. We cannot restrict the number of people who view it.

3. We collect very little, and here is what we do not collect

The service is structured in such a way that it requires very few personal data. Websites that are published are, by their nature, publicly accessible, and all that is required for operation is to know the account holder and whether a subscription has been paid.

Therefore, we do not collect:

The IP address and browser string are recorded once, upon creating a login session, and are only needed so that you can distinguish your sessions from one another. They are not collected during normal use of the service.

The rate limiting of code requests to email is implemented such that the IP address is not stored. A counter is maintained based on an irreversible value calculated from the address using our secret. The original IP address cannot be recovered from this value, and the counters are deleted after their expiration period.

4. What data do we collect

4.1. Account and Login

Via Google. Google provides us with the following information: email address, name, link to profile picture, email verification status, and your Google account's permanent identifier. We do not see or obtain your Google password.

Using a one-time code. We only receive the email address. The code is stored as an irreversible hash and is deleted after use or expiration.

4.2. Automatically upon use

4.3. Terms of Service

Files that you or an AI agent acting on your behalf upload for publication: HTML, CSS, JavaScript, images, fonts, and other static files. We do not analyze their content, index it, or use it for any purpose other than hosting it on the internet at your request. We do not use the content of your websites to train models.

4.4. Payment information

Payment card details are processed by Stripe. We do not receive, view, or store them. We store the customer's identifier and subscriptions, as well as payment amounts, currency, status, and dates, within Stripe – this is required for accounting purposes.

5. Why and on what grounds

PurposeDataGround (Article 6 GDPR)
Provision of the service, access to the accountAccount, sessionsPerformance of the Contract, Clause 1(b)
Hosting of your websitesWebsite contentPerformance of the Contract, Clause 1(b)
Payment acceptance and invoice generationPayment recordsPerformance of the Contract, Clause 1(b)
Accounting and tax accountingPayment recordsLegal obligation, paragraph 1(c)
Rate limiting, abuse protectionIP address, call logsLegitimate interest, paragraph 1(f)
Responses to your inquiriesCorrespondenceLegitimate interest, paragraph 1(f)

Legitimate interest in the two final lines – ensuring the service's functionality and security. You have the right to object to such processing (Section 9).

We do not use your data for advertising, do not profile you, and do not make automated decisions regarding you with legal consequences.

6. How long do we retain your data

DataTerm
Account and login methodsAs long as the account remains active
Sessions30 days after the expiration or termination date
One-time login codes30 minutes, or until the first use
Website contentAs long as the website remains active.
Publication History12 months after the website is removed
Payment records and invoices6 years – Commercial Code, Article 30

The daily automated cleaning process is executed, rather than a manual operation: upon its occurrence, records are deleted without your request or our involvement.

Upon deletion of your account, a string containing only your internal identifier and a deletion marker will remain, without your address, name, or any other personal information. This is necessary to free your email address – otherwise, it would not be possible to create a new account using the same email address.

We are legally obligated to retain payment records and cannot delete them earlier than required by law, even at your request. This constitutes a direct limitation on the right to deletion (Article 17 of the GDPR).

7. To whom do we transfer data

We do not sell your data or transfer it to third parties for their own purposes. We use the services of third-party processors:

HandlerWhat does it doWhere
Cloud infrastructure providerHosting of the service, database, and publication of your websites.EU and other regions
Google Ireland Ltd.Authentication via Google AccountEuropean Union
Stripe Payments Europe, Ltd.Payment acceptance and tax calculationEuropean Union
Transaction mail providerDelivery of emails with login codesEuropean Union

A data processing agreement has been concluded with each party.

The parties with whom you interact directly, we will identify by name. The list of infrastructure providers – this category may change, and we do not consider it necessary to disclose the full details of the service. An up-to-date list of processors with names is available upon request at pavel.knx@gmail.com – this is your right under Article 15 of the GDPR, and we cannot refuse it.

We may also disclose information if required by law or in response to a valid request from a duly authorized governmental agency or regulatory body.

8. Transfer outside the EEA

Certain processors may process data in the United States or other countries outside the EEA. In such cases, we ensure compliance with Chapter V of the GDPR: standard contractual terms (SCC), approved by the European Commission, and/or certification of the recipient under the EU-U.S. Data Privacy Framework. Copies of the guarantees and an up-to-date list of recipients can be obtained at pavel.knx@gmail.com.

9. Your Rights

Contact us at pavel.knx@gmail.com. We will respond within 30 days. We may request proof of identity if the request is not made from an address associated with the account.

Right to Complain (Article 77). The supervisory authority of the controller is the Agencia Española de Protección de Datos, Spain, www.aepd.es. If you are located in the EU/EEA, you may also contact the data protection authority in your country of residence.

10. Account Deletion

The account can be deleted in the personal account. Upon deletion:

Cancellation of subscription and account deletion are separate actions. The procedure for refunding for unused periods is described in the Purchase Policy.

11. Cookies

The service uses only technically necessary cookies:

CookiePurposeTerm
siteai_sessionMaintaining login to the account30 days
siteai_oauth_stateProtection against fraudulent login requests via Google10 minutes

We do not use analytical, advertising, or any third-party tracking cookies. Therefore, we do not display the consent banner: cookies necessary for technical functionality do not require consent. If analytics are ever implemented, the banner will become mandatory, and this section will become invalid.

The websites you publish may contain their own cookies – you are responsible for these and for obtaining consent for their use.

12. Safety

Measures under Article 32 of the GDPR:

No system is absolutely secure. In the event of a breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours (Article 33) and, in cases of high risk, you (Article 34).

13. A single standard for all countries

We apply a single standard of personal data protection to all users, regardless of their location. This standard is based on GDPR: the legal grounds, the rights of subjects, the retention periods, and the requirements for processors, as well as the guarantees of transfer, as outlined in sections 2–12, all apply to everyone. If the laws of your country of residence grant you more rights or shorter retention periods, those laws will apply.

14. Age

This service is not intended for persons under the age of 18. We deliberately do not collect data from children.

15. Changes

We may update this Policy. We will notify you of any material changes by email at least 30 days before the changes take effect. The version and date are indicated at the beginning of this document.

16. Contacts

pavel.knx@gmail.com