SyllonautBETA
Privacy

Privacy and personal data (GDPR)

This page explains which personal data Syllonaut processes, why it is needed, how long it is retained and what rights you have.

Version 1.9 · effective from 25 September 2026

1. Data controller

Václav Loubek
Business ID: 88878431
Slepá 868
289 24 Milovice – Mladá
Czech Republic

The controller operates Syllonaut at syllonaut.com. For privacy-related questions, contact vaclav@syllonaut.com or by phone at +420 733 377 199.

2. Data we process

  • Teacher account: email address, technical account identifier, entitlement data and AI usage-limit data.
  • Lessons and teacher work: briefs, generated lessons, edits, folder names and other saved content.
  • Lesson source materials: text extracted in the browser. The original file does not leave the device and the extracted text is not permanently stored by Syllonaut.
  • Syllonaut Help: the text of your question and of the earlier messages in the open Help panel, your plan and allowance usage, and the name of the app page you ask from. We do not store the conversation text. For each message we record only the time, the app page (without a lesson or live-lesson identifier), the question topic, the processing status, the AI cost and your rating of the answer, if you give one.
  • Live lessons: student display name, responses, team assignment, results, submission times and related operational data.
  • Security and operations: technical data needed for sign-in, abuse prevention, error diagnostics and security.
  • Terms acceptance: technical account identifier, Terms version / acceptance key and server acceptance time. The audit record does not duplicate the email address or another direct identifier.
  • Organisation DPA acceptance: for Team / School / Campus orders we record the active DPA version / acceptance key, server acceptance time and the technical account identifier of the person who accepted the DPA on behalf of the organisation.
  • Paid individual contract evidence: technical account identifier, plan, billing period, price and currency, Terms version / acceptance key, document language, the express request for immediate start of service, an immutable HTML snapshot of the contract information and model withdrawal form, integrity hash, server timestamp and technical Stripe Checkout link. The email address is not duplicated in this archived snapshot.
  • Online contract withdrawal: consumer name, electronic contact for confirmation, contract-snapshot identifier, plan and period, exact submission content, server date and time, integrity hash, confirmation-email delivery status and technical identifiers of the related refund process.
  • Marketing email consent: whether you opted in to news, case studies and offers, the consent date and the version of the consent text.
  • Contact form: the email address and message you submit. To protect the form, we temporarily retain only pseudonymised hashes of technical identifiers for rate limiting, not their readable form.
  • Analytics: only after consent, Google Analytics 4 may process website visit and usage data within the configured GA4 scope.

3. Purposes and legal bases

PurposeLegal basis
Registration, sign-in, lesson storage and provision of service featuresPerformance of a contract or steps taken at the user’s request before entering into a contract (Art. 6(1)(b) GDPR)
Recording acceptance of the Terms, paid-contract content and protecting legal claimsPerformance of the contract and legitimate interest in evidencing the formation and content of the contractual relationship and in establishing, exercising or defending legal claims (Art. 6(1)(b) and (f) GDPR)
Receiving a withdrawal, confirming it to the consumer, terminating the contract and settling paymentPerformance of the contract, compliance with consumer-protection legal obligations and legitimate interest in evidencing the settlement process (Art. 6(1)(b), (c) and (f) GDPR)
Recording an organisation’s acceptance of the Data Processing Agreement (DPA)Performance of the contract and legitimate interest in evidencing the binding controller–processor arrangement under Art. 28 GDPR and protecting legal claims (Art. 6(1)(b) and (f) GDPR)
Syllonaut Help: AI answers to questions about using the app, plans and allowances, and recording its use for the monthly message limit and budgetPerformance of the contract (Art. 6(1)(b) GDPR); analysing topics and answer ratings to improve Help is based on legitimate interest (Art. 6(1)(f) GDPR)
Service security, abuse prevention and technical diagnosticsLegitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR)
Compliance with legal obligationsLegal obligation (Art. 6(1)(c) GDPR)
Website analytics using GA4Consent (Art. 6(1)(a) GDPR); GA4 does not load without consent
News, case studies and promotional offers by emailVoluntary consent; registration is not conditional on this consent
Handling an enquiry submitted through the contact formSteps taken at the user’s request before entering into a contract where the enquiry concerns purchase or cooperation; otherwise legitimate interest in responding to an incoming enquiry

4. Marketing emails

During registration you can separately and voluntarily consent to receiving news, case studies and promotional offers. The checkbox is not preselected. Consent can be withdrawn at any time; every marketing email must provide a simple unsubscribe option. Withdrawing consent does not affect use of your account or operational emails related to the service.

If you have given consent, we send marketing emails based on how you use the service: your plan and plan changes, interface language, creating your first lesson, starting your first live lesson and use of your AI allowance. For this we share your email address, language, plan and the relevant event with our provider Resend. Without consent, or after you withdraw it, we do not send these events to Resend and you receive no marketing emails.

Loading your settings…

5. Cookies and Google Analytics 4

We use essential cookies and browser storage for sign-in, security, abuse prevention, language, taking part in a live lesson and storing your cookie choice. Analytics cookies are disabled by default, and refusing analytics does not restrict use of the service. On student pages (joining a lesson, the student lesson view and the classroom projection) we show no cookie banner and Google Analytics does not load.

TechnologyPurposeDuration
syllonaut_cookie_consent_v1Stores your cookie choice; essential.Up to 180 days.
Neon Auth (__Secure-neon-auth.session_token, __Secure-neon-auth.local.session_data)Teacher sign-in and secure session verification; essential. The second cookie is a short-lived signed copy of the session data.Until sign-out or session expiry; the session-data copy 5 minutes.
syllonaut_localeRemembers the chosen interface language; essential.1 year.
syllonaut_device_v1Random device identifier of a signed-in teacher for trusted-device limits and the free AI allowance per device; set only on sign-in or registration; essential.1 year.
ep_participant_<session>Links a student to their participation in a specific live lesson so they can submit responses; essential.Until the participation in that lesson expires.
Browser storage: IndexedDB (syllonaut-live-v1)Offline queue of student responses and the latest live-lesson state so answers are not lost when the connection drops; essential.Lesson state up to 24 hours; responses until successfully sent.
Browser storage: sessionStorage (syllonaut-live-control-v1:…)Access to real-time live-lesson control and team response drafts; essential.Until the browser tab is closed or access expires.
Cloudflare TurnstileAbuse protection only on the sign-in and registration forms; it loads only once those forms are opened and may use technical identifiers required for security.According to the security session and provider settings.
_ga, _ga_*Google Analytics 4 — measurement of traffic and service usage; only after consent.Approximately 13 months in Syllonaut’s configuration.

Google Analytics 4 loads only after active consent and only when measurement is configured in production. In this version, GA4 advertising signals and ad personalisation are disabled. If remarketing, Google Ads or other marketing tracking is added later, these notices will be updated and new consent will be requested where required.

You can change your choice at any time using the Cookie settings link in the footer. When analytics consent is withdrawn, Syllonaut blocks further measurement and attempts to remove existing GA cookies on the Syllonaut domain.

6. AI and uploaded source materials

AI processes text needed to create, edit or evaluate a lesson. Current AI paths enforce zero data retention at the Vercel AI Gateway level. For supported source materials, text extraction happens in the browser; the original file is not sent to the Syllonaut server and extracted text is not permanently stored as a file archive.

Syllonaut Help: When you ask Help a question, we send the question text, the earlier messages in the open panel and your plan and allowance usage through Vercel AI Gateway with zero data retention to the AI model provider, only so that it can write the answer. We do not store the conversation; it disappears when you close the panel or reload the page. Help has no access to your lessons, student responses or payments and changes nothing in your account. Do not enter student names or responses in Help.

Do not include personal data that is unnecessary for teaching in briefs or source materials, especially sensitive student data.

Automated decision-making: Syllonaut does not make decisions based solely on automated processing that produce legal effects for students or teachers or similarly significantly affect them (Art. 22 GDPR). Points suggested by AI for student responses are only a suggestion: they count toward the score and ranking only after the teacher confirms them, and the teacher always decides the final points. A notice that AI may have been used to write a response is only a signal for the teacher; it does not change points and is not proof. We provide this information under Art. 13(2)(f) GDPR.

7. Students and school use

A student does not need a full account to join a live lesson. They enter a display name and may submit responses during the lesson. Teachers should request only the student identifier needed for the specific lesson.

The student’s name and responses are visible to the teacher running the lesson. For open, team and exit-ticket responses, AI may suggest points and short feedback. The suggestion does not award points: it counts only after the teacher confirms it, and the teacher can change it. Syllonaut may notify the teacher that AI may have been used to write a response; the notice does not change points and the teacher decides what to do. Student pages show no cookie banner and do not load Google Analytics. Live-lesson data is deleted according to the school’s rules and the retention periods in section 9.

For Team / School / Campus plans, where the organisation determines the purposes and means of processing student or staff personal data and uses Syllonaut for that processing, the organisation is the controller and Syllonaut is the processor. This relationship is governed by a binding Data Processing Agreement (DPA), expressly accepted by an authorised representative when the organisation places the order. From Terms 1.11 the same DPA also applies to individual Free, Teacher and Teacher Pro accounts where the teacher uses Syllonaut to process students’ personal data in teaching; the controller is then the teacher, or the school for which they teach. For Syllonaut’s own purposes – in particular billing, accounting, security, fraud prevention and contract evidence – Syllonaut acts as an independent controller. Current DPA.

8. Service providers

  • Neon (Databricks, Inc.) — production database, sign-in (Neon Auth) and Data API; data is stored in the EU (AWS Frankfurt).
  • Supabase — former database, since 23 September 2026 only a read-only backup until it is deleted (EU); no new data is written to it.
  • Vercel — application hosting and AI Gateway.
  • Cloudflare — Turnstile only on the sign-in and registration forms; Workers and Durable Objects for real-time control of live lessons (student name, lesson content, student and team responses); the Durable Objects run and store data only in the EU jurisdiction and the data is automatically deleted 7 days after the lesson’s last activity.
  • Stripe — payments and subscription management. CZK payments are processed by Stripe Payments Europe, Limited (Ireland); for EUR and USD payments the merchant of record is Sold through Link, LLC, part of the Stripe group. Stripe processes payment data on our behalf and, for its own purposes (fraud prevention, regulatory compliance), also as an independent controller.
  • Resend — transactional emails, marketing mailings based on granted consent and delivery of contact-form enquiries.
  • AI model providers — only to the extent needed for the specific AI operation.
  • Google — Google Analytics 4, only after analytics consent and never on student pages.

Where a provider transfers personal data outside the European Economic Area, appropriate GDPR transfer safeguards must be used.

The current list of sub-processors relevant to organisations and teachers, their purposes, data scope and change procedure is included in the Data Processing Agreement (DPA).

9. Retention periods

  • Account data and saved lessons are retained while the account is active or until deletion, unless a legal obligation requires longer retention.
  • Ended live sessions are scheduled for automatic deletion after 12 months.
  • Abandoned sessions left in lobby/live state are scheduled for automatic deletion after 30 days.
  • The real-time live-lesson copy (Cloudflare, EU jurisdiction) is deleted automatically 7 days after the lesson’s last activity.
  • Syllonaut Help usage records (without the conversation text) are retained while the account exists, because the monthly message limit and budget are calculated from them; they are deleted together with the account.
  • Short-lived editing locks are cleared after 24 hours.
  • Cookie choices are retained for no more than 180 days.
  • A Terms acceptance audit record (account ID, version / acceptance key and server timestamp) may be retained after account deletion for as long as reasonably necessary to evidence the contractual relationship or to establish, exercise or defend legal claims; it is then deleted or anonymised.
  • An organisation DPA acceptance record (version / acceptance key, server timestamp and accepting account ID) may be retained for as long as reasonably necessary to evidence the binding processing agreement and to establish, exercise or defend legal claims; it is then deleted or anonymised unless further retention is legally required.
  • An immutable paid individual contract snapshot (account ID, plan, price, billing period, accepted Terms version, immediate-start request, contract HTML document, model withdrawal form, integrity hash and technical checkout link) may likewise be retained after account deletion only for as long as reasonably necessary to evidence the contract content, comply with legal obligations or establish, exercise or defend legal claims; it is then deleted or anonymised to the extent the purpose allows.
  • The immutable withdrawal record and related settlement are retained only for as long as reasonably necessary to evidence receipt and content of the submission, comply with consumer and accounting obligations, and establish, exercise or defend legal claims; the data is then deleted or anonymised to the extent the purpose allows.
  • For a complaint (name, contact email, account ID, complaint content, requested remedy, current plan, submission time and resolution record) we process data to fulfil the legal obligation to handle the complaint and confirm its receipt and resolution. The immutable record is retained only for as long as reasonably necessary to evidence the resolution and to establish, exercise or defend legal claims; it is then deleted or anonymised.
  • After withdrawal, a limited record of marketing consent may be retained where necessary to demonstrate that your choice and legal obligations were respected.
  • Contact-form messages are retained for the time needed to respond and handle related follow-up; if no contractual relationship or other reason for longer retention arises, we generally do not need the message for more than 12 months. Pseudonymised rate-limit records are continuously deleted after 30 days.

10. Your rights

Depending on the circumstances, you have rights of access, rectification, erasure, restriction, data portability and objection. You can withdraw consent to analytics or marketing emails at any time; withdrawal does not retrospectively affect the lawfulness of prior processing.

You also have the right to lodge a complaint with the Czech Office for Personal Data Protection. Current contact details are available on the authority website.

11. Changes to this notice

This page will be updated if processing practices, service providers or legal requirements change. If a material change requires new consent, consent will be requested again.